Jeg har vedlagt ComboFix filen.
ComboFix 10-09-01.03 - Peter 02-09-2010 9:57.1.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1252.45.1030.18.3567.2519 [GMT 2:00]
Kører fra: c:\users\Peter\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Install.exe
c:\windows\system32\%appdata%
.
((((((((((((((((((((((((((((( Filer skabt fra 2010-08-02 til 2010-09-02 )))))))))))))))))))))))))))))))))))
.
2010-09-02 08:02 . 2010-09-02 08:02 ———— d——-w- c:\users\Default\AppData\Local\temp
2010-09-01 17:51 . 2010-09-01 17:51 ———— d——-w- c:\program files\Imagenomic
2010-08-30 16:32 . 2010-08-30 16:32 ———— d——-w- c:\users\Peter\AppData\Roaming\Canneverbe Limited
2010-08-30 16:32 . 2010-08-30 16:32 ———— d——-w- c:\programdata\Canneverbe Limited
2010-08-30 16:30 . 2009-11-12 12:48 7168 ——a-w- c:\windows\system32\drivers\StarOpen.sys
2010-08-30 15:12 . 2010-08-30 15:13 ———— d——-w- c:\windows\WindowsMobile
2010-08-29 16:32 . 2010-08-29 16:38 97549 ——a-w- c:\windows\system32\drivers\klick.dat
2010-08-29 16:32 . 2010-08-29 16:38 113933 ——a-w- c:\windows\system32\drivers\klin.dat
2010-08-29 16:31 . 2010-08-29 16:31 ———— d——-w- c:\program files\Kaspersky Lab
2010-08-29 16:29 . 2010-08-29 16:29 ———— d——-w- c:\programdata\Kaspersky Lab Setup Files
2010-08-25 13:49 . 2010-04-07 07:10 571904 ——a-w- c:\windows\system32\oleaut32.dll
2010-08-23 12:48 . 2010-09-02 08:46 ———— d——-w- c:\program files\Keepit
2010-08-22 18:52 . 2010-08-22 18:54 ———— d——-w- c:\programdata\Apple Computer
2010-08-22 18:52 . 2010-08-22 18:53 ———— d——-w- c:\program files\QuickTime
2010-08-22 18:45 . 2010-08-22 18:45 ———— d——-w- c:\program files\Secunia
2010-08-19 14:48 . 2010-08-19 14:48 ———— d——-w- c:\program files\PhotomatixPro3
2010-08-18 17:30 . 2010-08-18 17:31 ———— d——-w- c:\programdata\PhotoStitch
2010-08-11 16:49 . 2010-08-11 16:50 ———— d——-w- c:\program files\EnhanceMySe7en
2010-08-03 16:10 . 2010-08-03 16:10 ———— d——-w- c:\program files\Microsoft Synchronization Services
2010-08-03 16:09 . 2010-08-03 16:09 ———— d——-w- c:\windows\PCHEALTH
2010-08-03 16:09 . 2010-08-03 16:09 ———— d——-w- c:\program files\Microsoft.NET
2010-08-03 16:09 . 2010-08-03 16:09 ———— d——-w- c:\program files\Microsoft Sync Framework
2010-08-03 16:09 . 2010-08-03 16:09 ———— d——-w- c:\program files\Microsoft SQL Server Compact Edition
2010-08-03 16:05 . 2010-08-03 16:05 ———— d——-w- c:\program files\Microsoft Analysis Services
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-02 08:47 . 2009-12-05 14:25 ———— d——-w- c:\users\Peter\AppData\Roaming\MailWasherPro
2010-09-02 08:47 . 2009-12-05 13:00 ———— d——-w- c:\users\Peter\AppData\Roaming\Dropbox
2010-09-02 08:45 . 2009-12-05 12:27 ———— d——-w- c:\programdata\Kaspersky Lab
2010-09-02 07:55 . 2010-04-20 15:28 ———— d——-w- c:\users\Peter\AppData\Roaming\TeraCopy
2010-08-31 18:23 . 2010-04-06 13:43 ———— d——-w- c:\program files\Malwarebytes’ Anti-Malware
2010-08-30 16:32 . 2009-12-05 15:03 ———— d——-w- c:\program files\CDBurnerXP
2010-08-30 15:12 . 2010-08-30 15:12 0 —-ha-w- c:\windows\system32\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
2010-08-30 15:09 . 2010-05-07 08:30 0 ——a-w- c:\users\Peter\temp.dat
2010-08-29 16:38 . 2010-06-28 17:47 283984 ——a-w- c:\programdata\Kaspersky Lab\AVP11\Bases\avengine.dll
2010-08-29 16:38 . 2010-08-29 16:38 404152 ——a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav11\11.0.1.400\mcouas.dll
2010-08-29 16:38 . 2010-08-29 16:38 166584 ——a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav11\11.0.1.400\klwtblc.dll
2010-08-29 16:38 . 2010-08-29 16:38 125624 ——a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav11\11.0.1.400\shellex.dll
2010-08-29 16:38 . 2010-08-29 16:38 113336 ——a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav11\11.0.1.400\sbstart.exe
2010-08-29 16:38 . 2010-08-29 16:38 404152 ——a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav11\11.0.1.400\mcouas.dll
2010-08-29 16:38 . 2010-08-29 16:38 129720 ——a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav11\11.0.1.400\shellex.dll
2010-08-29 16:38 . 2010-08-29 16:38 113336 ——a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav11\11.0.1.400\sbstart.exe
2010-08-29 16:38 . 2010-08-29 16:38 170680 ——a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav11\11.0.1.400\klwtblc.dll
2010-08-29 16:34 . 2010-08-29 16:34 283984 ——a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\bases\av\kdb\i386\win\avengine.dll
2010-08-25 14:23 . 2009-12-05 16:31 ———— d——-w- c:\program files\Canon
2010-08-25 14:04 . 2010-08-25 14:04 15376 ——a-w- c:\programdata\Kaspersky Lab\AVP9\Update distribution\AutoPatches\kav9exec\9.0.0.736\clldr.dll
2010-08-25 14:04 . 2010-08-25 14:04 15376 ——a-w- c:\programdata\Kaspersky Lab\AVP9\Update distribution\AutoPatches\kav9exec\9.0.0.459\clldr.dll
2010-08-24 14:06 . 2009-07-14 08:48 77544 ——a-w- c:\windows\system32\perfc006.dat
2010-08-24 14:06 . 2009-07-14 08:48 464072 ——a-w- c:\windows\system32\perfh006.dat
2010-08-19 19:31 . 2010-01-16 15:34 ———— d——-w- c:\program files\YouTube Downloader
2010-08-18 17:31 . 2010-05-31 17:19 ———— d——-w- c:\users\Peter\AppData\Roaming\Canon
2010-08-18 17:06 . 2010-08-18 17:06 340520 ——a-w- c:\programdata\Kaspersky Lab\AVP9\Update distribution\AutoPatches\kav9exec\9.0.0.736\avp.exe
2010-08-18 17:06 . 2010-08-18 17:06 311680 ——a-w- c:\programdata\Kaspersky Lab\AVP9\Update distribution\AutoPatches\kav9exec\9.0.0.459\avp.exe
2010-08-18 17:06 . 2010-08-18 17:06 254040 ——a-w- c:\programdata\Kaspersky Lab\AVP9\Update distribution\AutoPatches\kav9exec\9.0.0.736\x64\prloader.dll
2010-08-18 17:06 . 2010-08-18 17:06 248408 ——a-w- c:\programdata\Kaspersky Lab\AVP9\Update distribution\AutoPatches\kav9exec\9.0.0.459\x64\prloader.dll
2010-08-18 17:06 . 2010-08-18 17:06 170584 ——a-w- c:\programdata\Kaspersky Lab\AVP9\Update distribution\AutoPatches\kav9exec\9.0.0.736\prloader.dll
2010-08-18 17:06 . 2010-08-18 17:06 170584 ——a-w- c:\programdata\Kaspersky Lab\AVP9\Update distribution\AutoPatches\kav9exec\9.0.0.459\prloader.dll
2010-08-11 16:41 . 2009-12-05 12:38 ———— d——-w- c:\programdata\Microsoft Help
2010-08-10 15:20 . 2010-01-07 15:23 ———— d——-w- c:\program files\CrystalDiskInfo
2010-08-04 15:23 . 2009-12-05 14:15 111120 ——a-w- c:\users\Peter\AppData\Local\GDIPFONTCACHEV1.DAT
2010-08-03 16:30 . 2009-12-05 16:52 ———— d——-w- c:\program files\CCleaner
2010-08-03 16:10 . 2009-07-14 04:52 ———— d——-w- c:\program files\MSBuild
2010-08-01 16:11 . 2010-08-01 16:11 ———— d——-w- c:\program files\Common Files\Java
2010-08-01 16:11 . 2009-12-05 15:07 ———— d——-w- c:\program files\Java
2010-08-01 15:33 . 2010-05-02 15:47 292688 ——a-w- c:\programdata\Kaspersky Lab\AVP9\Update distribution\bases\av\kdb\x64\win\avengine.dll
2010-08-01 15:33 . 2010-05-02 15:47 283984 ——a-w- c:\programdata\Kaspersky Lab\AVP9\Update distribution\bases\av\kdb\i386\win\avengine.dll
2010-07-29 06:30 . 2010-08-11 16:36 197632 ——a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-11 16:36 82944 ——a-w- c:\windows\system32\iccvid.dll
2010-07-17 03:00 . 2010-04-22 15:05 423656 ——a-w- c:\windows\system32\deployJava1.dll
2010-07-07 15:11 . 2009-12-16 17:49 ———— d——-w- c:\users\Peter\AppData\Roaming\Skype
2010-07-07 15:11 . 2010-07-07 15:11 48 —-ha-w- c:\windows\system32\ezsidmv.dat
2010-07-07 15:11 . 2010-07-07 15:11 ———— d——-w- c:\users\Peter\AppData\Roaming\skypePM
2010-07-07 15:10 . 2010-07-07 15:10 ———— d——-w- c:\program files\Common Files\Skype
2010-07-07 15:10 . 2010-03-23 12:02 ———— d——-r- c:\program files\Skype
2010-07-07 15:10 . 2009-12-16 17:48 ———— d——-w- c:\programdata\Skype
2010-07-07 14:05 . 2010-07-07 14:05 14904 ——a-w- c:\windows\system32\drivers\psi_mf.sys
2010-07-01 19:35 . 2010-07-01 19:35 228024 ——a-w- c:\windows\system32\klogon.dll
2010-07-01 18:22 . 2010-07-01 18:22 92816 ——a-w- c:\programdata\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2011 11.0.1.400\English\setup.exe
2010-07-01 06:06 . 2010-07-01 06:06 1037648 ——a-w- c:\programdata\Kaspersky Lab\AVP11\Bases\klavasyswatch.dll
2010-06-30 06:25 . 2010-08-11 16:36 978432 ——a-w- c:\windows\system32\wininet.dll
2010-06-30 05:06 . 2010-06-30 05:06 271696 ——a-w- c:\programdata\Kaspersky Lab\AVP11\Bases\sys_critical_obj.dll
2010-06-22 02:47 . 2010-08-11 16:36 310784 ——a-w- c:\windows\system32\drivers\srv.sys
2010-06-22 02:47 . 2010-08-11 16:36 307200 ——a-w- c:\windows\system32\drivers\srv2.sys
2010-06-22 02:47 . 2010-08-11 16:36 113664 ——a-w- c:\windows\system32\drivers\srvnet.sys
2010-06-19 06:33 . 2010-08-11 16:36 3955080 ——a-w- c:\windows\system32\ntkrnlpa.exe
2010-06-19 06:33 . 2010-08-11 16:36 3899784 ——a-w- c:\windows\system32\ntoskrnl.exe
2010-06-19 06:23 . 2010-08-11 16:36 37376 ——a-w- c:\windows\system32\rtutils.dll
2010-06-19 04:07 . 2010-08-11 16:36 2326016 ——a-w- c:\windows\system32\win32k.sys
2010-06-16 05:48 . 2010-08-11 16:36 224256 ——a-w- c:\windows\system32\schannel.dll
2010-06-15 12:38 . 2010-06-15 12:38 133720 ——a-w- c:\programdata\Kaspersky Lab\AVP9\Update distribution\AutoPatches\kav9exec\9.0.0.736\mmpprtc.dll
2010-06-15 12:38 . 2010-06-15 12:38 129624 ——a-w- c:\programdata\Kaspersky Lab\AVP9\Update distribution\AutoPatches\kav9exec\9.0.0.459\mmpprtc.dll
2010-06-14 06:12 . 2010-08-11 16:36 1286016 ——a-w- c:\windows\system32\drivers\tcpip.sys
2010-06-09 15:43 . 2010-06-09 15:43 11352 ——a-w- c:\windows\system32\drivers\kl2.sys
2010-06-09 15:43 . 2010-06-09 15:43 132184 ——a-w- c:\windows\system32\drivers\kl1.sys
2010-06-08 06:02 . 2010-08-11 16:36 1233920 ——a-w- c:\windows\system32\msxml3.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 —sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 —sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@=”{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}”
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ——a-w- c:\users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@=”{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}”
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ——a-w- c:\users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@=”{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}”
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ——a-w- c:\users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“OfficeSyncProcess”=“c:\program files\Microsoft Office\Office14\MSOSYNC.EXE” [2010-03-16 718208]
“Sidebar”=“c:\program files\Windows Sidebar\sidebar.exe” [2009-07-14 1173504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Adobe Reader Speed Launcher”=“c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe” [2010-06-20 35760]
“Adobe ARM”=“c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe” [2010-06-09 976832]
“SunJavaUpdateSched”=“c:\program files\Common Files\Java\Java Update\jusched.exe” [2010-05-14 248552]
“BCSSync”=“c:\program files\Microsoft Office\Office14\BCSSync.exe” [2010-03-13 91520]
“QuickTime Task”=“c:\program files\QuickTime\QTTask.exe” [2010-08-10 421888]
“Windows Mobile Device Center”=“c:\windows\WindowsMobile\wmdc.exe” [2007-05-31 648072]
“avp”=“c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe” [2010-07-01 357096]
c:\users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
MailWasherPro.lnk - c:\program files\FireTrust\MailWasher Pro\MailWasher.exe [2009-12-5 19291304]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Keepit.lnk - c:\windows\Installer\{9C6FCA5D-F758-491E-9A69-F3E418C3784C}\KeepitIcon.exe [2010-8-23 87663]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“ConsentPromptBehaviorAdmin”= 0 (0x0)
“ConsentPromptBehaviorUser”= 3 (0x3)
“EnableLUA”= 0 (0x0)
“EnableUIADesktopToggle”= 0 (0x0)
“PromptOnSecureDesktop”= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
“NoUserFolderInStartMenu”= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
“AppInit_DLLs”=c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
“DisableMonitoring”=dword:00000001
R3 cpuz134;cpuz134;c:\users\Peter\AppData\Local\Temp\cpuz134\cpuz134_x32.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-07-07 14904]
R3 WatAdminSvc;Tjenesten Windows Aktivering;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-15 1343400]
S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2010-06-09 11352]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2010-04-22 22104]
S2 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-09-06 169312]
S2 Keepit;Keepit service;c:\program files\Keepit\K465I7KC.ver\keepit.exe [2010-09-01 962424]
S2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [2010-07-06 173352]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-02 19984]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Indhold af mappen ‘Planlagte Opgaver’
2010-06-15 c:\windows\Tasks\AWC Update.job
- c:\program files\IObit\Advanced SystemCare 3\IObitUpdate.exe [2009-12-06 09:08]
.
.
———- Yderligere scanning———-
.
uStart Page = hxxp://www.google.dk/
IE: E&ksporter; til Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Locate Spot on Map by GPS - c:\program files\Opanda\IExif 2.3\IExifMap.htm
IE: S&end; til OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
IE: View Exif/GPS/IPTC with IExif - c:\program files\Opanda\IExif 2.3\IExifCom.htm
Trusted Zone: danid.dk
Trusted Zone: danskebank.dk
Trusted Zone: danid.dk
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
DPF: {DC6FEBC5-0A2D-458A-A01B-5DB15EEC4305} - hxxp://webc.pjnet.dk/auth/controls/IlosoftImageUpload.dll
.
.
——————————- LÅSTE REGISTRERINGS NØGLER——————————-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@=“FlashBroker”
“LocalizedString”=”@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101”
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
“Enabled”=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@=“c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe”
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@=”{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@=“IFlashBroker4”
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@=”{00020424-0000-0000-C000-000000000046}”
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@=”{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”
“Version”=“1.0”
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
——————————- DLLs startet under kørende Processer——————————-
- - - - - - - > ‘Explorer.exe’(112)
c:\users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_dan.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
.
————————————Andre kørende processer————————————
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\taskhost.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\windows\system32\conhost.exe
c:\program files\Keepit\K465I7KC.ver\gui.exe
c:\windows\system32\WUDFHost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\sppsvc.exe
c:\windows\system32\msfeedssync.exe
.
**************************************************************************
.
Gennemført tid: 2010-09-02 10:50:48 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2010-09-02 08:50
Pre-Kørsel: 124.576.460.800 byte ledig
Post-Kørsel: 124.376.317.952 byte ledig
- - End Of File - - 94AC4CF0CE04DA1746C3FA92C2257767