Combofix Log..
ComboFix 09-03-22.01 - klaus 2009-03-23 22:15:09.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3199.2698 [GMT 1:00]
Running from: C:\Documents and Settings\klaus\Desktop\ComboFix.exe
AV: YouSee Sikkerhedspakke 7.02 *On-access scanning enabled* (Updated)
FW: YouSee Sikkerhedspakke 7.02 *enabled*
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
ADS - WINDOWS: deleted 24 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\admintxt.txt
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\systeminfo.dll
C:\WINDOWS\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ISODRIVE
-------\Service_ISODrive
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2009-02-23 to 2009-03-23 )))))))))))))))))))))))))))))))
.
2009-03-18 18:51 . 2009-03-23 22:24 280 --a------ C:\WINDOWS\system32\PDBootState
2009-03-18 18:37 . 2009-03-18 18:37 <DIR> d-------- C:\Program Files\IObit
2009-03-18 18:37 . 2009-03-23 08:11 <DIR> d-------- C:\Documents and Settings\klaus\Application Data\IObit
2009-03-17 21:56 . 2009-03-23 18:38 <DIR> d-------- C:\Ebooks_Thomas
2009-03-17 17:10 . 2009-03-17 17:10 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2009-03-17 17:10 . 2009-03-17 17:10 <DIR> d-------- C:\Documents and Settings\klaus\Application Data\Malwarebytes
2009-03-17 17:10 . 2009-03-17 17:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-03-17 17:10 . 2009-02-11 10:19 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2009-03-17 17:10 . 2009-02-11 10:19 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2009-03-17 17:01 . 2009-03-09 20:06 15,688 --a------ C:\WINDOWS\system32\lsdelete.exe
2009-03-16 21:51 . 2009-03-23 21:48 <DIR> d-------- C:\Documents and Settings\klaus\Tracing
2009-03-16 21:43 . 2009-03-16 21:43 <DIR> d-------- C:\Program Files\Microsoft
2009-03-16 21:42 . 2009-03-16 21:42 <DIR> d-------- C:\Program Files\Windows Live SkyDrive
2009-03-16 21:37 . 2009-03-16 21:37 <DIR> d-------- C:\Program Files\Common Files\Windows Live
2009-03-16 20:43 . 2009-03-09 20:06 64,160 --a------ C:\WINDOWS\system32\drivers\Lbd.sys
2009-03-16 20:41 . 2009-03-16 20:41 <DIR> d-------- C:\Program Files\Lavasoft
2009-03-16 20:41 . 2009-03-16 20:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-03-16 20:41 . 2009-03-16 20:42 <DIR> d--h-c--- C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-03-16 20:29 . 2009-03-16 20:29 <DIR> d-------- C:\Program Files\CCleaner
2009-03-03 22:09 . 2008-04-14 01:12 218,624 --a------ C:\WINDOWS\system32\uxtheme.backup
2009-03-02 23:38 . 2009-03-03 00:33 3 --a------ C:\winptfd.dat
2009-03-02 23:21 . 2009-03-17 23:26 <DIR> d-------- C:\Program Files\Thoosje Vista Sidebar
2009-03-02 22:45 . 2009-03-02 22:45 <DIR> d-------- C:\Games
2009-03-02 22:09 . 2009-03-02 22:09 <DIR> d-------- C:\Program Files\Yahoo!
2009-03-02 22:04 . 2004-12-19 23:00 111,104 --a------ C:\WINDOWS\system32\Uharc.exe
2009-03-02 22:04 . 2006-02-26 20:43 19,968 --a------ C:\WINDOWS\system32\reico.exe
2009-03-02 20:29 . 2009-03-03 08:47 <DIR> d-------- C:\Program_Genvej
2009-02-23 15:59 . 2009-02-23 15:59 231,176 --a------ C:\WINDOWS\system32\PDBoot.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-23 21:04 --------- d-----w C:\Documents and Settings\klaus\Application Data\FileZilla
2009-03-23 07:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-03-23 06:51 --------- d-----w C:\Program Files\Logitech
2009-03-23 06:46 --------- d-----w C:\Program Files\LogMeIn
2009-03-18 17:49 --------- d-----w C:\Program Files\RAXCO
2009-03-18 17:43 --------- d-----w C:\Program Files\Curse
2009-03-17 22:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\SlySoft
2009-03-17 21:51 --------- d-----w C:\Documents and Settings\klaus\Application Data\dvdcss
2009-03-17 16:50 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2009-03-16 20:48 --------- d-----w C:\Program Files\Windows Live
2009-03-16 19:42 --------- d-----w C:\Program Files\Spyware Doctor
2009-03-16 19:26 --------- d-----w C:\Documents and Settings\klaus\Application Data\uTorrent
2009-03-16 18:46 --------- d--h--w C:\Program Files\InstallShield Installation Information
2009-03-16 18:46 --------- d-----w C:\Program Files\Realtek
2009-03-04 15:56 --------- d-----w C:\Documents and Settings\klaus\Application Data\Apple Computer
2009-03-04 15:55 --------- d-----w C:\Program Files\Safari
2009-03-02 20:39 --------- d-----w C:\Program Files\iTunes
2009-03-02 17:34 --------- d-----w C:\Program Files\uTorrent
2009-02-18 17:42 --------- d-----w C:\Program Files\Valve
2009-02-18 16:50 --------- d-----w C:\Program Files\DVD Shrink
2009-02-17 13:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2009-02-15 22:12 --------- d-----w C:\Program Files\NTI
2009-02-15 22:11 --------- d-----w C:\Program Files\NewTech Infosystems
2009-02-15 22:09 --------- d-----w C:\Program Files\Common Files\muvee Technologies
2009-02-15 22:00 --------- d-----w C:\Program Files\SlySoft
2009-02-15 21:58 --------- d-----w C:\Documents and Settings\klaus\Application Data\Nero
2009-02-15 21:18 --------- d-----w C:\Program Files\Common Files\Nero
2009-02-15 21:01 --------- d-----w C:\Program Files\Nero
2009-02-15 21:00 --------- d-----w C:\Program Files\Windows Sidebar
2009-02-15 20:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2009-02-15 20:32 --------- d-----w C:\Program Files\Common Files\LightScribe
2009-02-14 11:52 --------- d-----w C:\Documents and Settings\klaus\Application Data\vlc
2009-02-14 00:09 --------- d-----w C:\Program Files\Java
2009-02-12 14:25 --------- d-----w C:\Program Files\Google
2009-02-06 18:03 307,576 ----a-w C:\WINDOWS\WLXPGSS.SCR
2009-02-04 13:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2009-01-29 20:31 --------- d-----w C:\Program Files\FileZilla FTP Client
2009-01-26 23:37 --------- d-----w C:\Documents and Settings\klaus\Application Data\LimeWire
2009-01-26 18:43 --------- d-----w C:\Program Files\TeamViewer
2009-01-19 10:11 0 ----a-w C:\Documents and Settings\klaus\temp.dat
2008-02-28 12:30 8,784 ----a-w C:\Program Files\mozilla firefox\plugins\ractrlkeyhook.dll
2008-02-28 12:33 245,408 ----a-w C:\Program Files\mozilla firefox\plugins\unicows.dll
2008-10-22 18:41 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008102220081023\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 01:12 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-02-13 14:05 86016]
"LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2008-02-28 14:31 63048]
"F-Secure Manager"="C:\Program Files\YouSee\Sikkerhedspakke\Common\FSM32.EXE" [2007-06-01 14:19 183208]
"F-Secure TNB"="C:\Program Files\YouSee\Sikkerhedspakke\FSGUI\TNBUtil.exe" [2007-06-01 14:17 740208]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-02-13 14:05 7557120]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-07-22 23:25 28160 C:\WINDOWS\KHALMNPR.Exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-01-07 13:18:58 528384]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-17 20:07 87352 C:\WINDOWS\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Hurtigstart.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Hurtigstart.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Hurtigstart.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^klaus^Start Menu^Programs^Startup^MagicDisc.lnk]
path=C:\Documents and Settings\klaus\Start Menu\Programs\Startup\MagicDisc.lnk
backup=C:\WINDOWS\pss\MagicDisc.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^klaus^Start Menu^Programs^Startup^Picture Motion Browser Media Check Tool.lnk]
path=C:\Documents and Settings\klaus\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk
backup=C:\WINDOWS\pss\Picture Motion Browser Media Check Tool.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^klaus^Start Menu^Programs^Startup^Thoosje Sidebar.lnk]
path=C:\Documents and Settings\klaus\Start Menu\Programs\Startup\Thoosje Sidebar.lnk
backup=C:\WINDOWS\pss\Thoosje Sidebar.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
--a------ 2008-01-11 18:54 623992 C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
--a------ 2006-07-21 00:13 126976 C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
--a------ 2006-07-21 00:15 1848155 C:\Program Files\Acronis\TrueImageWorkstation\TimounterMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Watch]
--a------ 2009-03-09 20:06 515416 C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-06-12 01:38 34672 C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe_ID0EYTHM]
--a------ 2007-03-20 16:40 1884160 C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
--a------ 2009-02-06 16:27 177472 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BkupTray]
--a------ 2008-03-26 04:02 34040 C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-14 01:12 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2007-08-24 06:00 33648 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
--a------ 2008-08-25 12:36 1168264 C:\Program Files\Spyware Doctor\pctsTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-11-20 13:20 290088 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a------ 2007-02-08 01:21 54832 C:\Program Files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
--a------ 2007-05-17 10:52 505368 C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
--a------ 2007-05-17 10:53 780312 C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-14 01:12 1695232 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2009-02-06 18:51 3885408 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-02-13 14:05 7557120 C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-11-04 10:30 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 2007-02-08 01:24 71216 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2009-02-14 00:39 148888 C:\Program Files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
--a------ 2006-07-21 09:03 1106528 C:\Program Files\Acronis\TrueImageWorkstation\TrueImageMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-r------- 2005-05-03 11:43 69632 C:\WINDOWS\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-02-13 14:05 1519616 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-r------- 2006-06-28 07:54 16248320 C:\WINDOWS\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
-r------- 2006-05-16 11:04 2879488 C:\WINDOWS\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=2 (0x2)
"W32Time"=2 (0x2)
"helpsvc"=2 (0x2)
"SharedAccess"=2 (0x2)
"Adobe Version Cue CS2"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"srservice"=2 (0x2)
"odserv"=3 (0x3)
"Microsoft Office Groove Audit Service"=3 (0x3)
"AcrSch2Svc"=3 (0x3)
"Pml Driver HPZ12"=2 (0x2)
"ose"=3 (0x3)
"Bonjour Service"=2 (0x2)
"SolidWorks Licensing Service"=3 (0x3)
"Nero BackItUp Scheduler 3"=2 (0x2)
"NTISchedulerSvc"=2 (0x2)
"NTIBackupSvc"=2 (0x2)
"Nero BackItUp Scheduler 4.0"=2 (0x2)
"BUNAgentSvc"=2 (0x2)
"WLSetupSvc"=3 (0x3)
"RichVideo"=2 (0x2)
"RemoteRegistry"=2 (0x2)
"RDSessMgr"=3 (0x3)
"RasMan"=3 (0x3)
"RasAuto"=3 (0x3)
"iPod Service"=3 (0x3)
"ERSvc"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"Adobe Version Cue CS3"=3 (0x3)
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"Lavasoft Ad-Aware Service"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 FSFW;F-Secure Firewall Driver;C:\WINDOWS\system32\drivers\fsdfw.sys [2008-11-13 17:03:45 51072]
R0 Lbd;Lbd;C:\WINDOWS\system32\drivers\Lbd.sys [2009-03-16 20:43:29 64160]
R1 F-Secure HIPS;F-Secure HIPS;C:\Program Files\YouSee\Sikkerhedspakke\HIPS\fshs.sys [2008-11-13 17:03:27 41184]
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\000.fcl [2006-11-03 01:51:58 13560]
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\x86\rainfo.sys [2008-02-28 14:31:52 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2008-08-06 14:14:02 47640]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\YouSee\Sikkerhedspakke\Anti-Virus\minifilter\fsgk.sys [2008-11-13 17:03:16 77824]
S2 gupdate1c985fd15fd378a;Google Update Service (gupdate1c985fd15fd378a);C:\Program Files\Google\Update\GoogleUpdate.exe [2009-02-03 13:43:58 133104]
S3 ggflt;SEMC USB Flash Driver Filter;C:\WINDOWS\system32\drivers\ggflt.sys [2008-08-23 12:54:53 13352]
S3 PDConsole;PDConsole;C:\Program Files\RAXCO\PerfectDisk10\PDConsole.exe [2009-02-23 15:59:04 935176]
S3 s3017bus;Sony Ericsson Device 3017 driver (WDM);C:\WINDOWS\system32\drivers\s3017bus.sys [2008-08-23 12:39:08 83880]
S3 s3017mdfl;Sony Ericsson Device 3017 USB WMC Modem Filter;C:\WINDOWS\system32\drivers\s3017mdfl.sys [2008-08-23 12:39:08 15016]
S3 s3017mdm;Sony Ericsson Device 3017 USB WMC Modem Driver;C:\WINDOWS\system32\drivers\s3017mdm.sys [2008-08-23 12:39:08 110632]
S3 s3017mgmt;Sony Ericsson Device 3017 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\drivers\s3017mgmt.sys [2008-08-23 12:39:09 104616]
S3 s3017nd5;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (NDIS);C:\WINDOWS\system32\drivers\s3017nd5.sys [2008-08-23 12:39:08 25512]
S3 s3017obex;Sony Ericsson Device 3017 USB WMC OBEX Interface;C:\WINDOWS\system32\drivers\s3017obex.sys [2008-08-23 12:39:08 100648]
S3 s3017unic;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (WDM);C:\WINDOWS\system32\drivers\s3017unic.sys [2008-08-23 12:39:09 110120]
S3 USBAAPL;Apple Mobile USB Driver;C:\WINDOWS\system32\drivers\usbaapl.sys [2008-01-01 21:07:28 32000]
S4 BUNAgentSvc;NTI Backup Now 5 Agent Service;C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 12:11:14 16384]
S4 F-Secure Filter;F-Secure File System Filter;C:\Program Files\YouSee\Sikkerhedspakke\Anti-Virus\win2k\fsfilter.sys [2008-11-13 17:03:16 40048]
S4 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\YouSee\Sikkerhedspakke\Anti-Virus\win2k\fsrec.sys [2008-11-13 17:03:16 25456]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-09 20:06:55 951632]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
S4 NTIBackupSvc;NTI Backup Now 5 Backup Service;C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-03-21 04:09:30 53248]
S4 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-03-07 15:28:12 131072]
S4 sdAuxService;PC Tools Auxiliary Service;C:\Program Files\Spyware Doctor\pctsAuxs.exe [2008-11-13 17:12:56 356920]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-03-06 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 16:53]
2009-03-23 C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
- C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 20:06]
2009-03-06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-03-23 C:\WINDOWS\Tasks\GoogleUpdateTaskMachine.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2009-02-03 13:43]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-Acrobat Assistant 7 - C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
MSConfigStartUp-Adobe Version Cue CS2 - C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
MSConfigStartUp-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
MSConfigStartUp-HP Software Update - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
MSConfigStartUp-LDM - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
MSConfigStartUp-NBKeyScan - C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
MSConfigStartUp-NeroFilterCheck - C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
MSConfigStartUp-updateMgr - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AdobeUpdateManager.exe
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://google.dk/uInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Download valgte med Free Download Manager -
file://C:\Program Files\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager -
file://C:\Program Files\Free Download Manager\dlfvideo.htm
IE: E&ksporter til Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: C:\Program Files\YouSee\Sikkerhedspakke\FSPS\program\fslsp.dll
Trusted Zone: sparhobro.dk\www
Trusted Zone: virtualflycasting.com\www
DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} -
hxxps://www.sparhobro.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.30.cabFF - ProfilePath - C:\Documents and Settings\klaus\Application Data\Mozilla\Firefox\Profiles\s0yewx9y.default\
FF - prefs.js: browser.startup.homepage -
hxxp://google.dk/FF - prefs.js: keyword.URL -
hxxp://search.freecause.com/search?fr=freecause&ourmark=3&type=59033&ei=utf-8&yahoo_domain=search.yahoo.com&p=FF - component: C:\Documents and Settings\klaus\Application Data\Mozilla\Firefox\Profiles\s0yewx9y.default\extensions\{75ac016f-ff3f-486c-9f98-36637223a8e1}\components\Engine.dll
FF - plugin: C:\Program Files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npRACtrl.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
FF - user.js: network.http.max-connections-per-server - 8
.