ComboFix 09-05-26.05 - jette 28-05-2009 21:37.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1033.18.502.309 [GMT 2:00]
Kører fra: c:\documents and settings\jette\Desktop\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\jette\Desktop\CFScript.txt
AV: BullGuard Antivirus *On-access scanning disabled* (Outdated) {7A9BB333-8EDF-4FDC-A2A5-1A30FA021913}
FW: BullGuard Firewall *disabled* {2AEF4CB6-61B5-4E60-AF22-D95E75B63FA1}
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\jette\Application Data\
02000000d1495186C.manifest
c:\documents and settings\jette\Application Data\
02000000d1495186O.manifest
c:\documents and settings\jette\Application Data\
02000000d1495186P.manifest
c:\documents and settings\jette\Application Data\
02000000d1495186S.manifest
C:\xcrashdump.dat
.
((((((((((((((((((((((((((((( Filer skabt fra 2009-04-28 til 2009-05-28 )))))))))))))))))))))))))))))))))))
.
2009-05-28 16:59 . 2009-05-28 16:59 3371383 ----a-w c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-28 10:58 . 2009-05-28 19:41 117760 ----a-w c:\documents and settings\jette\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-05-28 10:57 . 2009-05-28 10:57 -------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-28 10:57 . 2009-05-28 10:57 -------- d-----w c:\program files\SUPERAntiSpyware
2009-05-28 10:57 . 2009-05-28 10:57 -------- d-----w c:\documents and settings\jette\Application Data\SUPERAntiSpyware.com
2009-05-28 10:38 . 2009-05-28 10:38 -------- d-----w c:\program files\CCleaner
2009-05-28 10:22 . 2009-05-28 10:22 -------- d-----w c:\documents and settings\jette\Application Data\Malwarebytes
2009-05-28 10:22 . 2009-05-26 11:19 19096 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-28 10:22 . 2009-05-26 11:20 40160 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-28 10:22 . 2009-05-28 10:22 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-28 10:22 . 2009-05-28 10:22 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-25 17:33 . 2009-05-25 17:33 -------- d-sh--w C:\FOUND.004
2009-05-25 17:20 . 2009-05-25 17:20 -------- d-----w c:\windows\system32\sysloc
2009-05-08 08:48 . 2009-05-08 08:48 -------- d-----w c:\documents and settings\jette\cbt
2009-05-05 15:17 . 2009-05-05 15:17 -------- d-----w c:\documents and settings\jette\Application Data\Cryptomathic
2009-05-05 15:15 . 2009-05-05 15:15 -------- d--h--w c:\documents and settings\All Users\Application Data\{D166A25B-41F0-45EA-B10E-DE7D7B5C3455}
2009-05-05 15:15 . 2009-01-30 11:45 3011128 ----a-w c:\documents and settings\All Users\Application Data\{D166A25B-41F0-45EA-B10E-DE7D7B5C3455}\csp.exe
2009-05-05 15:15 . 2009-05-05 15:15 -------- d-----w c:\program files\DanID
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-28 19:39 . 2006-09-22 12:27 12 ----a-w c:\windows\bthservsdp.dat
2009-03-31 16:15 . 2009-03-31 16:15 152576 ----a-w c:\documents and settings\jette\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-03-31 14:22 . 2009-03-31 14:22 -------- d-----w c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-03-09 03:19 . 2009-02-23 07:59 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-06 14:22 . 2004-08-10 18:00 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2006-01-09 18:02 826368 ----a-w c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BullGuard"="c:\program files\BullGuard Software\BullGuard\bullguard.exe" [2008-04-11 308552]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-05-28 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-12-21 53248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 761946]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\Monitor.exe" [2006-01-24 397312]
"BullGuard"="c:\program files\BullGuard Software\BullGuard\bullguard.exe" [2008-04-11 308552]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-08-10 352256]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 10:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Hurtig start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Hurtig start.lnk
backup=c:\windows\pss\HP Image Zone Hurtig start.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\MSMSGS.EXE"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [23-03-2009 14:07 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [23-03-2009 14:07 72944]
R1 VFILT;BullGuard Firewall Kernel Driver;c:\program files\BullGuard Software\BullGuard\fwengine\Filtnt.sys [27-10-2006 11:00 125216]
R2 BdFileSpy;BullGuard File Monitor Driver;c:\windows\system32\drivers\BdFileSpy.sys [29-01-2007 21:43 50896]
R2 BsFileScan;BullGuard File Scan Service;c:\windows\System32\svchost.exe -k BullGuard [10-08-2004 20:00 14336]
R2 BsFwall;BullGuard Firewall Service;c:\windows\System32\svchost.exe -k BullGuardFw [10-08-2004 20:00 14336]
R2 BsMailProxy;BullGuard Email Monitoring Service;c:\windows\System32\svchost.exe -k BullGuard [10-08-2004 20:00 14336]
R3 PROTECT.DLL;BullGuard Firewall Protection Plugin;c:\program files\BullGuard Software\BullGuard\fwengine\Protect.dll [27-10-2006 11:00 16960]
R3 Reconn;BullGuard Email Monitor;c:\program files\BullGuard Software\BullGuard\Reconn.sys [27-10-2006 11:01 16984]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [23-03-2009 14:07 7408]
S2 gupdate1c98dcaaed718e7;Tjenesten Google Update (gupdate1c98dcaaed718e7);c:\program files\Google\Update\GoogleUpdate.exe [13-02-2009 12:03 133104]
S3 ADBLOCK.DLL;BullGuard Firewall Adware Plugin;\??\c:\program files\BullGuard Software\BullGuard\FwEngine\AdBlock.dll --> c:\program files\BullGuard Software\BullGuard\FwEngine\AdBlock.dll [?]
S3 BGRaSvc;BGRaSvc;c:\program files\BullGuard Software\BullGuard\support\bgrasvc.exe [19-03-2008 10:39 79176]
S3 HTMLFILT.DLL;BullGuard Firewall HTML Plugin;\??\c:\program files\BullGuard Software\BullGuard\FwEngine\HtmlFilt.dll --> c:\program files\BullGuard Software\BullGuard\FwEngine\HtmlFilt.dll [?]
S3 HTTPFILT.DLL;BullGuard Firewall HTTP Plugin;\??\c:\program files\BullGuard Software\BullGuard\FwEngine\HttpFilt.dll --> c:\program files\BullGuard Software\BullGuard\FwEngine\HttpFilt.dll [?]
--- Andre Services/Drivers i Hukommelsen ---
*NewlyCreated* - SASDIFSV
*NewlyCreated* - UBHELPER
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
BullGuard REG_MULTI_SZ BgMainSvc BsFileScan BsMailProxy
BullGuardFw REG_MULTI_SZ BsFwall
.
Indhold af mappen 'Planlagte Opgaver'
2009-05-28 c:\windows\Tasks\HPpromotions journeysoftware.job
- c:\program files\hp\digital imaging\bin\hp promotions\journeysoftware\HPpromo.exe [2005-04-22 15:36]
2009-05-28 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-13 15:17]
2009-05-28 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-13 10:03]
.
- - - - TOMME GENVEJE FJERNET - - - -
Notify-1d0f11d5448 - c:\windows\System32\pifmgr32.dll
SafeBoot-procexp90.Sys
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.dk/uSearchMigratedDefaultURL =
hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7uInternet Connection Wizard,ShellNext =
hxxp://da.intl.acer.yahoo.com/uInternet Settings,ProxyServer = http=localhost:7171
uInternet Settings,ProxyOverride = *.local;<local>
uSearchURL,(Default) =
hxxp://uk.rd.yahoo.com/customize/ycomp/defaults/su/*http://uk.yahoo.comIE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: danid.dk
TCP: {2D3A32E7-179E-423F-BF2D-E1F9E9678BB9} = 213.174.139.72,10.20.63.141
TCP: {58F4D272-58B8-4A18-83CA-70C9C585DC53} = 213.174.139.72,10.20.63.141
TCP: {B9888F38-A4A3-474D-9D70-9483288348DE} = 213.174.139.72,10.20.63.141
DPF: {9DF01F00-08E7-4DBE-9070-94841463B3FE} -
hxxps://danid.dk/csp/authenticode/csp.exe.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-28 21:40
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- DLLs startet under kørende Processer ---------------------
- - - - - - - > 'winlogon.exe'(756)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
- - - - - - - > 'explorer.exe'(3112)
c:\program files\BullGuard Software\BullGuard\antispam\PluginHook.dll
c:\program files\BullGuard Software\BullGuard\res\dk\PluginHookRes.dll
c:\acer\Empowering Technology\ePower\SysHook.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\program files\LAVASOFT\AD-AWARE\AAWSERVICE.EXE
c:\acer\EMPOWERING TECHNOLOGY\ADMSERV.EXE
c:\program files\BULLGUARD SOFTWARE\BULLGUARD\BULLGUARDUPDATE.EXE
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\JAVA\JRE6\BIN\JQS.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\SYSTEM32\HPZIPM12.EXE
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Gennemført tid: 2009-05-28 21:44 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2009-05-28 19:44
Pre-Kørsel: 11.744.854.016 bytes free
Post-Kørsel: 11.876.237.312 byte ledig
187 --- E O F --- 2009-05-13 09:05