accepteret
her er loggen og så snart fix var færdig dukkede pop up :-) så tror jeg tilbagekalder computeren og så strarter helt forfra
ComboFix 09-06-23.01 - Belma Nezirevic 24-06-2009 17:12.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.45.1030.18.2045.1271 [GMT 2:00]
Kører fra: c:\users\Belma Nezirevic\Desktop\comp\ComboFix.exe
Kommandoer benyttet :: c:\users\Belma Nezirevic\Desktop\comp\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spyware Doctor *disabled* (Updated) {1C3EDD79-273E-46ac-99F8-EFA9E7CBC301}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-3227108159-1881649373-4094085349-500
c:\$recycle.bin\S-1-5-21-3227108159-1881649373-4094085349-500\desktop.ini
E:\Desktop.ini
.
((((((((((((((((((((((((((((( Filer skabt fra 2009-05-24 til 2009-06-24 )))))))))))))))))))))))))))))))))))
.
2009-06-24 15:16 . 2009-06-24 15:18 -------- d-----w- c:\users\Belma Nezirevic\AppData\Local\temp
2009-06-24 14:51 . 2008-12-11 06:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-06-24 14:51 . 2009-04-03 09:18 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-06-24 14:51 . 2008-12-18 10:16 73840 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-06-24 14:51 . 2009-06-24 14:51 -------- d-----w- c:\program files\Common Files\PC Tools
2009-06-24 14:51 . 2008-12-10 09:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-06-24 14:51 . 2009-06-24 14:52 -------- d-----w- c:\program files\Spyware Doctor
2009-06-24 14:51 . 2009-06-24 14:51 -------- d-----w- c:\users\Belma Nezirevic\AppData\Roaming\PC Tools
2009-06-24 14:51 . 2009-06-24 14:51 -------- d-----w- c:\programdata\PC Tools
2009-06-24 14:49 . 2009-06-24 14:55 -------- d-----w- c:\programdata\Google Updater
2009-06-24 14:49 . 2009-06-24 14:49 -------- d-----w- c:\program files\Google
2009-06-24 14:26 . 2006-12-20 06:03 229888 ----a-w- c:\windows\system32\msshsq.dll
2009-06-23 22:45 . 2009-06-23 22:45 268800 ----a-w- c:\windows\system32\es.dll
2009-06-23 22:44 . 2009-06-23 22:44 441856 ----a-w- c:\windows\system32\win32spl.dll
2009-06-23 22:44 . 2009-06-23 22:44 37376 ----a-w- c:\windows\system32\printcom.dll
2009-06-23 22:32 . 2009-06-23 22:32 -------- d-----w- c:\program files\SystemRequirementsLab
2009-06-23 20:12 . 2009-06-23 20:12 -------- d-----w- c:\users\Belma Nezirevic\AppData\Roaming\Malwarebytes
2009-06-23 20:12 . 2009-06-23 20:12 -------- d-----w- c:\programdata\Malwarebytes
2009-06-23 17:32 . 2009-06-23 20:10 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-06-23 16:45 . 2009-06-23 21:09 -------- dc----w- c:\windows\system32\DRVSTORE
2009-06-23 16:43 . 2009-06-23 21:09 -------- d-----w- c:\programdata\Lavasoft
2009-06-23 15:11 . 2009-06-23 15:11 -------- d-----w- C:\NVIDIA
2009-06-23 14:13 . 2009-06-23 22:52 -------- d-----w- c:\programdata\NVIDIA
2009-06-23 14:10 . 2009-06-24 14:34 -------- d-----w- c:\users\Belma Nezirevic\AppData\Roaming\vlc
2009-06-17 20:46 . 2009-06-17 20:46 61440 ----a-w- c:\windows\system32\winipsec.dll
2009-06-17 20:46 . 2009-06-17 20:46 28672 ----a-w- c:\windows\system32\FwRemoteSvr.dll
2009-06-17 20:46 . 2009-06-17 20:46 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2009-06-17 20:46 . 2009-06-17 20:46 272896 ----a-w- c:\windows\system32\polstore.dll
2009-06-17 20:42 . 2009-06-17 20:42 95232 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-06-17 20:42 . 2009-06-17 20:42 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-06-17 20:42 . 2009-06-17 20:42 160768 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-06-17 20:35 . 2009-06-17 20:35 1244672 ----a-w- c:\windows\system32\mcmde.dll
2009-06-17 20:35 . 2009-06-17 20:35 428032 ----a-w- c:\windows\system32\EncDec.dll
2009-06-17 20:35 . 2009-06-17 20:35 292352 ----a-w- c:\windows\system32\psisdecd.dll
2009-06-17 20:32 . 2009-06-17 20:32 39424 ----a-w- c:\windows\system32\ACCTRES.dll
2009-06-17 20:32 . 2009-06-17 20:32 87040 ----a-w- c:\windows\system32\msoert2.dll
2009-06-17 20:32 . 2009-06-17 20:32 205824 ----a-w- c:\windows\system32\msoeacct.dll
2009-06-17 20:26 . 2009-06-17 20:26 704000 ----a-w- c:\windows\system32\PhotoScreensaver.scr
2009-06-17 20:24 . 2009-06-17 20:24 194560 ----a-w- c:\windows\system32\WebClnt.dll
2009-06-17 20:24 . 2009-06-17 20:24 110080 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2009-06-17 20:23 . 2009-06-17 20:23 2028032 ----a-w- c:\windows\system32\win32k.sys
2009-06-17 20:21 . 2009-06-17 20:21 49664 ----a-w- c:\windows\system32\csrsrv.dll
2009-06-17 20:21 . 2009-06-17 20:21 376320 ----a-w- c:\windows\system32\winsrv.dll
2009-06-17 20:17 . 2009-06-17 20:17 376832 ----a-w- c:\windows\system32\winhttp.dll
2009-06-17 20:10 . 2009-06-17 20:10 297472 ----a-w- c:\windows\system32\gdi32.dll
2009-06-17 20:08 . 2009-06-17 20:08 1060920 ----a-w- c:\windows\system32\drivers\ntfs.sys
2009-06-17 20:08 . 2009-06-17 20:08 41984 ----a-w- c:\windows\system32\drivers\monitor.sys
2009-06-17 20:07 . 2009-06-17 20:07 211456 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2009-06-17 20:06 . 2009-06-17 20:06 374456 ----a-w- c:\windows\system32\mcupdate_GenuineIntel.dll
2009-06-17 20:04 . 2009-06-17 20:04 500736 ----a-w- c:\windows\system32\msdtcprx.dll
2009-06-17 20:04 . 2009-06-17 20:04 30208 ----a-w- c:\windows\system32\xolehlp.dll
2009-06-17 20:01 . 2009-06-17 20:01 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-06-17 20:01 . 2009-06-17 20:01 4247552 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-06-17 20:01 . 2009-06-17 20:01 1687040 ----a-w- c:\windows\system32\gameux.dll
2009-06-17 19:59 . 2009-06-17 19:59 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2009-06-17 19:56 . 2009-06-17 19:56 1194496 ----a-w- c:\windows\system32\msxml3.dll
2009-06-17 19:56 . 2009-06-17 19:56 2048 ----a-w- c:\windows\system32\msxml3r.dll
2009-06-17 19:54 . 2009-06-17 19:54 414208 ----a-w- c:\windows\system32\msscp.dll
2009-06-17 19:52 . 2009-06-17 19:52 356864 ----a-w- c:\windows\system32\MediaMetadataHandler.dll
2009-06-17 19:50 . 2009-06-17 19:50 63488 ----a-w- c:\windows\system32\drivers\mpsdrv.sys
2009-06-17 19:50 . 2009-06-17 19:50 392192 ----a-w- c:\windows\system32\FirewallAPI.dll
2009-06-17 19:50 . 2009-06-17 19:50 86016 ----a-w- c:\windows\system32\icfupgd.dll
2009-06-17 19:50 . 2009-06-17 19:50 396800 ----a-w- c:\windows\system32\MPSSVC.dll
2009-06-17 19:50 . 2009-06-17 19:50 16896 ----a-w- c:\windows\system32\wfapigp.dll
2009-06-17 19:50 . 2009-06-17 19:50 61952 ----a-w- c:\windows\system32\cmifw.dll
2009-06-17 19:50 . 2009-06-17 19:50 23040 ----a-w- c:\windows\system32\drivers\tunnel.sys
2009-06-17 19:50 . 2009-06-17 19:50 178688 ----a-w- c:\windows\system32\iphlpsvc.dll
2009-06-17 19:50 . 2009-06-17 19:50 15360 ----a-w- c:\windows\system32\drivers\TUNMP.SYS
2009-06-17 19:47 . 2009-06-17 19:47 2048 ----a-w- c:\windows\system32\tzres.dll
2009-06-17 19:41 . 2009-06-17 19:41 8147968 ----a-w- c:\windows\system32\wmploc.DLL
2009-06-17 19:41 . 2009-06-17 19:41 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-06-17 19:41 . 2009-06-17 19:41 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-06-17 19:36 . 2009-06-17 19:36 696832 ----a-w- c:\windows\system32\localspl.dll
2009-06-17 19:27 . 2009-06-17 19:27 45112 ----a-w- c:\windows\system32\drivers\pciidex.sys
2009-06-17 19:27 . 2009-06-17 19:27 21560 ----a-w- c:\windows\system32\drivers\atapi.sys
2009-06-17 19:27 . 2009-06-17 19:27 109624 ----a-w- c:\windows\system32\drivers\ataport.sys
2009-06-17 19:27 . 2009-06-17 19:27 25656 ----a-w- c:\windows\system32\drivers\msahci.sys
2009-06-17 19:27 . 2009-06-17 19:27 17464 ----a-w- c:\windows\system32\drivers\intelide.sys
2009-06-17 19:27 . 2009-06-17 19:27 211000 ----a-w- c:\windows\system32\drivers\volsnap.sys
2009-06-17 19:27 . 2009-06-17 19:27 154624 ----a-w- c:\windows\system32\drivers\nwifi.sys
2009-06-17 19:26 . 2009-06-17 19:26 104448 ----a-w- c:\windows\system32\DWWIN.EXE
2009-06-17 19:25 . 2009-06-17 19:25 2923520 ----a-w- c:\windows\explorer.exe
2009-06-17 19:22 . 2009-06-17 19:22 8704 ----a-w- c:\windows\system32\hcrstco.dll
2009-06-17 19:22 . 2009-06-17 19:22 8704 ----a-w- c:\windows\system32\hccoin.dll
2009-06-17 19:22 . 2009-06-17 19:22 5888 ----a-w- c:\windows\system32\drivers\usbd.sys
2009-06-17 19:22 . 2009-06-17 19:22 192000 ----a-w- c:\windows\system32\drivers\usbhub.sys
2009-06-17 19:22 . 2009-06-17 19:22 38400 ----a-w- c:\windows\system32\drivers\usbehci.sys
2009-06-17 19:22 . 2009-06-17 19:22 23040 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2009-06-17 19:22 . 2009-06-17 19:22 224768 ----a-w- c:\windows\system32\drivers\usbport.sys
2009-06-17 19:22 . 2009-06-17 19:22 73216 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-06-17 19:20 . 2009-06-17 19:20 803328 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-06-17 19:20 . 2009-06-17 19:20 24064 ----a-w- c:\windows\system32\netcfg.exe
2009-06-17 19:20 . 2009-06-17 19:20 22016 ----a-w- c:\windows\system32\netiougc.exe
2009-06-17 19:20 . 2009-06-17 19:20 216632 ----a-w- c:\windows\system32\drivers\netio.sys
2009-06-17 19:20 . 2009-06-17 19:20 167424 ----a-w- c:\windows\system32\tcpipcfg.dll
2009-06-17 19:12 . 2009-06-17 19:12 4981248 ----a-w- c:\windows\system32\NlsLexicons0013.dll
2009-06-17 19:12 . 2009-06-17 19:12 3331072 ----a-w- c:\windows\system32\NlsLexicons0018.dll
2009-06-17 19:12 . 2009-06-17 19:12 6781440 ----a-w- c:\windows\system32\NlsLexicons0019.dll
2009-06-17 19:12 . 2009-06-17 19:12 11722752 ----a-w- c:\windows\system32\NlsLexicons0001.dll
2009-06-17 19:12 . 2009-06-17 19:12 4164096 ----a-w- c:\windows\system32\NlsLexicons0002.dll
2009-06-17 19:12 . 2009-06-17 19:12 1452544 ----a-w- c:\windows\system32\NlsLexicons0003.dll
2009-06-17 19:12 . 2009-06-17 19:12 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2009-06-17 19:12 . 2009-06-17 19:12 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2009-06-17 19:12 . 2009-06-17 19:12 3419136 ----a-w- c:\windows\system32\NlsLexicons004a.dll
2009-06-17 19:12 . 2009-06-17 19:12 1702912 ----a-w- c:\windows\system32\NlsLexicons004b.dll
2009-06-17 19:11 . 2009-06-17 19:11 4093440 ----a-w- c:\windows\system32\NlsLexicons004c.dll
2009-06-17 19:11 . 2009-06-17 19:11 1972736 ----a-w- c:\windows\system32\NlsLexicons004e.dll
2009-06-17 19:11 . 2009-06-17 19:11 4045824 ----a-w- c:\windows\system32\NlsLexicons003e.dll
2009-06-17 19:11 . 2009-06-17 19:11 4096 ----a-w- c:\windows\system32\NlsLexicons002a.dll
2009-06-17 19:11 . 2009-06-17 19:11 6014976 ----a-w- c:\windows\system32\NlsLexicons001a.dll
2009-06-17 19:11 . 2009-06-17 19:11 6585856 ----a-w- c:\windows\system32\NlsLexicons001b.dll
2009-06-17 19:11 . 2009-06-17 19:11 6346240 ----a-w- c:\windows\system32\NlsLexicons001d.dll
2009-06-17 19:11 . 2009-06-17 19:11 9892864 ----a-w- c:\windows\system32\NlsLexicons000a.dll
2009-06-17 19:11 . 2009-06-17 19:11 6237696 ----a-w- c:\windows\system32\NlsLexicons000c.dll
2009-06-17 19:11 . 2009-06-17 19:11 1722368 ----a-w- c:\windows\system32\NlsLexicons000d.dll
2009-06-17 19:09 . 2009-06-17 19:09 1963520 ----a-w- c:\windows\system32\NlsData0c1a.dll
2009-06-17 18:56 . 2009-06-17 18:56 19456 ----a-w- c:\windows\system32\drivers\bthenum.sys
2009-06-17 18:56 . 2009-06-17 18:56 181760 ----a-w- c:\windows\system32\fsquirt.exe
2009-06-17 18:56 . 2009-06-17 18:56 29184 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2009-06-17 18:56 . 2009-06-17 18:56 220160 ----a-w- c:\windows\system32\drivers\bthport.sys
2009-06-17 18:54 . 2009-06-17 18:54 1585664 ----a-w- c:\windows\system32\setupapi.dll
2009-06-17 18:50 . 2009-06-17 18:50 549888 ----a-w- c:\windows\system32\rpcss.dll
2009-06-17 18:50 . 2009-06-17 18:50 3503584 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-06-17 18:50 . 2009-06-17 18:50 3469280 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-06-17 18:50 . 2009-06-17 18:50 654336 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-24 15:18 . 2009-06-23 15:15 64172 ----a-w- c:\programdata\nvModes.dat
2009-06-24 15:09 . 2006-11-21 04:49 80288 ----a-w- c:\windows\system32\perfc006.dat
2009-06-24 15:09 . 2006-11-21 04:49 485600 ----a-w- c:\windows\system32\perfh006.dat
2009-06-24 14:33 . 2007-02-04 07:19 -------- d-----w- c:\program files\CONEXANT
2009-06-23 22:29 . 2009-06-23 14:09 26049 ----a-w- c:\users\Belma Nezirevic\AppData\Roaming\nvModes.dat
2009-06-17 21:07 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-06-17 21:07 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-06-17 21:07 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-06-17 21:04 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-06-17 21:04 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-06-17 20:25 . 2009-06-17 20:25 356352 ----a-w- c:\windows\system32\wbem\wbemcomn.dll
2009-06-17 20:25 . 2009-06-17 20:25 24064 ----a-w- c:\windows\system32\wtsapi32.dll
2009-06-17 20:25 . 2009-06-17 20:25 258232 ----a-w- c:\windows\system32\drivers\acpi.sys
2009-06-17 20:25 . 2009-06-17 20:25 20920 ----a-w- c:\windows\system32\drivers\compbatt.sys
2009-06-17 20:25 . 2009-06-17 20:25 11264 ----a-w- c:\windows\system32\drivers\wmiacpi.sys
2009-06-17 20:25 . 2009-06-17 20:25 28344 ----a-w- c:\windows\system32\drivers\battc.sys
2009-06-17 20:25 . 2009-06-17 20:25 14208 ----a-w- c:\windows\system32\drivers\CmBatt.sys
2009-06-17 20:25 . 2009-06-17 20:25 542720 ----a-w- c:\windows\system32\sysmain.dll
2009-06-17 20:25 . 2009-06-17 20:25 67584 ----a-w- c:\windows\system32\wlanhlp.dll
2009-06-17 20:25 . 2009-06-17 20:25 47104 ----a-w- c:\windows\system32\wlanapi.dll
2009-06-17 20:25 . 2009-06-17 20:25 502784 ----a-w- c:\windows\system32\wlansvc.dll
2009-06-17 20:25 . 2009-06-17 20:25 297984 ----a-w- c:\windows\system32\wlansec.dll
2009-06-17 20:25 . 2009-06-17 20:25 290816 ----a-w- c:\windows\system32\wlanmsm.dll
2009-06-17 19:10 . 2009-06-17 19:10 5654528 ----a-w- c:\windows\system32\NlsLexicons000f.dll
2009-06-17 18:53 . 2009-06-17 18:53 40960 ----a-w- c:\windows\system32\srclient.dll
2009-06-17 18:41 . 2009-06-17 18:41 61440 ----a-w- c:\windows\system32\ntprint.exe
2009-06-17 18:41 . 2009-06-17 18:41 220160 ----a-w- c:\windows\system32\ntprint.dll
2009-06-17 18:41 . 2009-06-17 18:41 120320 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2009-06-17 18:41 . 2009-06-17 18:41 10240 ----a-w- c:\windows\system32\dhcpcmonitor.dll
2009-06-17 18:41 . 2009-06-17 18:41 1984512 ----a-w- c:\windows\system32\authui.dll
2009-06-17 18:41 . 2009-06-17 18:41 65024 ----a-w- c:\windows\system32\avicap32.dll
2009-06-17 18:41 . 2009-06-17 18:41 88576 ----a-w- c:\windows\system32\avifil32.dll
2009-06-17 18:41 . 2009-06-17 18:41 82944 ----a-w- c:\windows\system32\mciavi32.dll
2009-06-17 18:41 . 2009-06-17 18:41 31232 ----a-w- c:\windows\system32\msvidc32.dll
2009-06-17 18:41 . 2009-06-17 18:41 12800 ----a-w- c:\windows\system32\msrle32.dll
2009-06-17 18:41 . 2009-06-17 18:41 123904 ----a-w- c:\windows\system32\msvfw32.dll
2009-06-17 18:41 . 2009-06-17 18:41 69632 ----a-w- c:\windows\system32\sendmail.dll
2009-06-17 18:41 . 2009-06-17 18:41 8138240 ----a-w- c:\windows\system32\ssBranded.scr
2009-06-17 17:39 . 2009-06-17 17:39 72704 ----a-w- c:\windows\system32\admparse.dll
2009-06-17 17:39 . 2009-06-17 17:39 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-17 17:38 . 2009-06-17 17:38 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-06-17 17:38 . 2009-06-17 17:38 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-06-17 17:38 . 2009-06-17 17:38 56320 ----a-w- c:\windows\system32\iesetup.dll
2009-06-17 14:56 . 2007-02-04 07:40 -------- d-----w- c:\programdata\Sonic
2009-06-17 14:56 . 2007-02-04 07:55 -------- d-----w- c:\program files\HP
2009-06-17 14:52 . 2007-02-04 07:43 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-06-17 14:50 . 2007-02-04 07:44 -------- d-----w- c:\programdata\Symantec
2009-06-17 14:34 . 2007-02-04 07:33 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-17 14:32 . 2007-02-04 07:30 -------- d-----w- c:\program files\Hewlett-Packard
2009-06-17 14:22 . 2009-06-17 14:22 0 --sha-r- c:\windows\system32\drivers\103C_HP_cNB_Pavilion dv9000 (RY688EA#UUW)_Y5335KV_0U_QCNF7093BQM_E436463-DH3_4A_I30BD_SQuanta_V66.37_F.16_T070202_WV3-0_L406_M2046_J160_7Intel_86F6_91.67_#090617_N8086109A;80864222_(RY688EA#UUW)_XMOBILE_CN10_Z.MRK
2009-06-17 14:13 . 2009-06-17 14:13 -------- d-sh--we c:\programdata\Skrivebord
2009-06-17 14:13 . 2009-06-17 14:13 -------- d-sh--we c:\programdata\Skabeloner
2009-06-17 14:13 . 2009-06-17 14:13 -------- d-sh--we c:\programdata\Menuen Start
2009-06-17 14:13 . 2009-06-17 14:13 -------- d-sh--we c:\programdata\Favoritter
2009-06-17 14:13 . 2009-06-17 14:13 -------- d-sh--we c:\programdata\Dokumenter
2009-06-17 14:13 . 2009-06-17 14:13 -------- d-sh--we c:\program files\Fælles filer
2009-06-17 14:07 . 2007-02-04 07:56 -------- d-----w- c:\programdata\CyberLink
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-06-17 1232896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-11-06 159744]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0\bin\jusched.exe" [2007-02-04 77824]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-17 1948440]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-30 13605408]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-30 92704]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Hurtigstart.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Hurtigstart.lnk
backup=c:\windows\pss\Adobe Reader Hurtigstart.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3696602804-2983050917-1453129974-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{AFADD53A-CFE5-4319-BE5E-33ACD669EAA7}"= UDP:c:\program files\HP\QuickPlay\QP.exe:QP
"{27D31CF6-3C93-4D4B-93AE-39FA85B11E2A}"= TCP:c:\program files\HP\QuickPlay\QP.exe:QP
"{C09CB18D-A161-4376-BA2B-8A524BB99D43}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"{BC7ED77E-79B8-4C52-A81A-E2F76010FD4B}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{29E18082-8832-40A1-817A-E1509AC439C6}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
"TCP Query User{320E5038-B211-44BA-95E9-BB3CF375D5B4}c:\\users\\belma nezirevic\\desktop\\nasnavi2\\nasnavi2.exe"= UDP:c:\users\belma nezirevic\desktop\nasnavi2\nasnavi2.exe:nasnavi2.exe
"UDP Query User{43C4AB31-85C8-475F-9EC7-8A7D49B3FECB}c:\\users\\belma nezirevic\\desktop\\nasnavi2\\nasnavi2.exe"= TCP:c:\users\belma nezirevic\desktop\nasnavi2\nasnavi2.exe:nasnavi2.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-01-07 348752]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-04-03 130936]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-06-17 327688]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-06-17 108552]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-06-17 908568]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-06-17 298776]
S3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480]
S3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\system32\Drivers\R5U870FLx86.sys [2006-12-18 73472]
S3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\system32\Drivers\R5U870FUx86.sys [2006-12-18 43904]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
Indhold af mappen 'Planlagte Opgaver'
2009-06-24 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-06-24 14:49]
.
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.dk/mStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DA_DK&c=71&bd=Pavilion&pf=laptopDPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} -
hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-24 17:18
Windows 6.0.6000 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Andre kørende processer ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\rundll32.exe
c:\program files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\System32\drivers\XAudio.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\program files\HP\QuickPlay\Kernel\TV\CLSched.exe
c:\windows\System32\conime.exe
c:\program files\AVG\AVG8\avgtray.exe
c:\windows\System32\rundll32.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
c:\program files\Hewlett-Packard\SDP\RemEngine.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Gennemført tid: 2009-06-24 17:22 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2009-06-24 15:22
Pre-Kørsel: 109.444.100.096 byte ledig
Post-Kørsel: 109.313.376.256 byte ledig
319 --- E O F --- 2009-06-24 14:36