ComboFix 10-04-03.01 - Inger Clausen 03-04-2010 19:19:11.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.45.1030.18.1503.1182 [GMT 2:00]
Kører fra: c:\documents and settings\Inger Clausen\Skrivebord\banan.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\AppPatch\AcAdProc.dll
.
((((((((((((((((((((((((((((( Filer skabt fra 2010-03-03 til 2010-04-03 )))))))))))))))))))))))))))))))))))
.
2010-04-02 10:20 . 2010-04-02 10:20 -------- d-----w- c:\windows\system32\XPSViewer
2010-04-02 10:20 . 2010-04-02 10:20 -------- d-----w- c:\programmer\MSBuild
2010-04-02 10:19 . 2010-04-02 10:19 -------- d-----w- c:\programmer\Reference Assemblies
2010-04-02 10:19 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-04-02 10:18 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-04-02 10:18 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-04-02 10:18 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-04-02 10:18 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-04-02 10:18 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-04-02 10:18 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-04-02 10:18 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-04-02 10:18 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-04-02 10:18 . 2010-04-02 10:19 -------- d-----w- C:\7b9e93011a8f7d5c9b81c7ca
2010-04-01 15:17 . 2010-04-03 15:40 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-04-01 15:03 . 2010-04-01 15:03 -------- d-----w- c:\documents and settings\Inger Clausen\DoctorWeb
2010-03-31 22:19 . 2010-03-31 22:19 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-03-31 22:19 . 2010-03-31 22:19 -------- d-----w- c:\programmer\SUPERAntiSpyware
2010-03-31 22:19 . 2010-03-31 22:19 -------- d-----w- c:\documents and settings\Inger Clausen\Application Data\SUPERAntiSpyware.com
2010-03-31 21:25 . 2010-03-31 22:18 -------- d-----w- c:\programmer\Fælles filer\Wise Installation Wizard
2010-03-31 21:09 . 2010-03-31 21:09 -------- d-----w- c:\programmer\Fælles filer\Java
2010-03-29 18:57 . 2010-03-29 18:57 -------- d-----w- c:\programmer\CCleaner
2010-03-29 18:04 . 2010-03-29 18:04 -------- d-----w- c:\documents and settings\Inger Clausen\Application Data\Malwarebytes
2010-03-29 18:03 . 2010-01-07 14:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-29 18:03 . 2010-03-29 18:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-29 18:03 . 2010-01-07 14:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-29 18:03 . 2010-03-29 18:04 -------- d-----w- c:\programmer\Malwarebytes' Anti-Malware
2010-03-29 17:39 . 2010-03-29 17:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Driver Whiz
2010-03-29 16:12 . 2010-03-29 16:12 -------- d-sh--w- c:\documents and settings\Inger Clausen\IECompatCache
2010-03-29 15:57 . 2001-10-04 14:35 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2010-03-29 15:57 . 2001-10-04 14:35 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-03-29 15:57 . 2008-04-13 17:45 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2010-03-29 15:57 . 2008-04-13 17:45 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-03-12 10:56 . 2010-03-12 10:56 -------- d-----w- c:\documents and settings\Default User\Lokale indstillinger\Application Data\Microsoft Help
2010-03-11 11:16 . 2009-08-06 18:23 215920 ----a-w- c:\windows\system32\muweb.dll
2010-03-11 11:16 . 2009-08-06 18:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-03-11 11:01 . 2006-10-26 18:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2010-03-11 11:01 . 2008-11-10 10:41 32656 ----a-w- c:\windows\system32\msonpmon.dll
2010-03-11 10:48 . 2010-03-11 10:48 -------- d-----w- c:\documents and settings\Inger Clausen\Lokale indstillinger\Application Data\Microsoft Help
2010-03-11 10:47 . 2010-03-28 10:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-03-11 10:46 . 2010-03-11 10:46 -------- d-----r- C:\MSOCache
2010-03-11 09:47 . 2010-03-11 09:52 -------- d-----w- c:\programmer\PhotoFiltre
2010-03-10 14:54 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-02 10:28 . 2002-09-16 12:00 79002 ----a-w- c:\windows\system32\perfc006.dat
2010-04-02 10:28 . 2002-09-16 12:00 450630 ----a-w- c:\windows\system32\perfh006.dat
2010-03-31 22:20 . 2010-03-31 22:20 52224 ----a-w- c:\documents and settings\Inger Clausen\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-03-31 22:20 . 2010-03-31 22:20 117760 ----a-w- c:\documents and settings\Inger Clausen\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-03-31 21:08 . 2010-03-31 21:08 503808 ----a-w- c:\documents and settings\Inger Clausen\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-79ab4f56-n\msvcp71.dll
2010-03-31 21:08 . 2010-03-31 21:08 499712 ----a-w- c:\documents and settings\Inger Clausen\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-79ab4f56-n\jmc.dll
2010-03-31 21:08 . 2010-03-31 21:08 348160 ----a-w- c:\documents and settings\Inger Clausen\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-79ab4f56-n\msvcr71.dll
2010-03-31 21:08 . 2010-03-31 21:08 12800 ----a-w- c:\documents and settings\Inger Clausen\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6ced8ac7-n\decora-d3d.dll
2010-03-31 21:08 . 2010-03-31 21:08 61440 ----a-w- c:\documents and settings\Inger Clausen\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6ced8ac7-n\decora-sse.dll
2010-03-31 21:07 . 2009-02-25 20:38 -------- d-----w- c:\programmer\Java
2010-03-29 15:56 . 2009-06-18 06:55 -------- d-----w- c:\documents and settings\Inger Clausen\Application Data\OpenOffice.org2
2010-03-28 10:43 . 2009-02-25 18:10 74240 ----a-w- c:\documents and settings\Inger Clausen\Lokale indstillinger\Application Data\GDIPFONTCACHEV1.DAT
2010-03-27 21:55 . 2009-02-26 22:01 -------- d-----w- c:\programmer\McAfee
2010-03-19 14:23 . 2009-06-18 07:08 1 ----a-w- c:\documents and settings\Inger Clausen\Application Data\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2010-03-13 10:40 . 2009-03-18 12:11 -------- d-----w- c:\programmer\Microsoft Works
2010-03-13 08:16 . 2009-02-26 22:21 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2010-03-11 09:59 . 2009-02-28 07:57 -------- d-----w- c:\programmer\Google
2010-03-09 02:28 . 2009-02-25 20:38 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-02-27 16:02 . 2009-05-27 12:58 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLdw.DAT
2010-02-25 06:18 . 2006-06-23 12:27 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-19 23:47 . 2010-02-19 23:47 3604480 ----a-w- c:\windows\system32\GPhotos.scr
2010-02-12 11:29 . 2009-02-25 20:42 -------- d-----w- c:\programmer\Fælles filer\Adobe
2010-02-07 15:35 . 2010-02-07 15:35 -------- d-----w- c:\programmer\MSXML 4.0
2010-02-06 09:38 . 2010-02-06 09:38 49152 -c--a-r- c:\documents and settings\Inger Clausen\Application Data\Microsoft\Installer\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\ARPPRODUCTICON.exe
2010-02-06 09:38 . 2010-02-06 09:38 335872 -c--a-r- c:\documents and settings\Inger Clausen\Application Data\Microsoft\Installer\{237CD223-1B9D-47E8-A76C-E478B83CCEA2}\ARPPRODUCTICON.exe
2010-02-06 09:38 . 2009-05-27 12:59 -------- d-----w- c:\programmer\Fælles filer\Nikon
2010-02-06 09:37 . 2010-02-06 09:37 57344 -c--a-r- c:\documents and settings\Inger Clausen\Application Data\Microsoft\Installer\{87441A59-5E64-4096-A170-14EFE67200C3}\ARPPRODUCTICON.exe
2010-01-30 14:22 . 2010-02-06 11:37 2195878 ----a-w- c:\programmer\Stiftdamer og snebillleder 2010 123.jpg
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-03-31 2010864]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mcagent_exe"="c:\programmer\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"SunJavaUpdateSched"="c:\programmer\Fælles filer\Java\Java Update\jusched.exe" [2010-02-18 248040]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmer\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21 548352 ----a-w- c:\programmer\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^Inger Clausen^Menuen Start^Programmer^Start^OpenOffice.org 2.4.lnk]
path=c:\documents and settings\Inger Clausen\Menuen Start\Programmer\Start\OpenOffice.org 2.4.lnk
backup=c:\windows\pss\OpenOffice.org 2.4.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 14:57 948672 ----a-r- c:\programmer\Fælles filer\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 00:57 35760 ----a-w- c:\programmer\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus DX6000 Series]
2006-02-13 04:00 131072 ----a-w- c:\windows\system32\spool\drivers\w32x86\3\E_FATIBIE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 16:05 1695232 ----a-w- c:\programmer\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\Caplio Software\\RGateLXP.exe"=
"c:\\Programmer\\Messenger\\msmsgs.exe"=
"c:\\Programmer\\Fælles filer\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Programmer\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R1 SASDIFSV;SASDIFSV;c:\programmer\SUPERAntiSpyware\sasdifsv.sys [17-02-2010 11:25 12872]
R1 SASKUTIL;SASKUTIL;c:\programmer\SUPERAntiSpyware\SASKUTIL.SYS [17-02-2010 11:15 66632]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\programmer\McAfee\SiteAdvisor\McSACore.exe [27-02-2009 00:08 210216]
R3 SASENUM;SASENUM;c:\programmer\SUPERAntiSpyware\SASENUM.SYS [17-02-2010 11:15 12872]
.
Indhold af mappen 'Planlagte Opgaver'
2009-02-26 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-02-26 10:22]
2010-03-31 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-02-26 10:22]
2010-04-03 c:\windows\Tasks\Søg efter opdateringer til Windows Live Toolbar.job
- c:\programmer\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 10:20]
2010-04-03 c:\windows\Tasks\User_Feed_Synchronization-{72F21307-83D1-463C-B771-9C75853FCECD}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.dk/uDefault_Search_URL =
hxxp://www.google.com/ieuSearchAssistant =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: &Windows Live Search - c:\programmer\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: danskebank.dk
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cabDPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cabDPF: {D8575CE3-3432-4540-88A9-85A1325D3375} -
hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-04-03 19:34
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- DLLs startet under kørende Processer ---------------------
- - - - - - - > 'winlogon.exe'(616)
c:\programmer\SUPERAntiSpyware\SASWINLO.dll
- - - - - - - > 'explorer.exe'(1620)
c:\programmer\McAfee\SiteAdvisor\saHook.dll
c:\windows\system32\webcheck.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\programmer\Java\jre6\bin\jqs.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\FLLESF~1\mcafee\mna\mcnasvc.exe
c:\progra~1\FLLESF~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
c:\programmer\McAfee\MPF\MPFSrv.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
.
**************************************************************************
.
Gennemført tid: 2010-04-03 19:43:39 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2010-04-03 17:43
Pre-Kørsel: 18.241.908.736 byte ledig
Post-Kørsel: 18.425.200.640 byte ledig
- - End Of File - - 0730DAA418F89EC7EE9C54F4BB781975