Den er helt gal!!! Startede op her til morgen, og der er virkeligt meget netaktivitet…..... DEN SENDER STADIG SPAM!!!
Håber sindssygt meget at I kan hjælpe….. Udover at Cybercity pr. brev har informeret os om at de lukker for forbindelsen hvis ikke problemet klares (hvilket er forståeligt nok), bliver min linie utroligt sløv.
Skal I have mere info om programmer, hvilket jeg vil have til at starte op osv?
Log fra combofix:
Partner - 06-11-23 7:56:02,35 Service Pack 2
ComboFix 06.11.22 - Running from: “C:\Documents and Settings\Partner\Skrivebord”
((((((((((((((((((((((((((((((( Files Created from 2006-10-23 to 2006-11-23 ))))))))))))))))))))))))))))))))))
2006-11-22 23:21 <DIR> d————C:\Programmer\LingvoSoft
2006-11-22 12:48 <DIR> d————C:\Documents and Settings\Partner\DoctorWeb
2006-11-21 16:46 <DIR> d————C:\WINDOWS\system32\LogFiles
2006-11-21 15:54 <DIR> d————C:\Documents and Settings\Partner\Application Data\Logitech
2006-11-21 14:16 <DIR> d————C:\WINDOWS\Temp
2006-11-21 14:09 94,208—a———C:\WINDOWS\KHALMNPR.Exe
2006-11-21 14:09 71,936—a———C:\WINDOWS\system32\drivers\LMouKE.Sys
2006-11-21 14:09 69,632—a———C:\WINDOWS\system32\KemXML.dll
2006-11-21 14:09 55,936—a———C:\WINDOWS\system32\drivers\L8042MOU.SYS
2006-11-21 14:09 3,712—a———C:\WINDOWS\system32\drivers\LBeepKE.sys
2006-11-21 14:09 155,648—a———C:\WINDOWS\system32\kemutb.dll
2006-11-21 14:09 131,072—a———C:\WINDOWS\system32\KemUtil.dll
2006-11-21 14:09 110,592—a———C:\WINDOWS\system32\KemWnd.dll
2006-11-21 14:09 <DIR> d————C:\Programmer\Logitech
2006-11-20 19:51 24,576—a———C:\WINDOWS\system32\STKIT432.DLL
2006-11-20 14:43 816,672—a———C:\WINDOWS\system32\drivers\avg7core.sys
2006-11-20 14:43 4,224—a———C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-11-20 14:43 3,968—a———C:\WINDOWS\system32\drivers\avgclean.sys
2006-11-20 14:43 28,416—a———C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-11-20 14:43 18,240—a———C:\WINDOWS\system32\drivers\avgmfx86.sys
2006-11-20 14:43 <DIR> d————C:\Documents and Settings\Partner\Application Data\AVG7
2006-11-20 14:43 <DIR> d————C:\Documents and Settings\All Users\Application Data\Grisoft
2006-11-20 13:32 <DIR> d————C:\Programmer\ewido
2006-11-20 13:20 208,896—a———C:\WINDOWS\system32\nvudisp.exe
2006-11-20 13:19 208,896—a———C:\WINDOWS\system32\NVUNINST.EXE
2006-11-19 16:41 <DIR> d————C:\WINDOWS\system32\ActiveScan
2006-11-15 21:06 <DIR> d————C:\Documents and Settings\Partner\Application Data\iPodder
2006-11-14 10:55 <DIR> d————C:\WINDOWS\Internet Logs
2006-11-14 10:13 <DIR> d————C:\WINDOWS\LastGood
2006-11-14 09:53 <DIR> d————C:\Programmer\GiPo@Utilities
2006-11-14 09:53 <DIR> d————C:\Programmer\F‘lles filer\Gibinsoft Shared
2006-11-14 09:49 <DIR> d————C:\Programmer\Lavasoft
2006-11-11 17:30 76,560—a———C:\WINDOWS\system32\drivers\tmcomm.sys
2006-11-11 08:59 <DIR> d————C:\WINDOWS\LastGood.Tmp
2006-11-11 08:54 <DIR> d—hs——C:\WINDOWS\CSC
2006-11-10 11:58 <DIR> d————C:\Programmer\Softwin
2006-11-10 11:58 <DIR> d————C:\Programmer\F‘lles filer\Softwin
2006-11-10 11:53 <DIR> d————C:\Documents and Settings\All Users\Application Data\Avg7
2006-11-04 14:14 1,245,696—a———C:\WINDOWS\system32\msxml4.dll
2006-11-01 13:09 5,120—a———C:\WINDOWS\system32\ff_vfw.dll
2006-11-01 13:09 <DIR> d————C:\Programmer\ffdshow
2006-10-27 21:45 <DIR> d————C:\Documents and Settings\Partner\Application Data\Media Player Classic
2006-10-27 20:59 <DIR> d————C:\Documents and Settings\All Users\Application Data\nView_Profiles
2006-10-27 20:57 <DIR> d————C:\WINDOWS\nview
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
Rootkit driver pe386 is present. A rootkit scan is required
2006-11-21 17:03————d————C:\Documents and Settings\Partner\Application Data\Azureus
2006-11-21 14:09————d————C:\Programmer\F‘lles filer\Logitech
2006-11-20 14:28————d————C:\Programmer\Grisoft
2006-11-19 17:07————d————C:\Programmer\WinRAR
2006-11-19 17:06————d————C:\Programmer\Internet Explorer
2006-11-14 09:53————d————C:\Programmer\F‘lles filer
2006-11-14 09:50————d————C:\Documents and Settings\Partner\Application Data\Lavasoft
2006-11-11 23:04 188468—a———C:\Programmer\serial.zip
2006-11-11 23:04 188468—a———C:\Programmer\serial.dat
2006-11-10 14:08 24064—a———C:\WINDOWS\system32\drivers\SysTool.sys
2006-10-27 21:12————d————C:\Programmer\Windows Media Player
2006-10-22 12:22 888832—a———C:\WINDOWS\system32\nvmobls.dll
2006-10-22 12:22 86016—a———C:\WINDOWS\system32\nvmctray.dll
2006-10-22 12:22 81920—a———C:\WINDOWS\system32\nvwddi.dll
2006-10-22 12:22 794624—a———C:\WINDOWS\system32\nvcplui.exe
2006-10-22 12:22 7700480—a———C:\WINDOWS\system32\nvcpl.dll
2006-10-22 12:22 581632—a———C:\WINDOWS\system32\nvhwvid.dll
2006-10-22 12:22 5644288—a———C:\WINDOWS\system32\nvoglnt.dll
2006-10-22 12:22 5619712—a———C:\WINDOWS\system32\nvdisps.dll
2006-10-22 12:22 5255168—a———C:\WINDOWS\system32\nvdispsr.dll
2006-10-22 12:22 466944—a———C:\WINDOWS\system32\nvshell.dll
2006-10-22 12:22 458752—a———C:\WINDOWS\system32\nvmccssr.dll
2006-10-22 12:22 4527488—a———C:\WINDOWS\system32\nv4_disp.dll
2006-10-22 12:22 45056—a———C:\WINDOWS\system32\nvmccsrs.dll
2006-10-22 12:22 442368—a———C:\WINDOWS\system32\nvappbar.exe
2006-10-22 12:22 425984—a———C:\WINDOWS\system32\keystone.exe
2006-10-22 12:22 3994624—a———C:\WINDOWS\system32\drivers\nv4_mini.sys
2006-10-22 12:22 35840—a———C:\WINDOWS\system32\nvcodins.dll
2006-10-22 12:22 35840—a———C:\WINDOWS\system32\nvcod.dll
2006-10-22 12:22 335872—a———C:\WINDOWS\system32\nvwrses.dll
2006-10-22 12:22 335872—a———C:\WINDOWS\system32\nvwrsel.dll
2006-10-22 12:22 327680—a———C:\WINDOWS\system32\nvwrsfr.dll
2006-10-22 12:22 327680—a———C:\WINDOWS\system32\nvwrsesm.dll
2006-10-22 12:22 323584—a———C:\WINDOWS\system32\nvwrspt.dll
2006-10-22 12:22 323584—a———C:\WINDOWS\system32\nvwrsit.dll
2006-10-22 12:22 323584—a———C:\WINDOWS\system32\nvrshe.dll
2006-10-22 12:22 323584—a———C:\WINDOWS\system32\nvrsar.dll
2006-10-22 12:22 3203072—a———C:\WINDOWS\system32\nvgamesr.dll
2006-10-22 12:22 319488—a———C:\WINDOWS\system32\nvwrsptb.dll
2006-10-22 12:22 319488—a———C:\WINDOWS\system32\nvwrsnl.dll
2006-10-22 12:22 315392—a———C:\WINDOWS\system32\nvwrsru.dll
2006-10-22 12:22 315392—a———C:\WINDOWS\system32\nvwrshu.dll
2006-10-22 12:22 311296—a———C:\WINDOWS\system32\nvwrsde.dll
2006-10-22 12:22 311296—a———C:\WINDOWS\system32\nvexpbar.dll
2006-10-22 12:22 3047424—a———C:\WINDOWS\system32\nvgames.dll
2006-10-22 12:22 303104—a———C:\WINDOWS\system32\nvwrstr.dll
2006-10-22 12:22 303104—a———C:\WINDOWS\system32\nvwrssl.dll
2006-10-22 12:22 303104—a———C:\WINDOWS\system32\nvwrsfi.dll
2006-10-22 12:22 299008—a———C:\WINDOWS\system32\nvwrssk.dll
2006-10-22 12:22 299008—a———C:\WINDOWS\system32\nvwrsno.dll
2006-10-22 12:22 2973696—a———C:\WINDOWS\system32\nvvitvsr.dll
2006-10-22 12:22 294912—a———C:\WINDOWS\system32\nvwrssv.dll
2006-10-22 12:22 294912—a———C:\WINDOWS\system32\nvwrspl.dll
2006-10-22 12:22 294912—a———C:\WINDOWS\system32\nvwrsda.dll
2006-10-22 12:22 2924544—a———C:\WINDOWS\system32\nvvitvs.dll
2006-10-22 12:22 286720—a———C:\WINDOWS\system32\nvwrseng.dll
2006-10-22 12:22 286720—a———C:\WINDOWS\system32\nvwrscs.dll
2006-10-22 12:22 286720—a———C:\WINDOWS\system32\nvnt4cpl.dll
2006-10-22 12:22 2859008—a———C:\WINDOWS\system32\nvmoblsr.dll
2006-10-22 12:22 282624—a———C:\WINDOWS\system32\nvwrsar.dll
2006-10-22 12:22 278528—a———C:\WINDOWS\system32\nvwrshe.dll
2006-10-22 12:22 278528—a———C:\WINDOWS\system32\nvrsfr.dll
2006-10-22 12:22 274432—a———C:\WINDOWS\system32\nvrsit.dll
2006-10-22 12:22 274432—a———C:\WINDOWS\system32\nvrses.dll
2006-10-22 12:22 274432—a———C:\WINDOWS\system32\nvrsel.dll
2006-10-22 12:22 270336—a———C:\WINDOWS\system32\nvrsde.dll
2006-10-22 12:22 266240—a———C:\WINDOWS\system32\nvrspt.dll
2006-10-22 12:22 266240—a———C:\WINDOWS\system32\nvrsnl.dll
2006-10-22 12:22 266240—a———C:\WINDOWS\system32\nvrsesm.dll
2006-10-22 12:22 262144—a———C:\WINDOWS\system32\nvrsru.dll
2006-10-22 12:22 262144—a———C:\WINDOWS\system32\nvrsptb.dll
2006-10-22 12:22 262144—a———C:\WINDOWS\system32\nvrsja.dll
2006-10-22 12:22 258048—a———C:\WINDOWS\system32\nvrsko.dll
2006-10-22 12:22 253952—a———C:\WINDOWS\system32\nvrshu.dll
2006-10-22 12:22 249856—a———C:\WINDOWS\system32\nvrstr.dll
2006-10-22 12:22 249856—a———C:\WINDOWS\system32\nvrssl.dll
2006-10-22 12:22 249856—a———C:\WINDOWS\system32\nvrssk.dll
2006-10-22 12:22 249856—a———C:\WINDOWS\system32\nvrspl.dll
2006-10-22 12:22 249856—a———C:\WINDOWS\system32\nvrsno.dll
2006-10-22 12:22 245760—a———C:\WINDOWS\system32\nvrssv.dll
2006-10-22 12:22 245760—a———C:\WINDOWS\system32\nvrsda.dll
2006-10-22 12:22 241664—a———C:\WINDOWS\system32\nvrsfi.dll
2006-10-22 12:22 241664—a———C:\WINDOWS\system32\nvrseng.dll
2006-10-22 12:22 241664—a———C:\WINDOWS\system32\nvrscs.dll
2006-10-22 12:22 229376—a———C:\WINDOWS\system32\nvmccs.dll
2006-10-22 12:22 221184—a———C:\WINDOWS\system32\nvrszhc.dll
2006-10-22 12:22 212992—a———C:\WINDOWS\system32\nvwrsja.dll
2006-10-22 12:22 212992—a———C:\WINDOWS\system32\nvapi.dll
2006-10-22 12:22 196608—a———C:\WINDOWS\system32\nvwrsko.dll
2006-10-22 12:22 188416—a———C:\WINDOWS\system32\nvmccss.dll
2006-10-22 12:22 1732608—a———C:\WINDOWS\system32\nvwssr.dll
2006-10-22 12:22 167936—a———C:\WINDOWS\system32\nvwrszht.dll
2006-10-22 12:22 1662976—a———C:\WINDOWS\system32\nvwdmcpl.dll
2006-10-22 12:22 163840—a———C:\WINDOWS\system32\nvwrszhc.dll
2006-10-22 12:22 1622016—a———C:\WINDOWS\system32\nwiz.exe
2006-10-22 12:22 159810—a———C:\WINDOWS\system32\nvsvc32.exe
2006-10-22 12:22 147456—a———C:\WINDOWS\system32\nvcolor.exe
2006-10-22 12:22 1470464—a———C:\WINDOWS\system32\nview.dll
2006-10-22 12:22 1339392—a———C:\WINDOWS\system32\nvdspsch.exe
2006-10-22 12:22 1236992—a———C:\WINDOWS\system32\nvwss.dll
2006-10-22 12:22 118784—a———C:\WINDOWS\system32\nvrszht.dll
2006-10-22 12:22 1019904—a———C:\WINDOWS\system32\nvwimg.dll
2006-10-22 12:22 1011712—a———C:\WINDOWS\system32\nvcpluir.dll
2006-10-17 12:33 6049280————- C:\WINDOWS\system32\ieframe.dll
2006-10-17 12:33 50688————- C:\WINDOWS\system32\msfeedsbs.dll
2006-10-17 12:33 458752————- C:\WINDOWS\system32\msfeeds.dll
2006-10-17 12:33 413696—a———C:\WINDOWS\system32\vbscript.dll
2006-10-17 12:33 231424—a———C:\WINDOWS\system32\webcheck.dll
2006-10-17 12:33 180736————- C:\WINDOWS\system32\ieui.dll
2006-10-17 12:33 156160—a———C:\WINDOWS\system32\msls31.dll
2006-10-17 12:06 78336—a———C:\WINDOWS\system32\ieencode.dll
2006-10-17 12:05 40960—a———C:\WINDOWS\system32\licmgr10.dll
2006-10-17 12:05 206336————- C:\WINDOWS\system32\WinFXDocObj.exe
2006-10-17 12:05 105984—a———C:\WINDOWS\system32\url.dll
2006-10-17 12:04 101376—a———C:\WINDOWS\system32\occache.dll
2006-10-17 12:03 17408—a———C:\WINDOWS\system32\corpol.dll
2006-10-17 12:01 71680—a———C:\WINDOWS\system32\admparse.dll
2006-10-17 12:01 55296—a———C:\WINDOWS\system32\iesetup.dll
2006-10-17 12:01 382976—a———C:\WINDOWS\system32\iedkcs32.dll
2006-10-17 12:01 229376—a———C:\WINDOWS\system32\ieaksie.dll
2006-10-17 12:01 152064—a———C:\WINDOWS\system32\ieakeng.dll
2006-10-17 12:01 13312—a———C:\WINDOWS\system32\ieudinit.exe
2006-10-17 12:00 54784—a———C:\WINDOWS\system32\ie4uinit.exe
2006-10-17 12:00 43008—a———C:\WINDOWS\system32\iernonce.dll
2006-10-17 12:00 123904—a———C:\WINDOWS\system32\advpack.dll
2006-10-17 11:58 61952————- C:\WINDOWS\system32\icardie.dll
2006-10-17 11:58 12288————- C:\WINDOWS\system32\msfeedssync.exe
2006-10-17 11:57 36352—a———C:\WINDOWS\system32\imgutil.dll
2006-10-17 11:57 266752————- C:\WINDOWS\system32\iertutil.dll
2006-10-17 11:56 45568—a———C:\WINDOWS\system32\mshta.exe
2006-10-17 11:28 48128—a———C:\WINDOWS\system32\mshtmler.dll
2006-10-17 11:27 380928————- C:\WINDOWS\system32\ieapfltr.dll
2006-10-17 11:23 161792—a———C:\WINDOWS\system32\ieakui.dll
2006-10-13 13:39 65536—a———C:\WINDOWS\system32\nwwks.dll
2006-10-13 13:39 64000—a———C:\WINDOWS\system32\nwapi32.dll
2006-10-13 13:39 142848—a———C:\WINDOWS\system32\nwprovau.dll
2006-10-13 11:23 163584—a———C:\WINDOWS\system32\drivers\nwrdr.sys
2006-10-12 08:08————d————C:\Programmer\Linksys Wireless-G PCI Wireless Network Monitor
2006-10-12 08:08————d————C:\Programmer\Google
2006-10-11 18:49————d—h——- C:\Programmer\InstallShield Installation Information
2006-10-11 11:21————d————C:\Programmer\MSN Messenger
2006-10-10 11:28 0—a———C:\wuxlbsl.exe
2006-10-10 11:27 0—a———C:\yidknjo.exe
2006-10-10 11:27 0—a———C:\rtos.exe
2006-10-10 11:27 0—a———C:\kosjlqeb.exe
2006-10-10 11:27 0—a———C:\jojg.exe
2006-10-10 11:26 0—a———C:\vesuyym.exe
2006-10-10 11:26 0—a———C:\sfokuk.exe
2006-10-10 11:26 0—a———C:\rrhedgnt.exe
2006-10-10 11:26 0—a———C:\exwfrso.exe
2006-10-10 11:07————d—-s——C:\Documents and Settings\Partner\Application Data\Microsoft
2006-10-10 10:57————d————C:\Programmer\Microsoft Games
2006-10-05 09:01————d————C:\Documents and Settings\Partner\Application Data\Skype
2006-10-04 08:15————d————C:\Programmer\Webteh
2006-10-02 12:48————d————C:\Documents and Settings\Partner\Application Data\Adobe
2006-10-02 12:24————d————C:\Programmer\F‘lles filer\Adobe Systems Shared
2006-10-02 12:24————d————C:\Programmer\F‘lles filer\Adobe
2006-09-27 13:38————d————C:\Programmer\Microsoft ActiveSync
2006-09-27 13:06————d————C:\Programmer\WIDCOMM
2006-09-26 10:26————d————C:\Programmer\PDAmill
2006-09-26 10:09————d————C:\Programmer\ePocket Solutions ASA
2006-09-13 06:06 1084416—a———C:\WINDOWS\system32\msxml3.dll
2006-09-06 16:43 22752—a———C:\WINDOWS\system32\spupdsvc.exe
2006-09-04 10:20 2508—a———C:\Documents and Settings\Partner\Application Data\$_hpcst$.hpc
2006-08-25 16:51 617472—a———C:\WINDOWS\system32\comctl32.dll
2006-08-14 10:26 94080—a—c—- C:\Documents and Settings\Partner\Application Data\ezplay.sys
2006-08-14 10:26 81920—a—c—- C:\Documents and Settings\Partner\Application Data\ezpinst.exe
2006-08-14 10:26 7176—a—c—- C:\Documents and Settings\Partner\Application Data\pcouffin.cat
2006-08-14 10:26 7172—a—c—- C:\Documents and Settings\Partner\Application Data\ezplay.cat
2006-08-14 10:26 47360—a—c—- C:\Documents and Settings\Partner\Application Data\pcouffin.sys
2006-08-14 10:26 34—a—c—- C:\Documents and Settings\Partner\Application Data\pcouffin.log
2006-08-14 10:26 34—a—c—- C:\Documents and Settings\Partner\Application Data\OFGWLYDA.log
2006-08-14 10:26 125—a—c—- C:\Documents and Settings\Partner\Application Data\OFGWLYDA.ini
2006-08-14 10:26 1144—a—c—- C:\Documents and Settings\Partner\Application Data\pcouffin.inf
2006-08-14 10:26 1103—a—c—- C:\Documents and Settings\Partner\Application Data\OFGWLYDA.inf
2006-08-03 10:37 62—ahs——C:\Documents and Settings\Partner\Application Data\desktop.ini
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
“H/PC Connection Agent”=”\“D:\\Programmer\\Microsoft ActiveSync\\wcescomm.exe\”“
“ctfmon.exe”=“C:\\WINDOWS\\system32\\ctfmon.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
“PrdgPan”=“PrdgPan.Exe”
“NvCplDaemon”=“RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup”
“nwiz”=“nwiz.exe /install”
“NvMediaCenter”=“RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit”
“AVG7_CC”=“C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP”
“RegistryMechanic”=”“
“Kernel and Hardware Abstraction Layer”=“KHALMNPR.EXE”
“Logitech Hardware Abstraction Layer”=”\“C:\\Programmer\\Fælles filer\\Logitech\\khalshared\\KHALMNPR.EXE\”“
@=”“
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
“Installed”=“1”
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
“Installed”=“1”
“NoChange”=“1”
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
“Installed”=“1”
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
“DeskHtmlVersion”=dword:00000110
“DeskHtmlMinorVersion”=dword:00000005
“Settings”=dword:00000001
“GeneralFlags”=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
“Source”=“About:Home”
“SubscribedURL”=“About:Home”
“FriendlyName”=“Min aktuelle startside”
“Flags”=dword:00000002
“Position”=hex:2c,00,00,00,10,01,00,00,00,00,00,00,40,04,00,00,e4,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
“CurrentState”=hex:04,00,00,40
“OriginalStateInfo”=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
“RestoredStateInfo”=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
“CTFMON.EXE”=“C:\\WINDOWS\\system32\\CTFMON.EXE”
“AVG7_Run”=“C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE”
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
“CTFMON.EXE”=“C:\\WINDOWS\\system32\\CTFMON.EXE”
“AVG7_Run”=“C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE”
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
“{438755C2-A8BA-11D1-B96B-00A0C90312E1}”=“Browseui preloader”
“{8C7461EF-2B13-11d2-BE35-3078302C2030}”=“Component Categories cache daemon”
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
“{AEB6717E-7E19-11d0-97EE-00C04FD91972}”=”“
“{54D9498B-CF93-414F-8984-8CE7FDE0D391}”=“ewido shell guard”
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
“NoDriveTypeAutoRun”=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“dontdisplaylastusername”=dword:00000000
“legalnoticecaption”=”“
“legalnoticetext”=”“
“shutdownwithoutlogon”=dword:00000001
“undockwithoutlogon”=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
“NoDriveTypeAutoRun”=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
“NoDriveTypeAutoRun”=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
“PostBootReminder”=”{7849596a-48ea-486e-8937-a2a3009f31a9}”
“CDBurn”=”{fbeb8a05-beee-4442-804e-409d6c4515e9}”
“WebCheck”=”{E6FB5E20-DE35-11CF-9C87-00AA005127ED}”
“SysTray”=”{35CEC8A3-2BE6-11D2-8773-92E220524153}”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Adobe Acrobat Speed Launcher.lnk]
“backup”=“C:\\WINDOWS\\pss\\Adobe Acrobat Speed Launcher.lnkCommon Startup”
“location”=“Common Startup”
“command”=“C:\\WINDOWS\\Installer\\{AC76BA86-1033-0000-7760-000000000002}\\SC_Acrobat.exe “
“item”=“Adobe Acrobat Speed Launcher”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Adobe Reader Hurtigstart.lnk]
“backup”=“C:\\WINDOWS\\pss\\Adobe Reader Hurtigstart.lnkCommon Startup”
“location”=“Common Startup”
“command”=“C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE “
“item”=“Adobe Reader Hurtigstart”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^hp psc 2000 Series.lnk]
“backup”=“C:\\WINDOWS\\pss\\hp psc 2000 Series.lnkCommon Startup”
“location”=“Common Startup”
“command”=“C:\\PROGRA~1\\HEWLET~1\\DIGITA~1\\bin\\hpobnz08.exe “
“item”=“hp psc 2000 Series”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^hpoddt01.exe.lnk]
“backup”=“C:\\WINDOWS\\pss\\hpoddt01.exe.lnkCommon Startup”
“location”=“Common Startup”
“command”=“C:\\PROGRA~1\\HEWLET~1\\DIGITA~1\\bin\\hpotdd01.exe “
“item”=“hpoddt01.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^RAID Manager.lnk]
“backup”=“C:\\WINDOWS\\pss\\RAID Manager.lnkCommon Startup”
“location”=“Common Startup”
“command”=“C:\\PROGRA~1\\ITE\\ITEIT8~1\\RaidMgr.exe “
“item”=“RAID Manager”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
“key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”
“item”=”“
“hkey”=“HKLM”
“command”=”“
“inimapping”=“0”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
“key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”
“item”=“Acrotray”
“hkey”=“HKLM”
“command”=”\“C:\\Programmer\\Adobe\\Acrobat 7.0\\Distillr\\Acrotray.exe\”“
“inimapping”=“0”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
“key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”
“item”=“NMBgMonitor”
“hkey”=“HKCU”
“command”=”\“C:\\Programmer\\Fælles filer\\Ahead\\lib\\NMBgMonitor.exe\”“
“inimapping”=“0”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\I downloaded pirated Software from P2P 2006]
“key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”
“item”=“Flight Simulator X”
“hkey”=“HKLM”
“command”=“Flight Simulator X”
“inimapping”=“0”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
“key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”
“item”=“msmsgs”
“hkey”=“HKCU”
“command”=”\“C:\\Programmer\\Messenger\\msmsgs.exe\” /background”
“inimapping”=“0”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
“key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”
“item”=“NeroCheck”
“hkey”=“HKLM”
“command”=“C:\\WINDOWS\\system32\\NeroCheck.exe”
“inimapping”=“0”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
“key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”
“item”=“NvCpl”
“hkey”=“HKLM”
“command”=“RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup”
“inimapping”=“0”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
“key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”
“item”=“qttask”
“hkey”=“HKLM”
“command”=”\“C:\\Programmer\\QuickTime\\qttask.exe\” -atboottime”
“inimapping”=“0”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
“key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”
“item”=“jusched”
“hkey”=“HKLM”
“command”=“C:\\Programmer\\Java\\jre1.5.0_06\\bin\\jusched.exe”
“inimapping”=“0”
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn\Event
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
“SecurityProviders”=“msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll”
Contents of the ‘Scheduled Tasks’ folder
C:\WINDOWS\tasks\At1.job
C:\WINDOWS\tasks\At2.job
C:\WINDOWS\tasks\At3.job
C:\WINDOWS\tasks\At4.job
C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 2170 series#1154636652.job
Completion time: 06-11-23 7:57:21.95
C:\ComboFix.txt ... 06-11-23 07:57