Så kom den videre ![]()
ComboFix 11-12-24.01 - Nicolai Nielsen 24-12-2011 13:37:18.3.8 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.45.1033.18.6135.4252 [GMT 1:00]
Kører fra: c:\users\Nicolai Nielsen\Desktop\ComboFix.exe
Kommandoer benyttet :: c:\users\Nicolai Nielsen\Desktop\CFScript.txt
AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((( Filer skabt fra 2011-11-24 til 2011-12-24 )))))))))))))))))))))))))))))))))))
.
.
2011-12-24 14:01 . 2011-12-24 14:01 ———— d——-w- c:\users\UpdatusUser\AppData\Local\temp
2011-12-24 14:01 . 2011-12-24 14:01 ———— d——-w- c:\users\Default\AppData\Local\temp
2011-12-24 11:36 . 2011-11-30 01:21 8822856 ——a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BE4028D2-5F69-4D4C-800B-F448EFDF4EF9}\mpengine.dll
2011-12-23 08:37 . 2011-12-23 08:37 ———— d——-w- c:\users\Nicolai Nielsen\AppData\Local\CrashDumps
2011-12-22 20:30 . 2011-12-22 20:30 ———— d——-w- C:\_OTL
2011-12-22 20:10 . 2011-12-22 20:10 22 —sha-w- c:\users\Nicolai Nielsen\AppData\Roaming\Sys2662.Config.Repository.bin
2011-12-22 20:10 . 2011-12-22 20:10 ———— d——-w- c:\program files (x86)\jv16 PowerTools 2011
2011-12-21 17:46 . 2011-12-21 18:02 ———— d——-w- c:\users\Nicolai Nielsen\AppData\Local\NPE
2011-12-21 14:34 . 2011-12-22 18:36 43992 ——a-w- c:\program files (x86)\Mozilla Firefox\mozutils.dll
2011-12-21 14:34 . 2011-12-21 14:34 479232 ——a-w- c:\program files (x86)\Mozilla Firefox\msvcm80.dll
2011-12-21 14:34 . 2011-12-21 14:34 548864 ——a-w- c:\program files (x86)\Mozilla Firefox\msvcp80.dll
2011-12-21 14:34 . 2011-12-21 14:34 626688 ——a-w- c:\program files (x86)\Mozilla Firefox\msvcr80.dll
2011-12-21 14:29 . 2011-12-21 14:29 ———— d——-w- c:\users\Nicolai Nielsen\AppData\Local\Secunia PSI
2011-12-21 14:29 . 2011-12-21 14:29 ———— d——-w- c:\program files (x86)\Secunia
2011-12-21 12:32 . 2010-08-21 04:59 34152 ——a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2011-12-21 12:32 . 2011-12-21 13:52 174200 ——a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS
2011-12-21 12:32 . 2011-12-21 13:52 ———— d——-w- c:\program files\Symantec
2011-12-21 12:32 . 2011-12-21 12:32 ———— d——-w- c:\program files\Common Files\Symantec Shared
2011-12-21 12:32 . 2011-12-21 17:48 ———— d——-w- c:\windows\system32\drivers\N360x64
2011-12-21 12:32 . 2011-12-21 12:32 ———— d——-w- c:\program files (x86)\Norton 360
2011-12-21 12:32 . 2011-12-21 12:32 ———— d——-w- c:\program files (x86)\NortonInstaller
2011-12-18 15:06 . 2011-12-18 15:06 ———— d——-w- c:\users\Nicolai Nielsen\AppData\Roaming\Registry Mechanic
2011-12-18 15:05 . 2011-12-12 13:07 512472 ——a-w- c:\windows\SysWow64\msxml.dll
2011-12-18 15:05 . 2011-12-12 13:07 40408 ——a-w- c:\windows\system32\CleanMFT64.exe
2011-12-18 15:05 . 2008-09-17 21:17 658432 ——a-w- c:\windows\SysWow64\MSCOMCT2.OCX
2011-12-18 15:05 . 2008-04-02 15:54 1101824 ——a-w- c:\windows\SysWow64\UniBox210.ocx
2011-12-18 15:05 . 2008-04-02 15:53 212992 ——a-w- c:\windows\SysWow64\UniBoxVB12.ocx
2011-12-18 15:05 . 2008-04-02 15:53 880640 ——a-w- c:\windows\SysWow64\UniBox10.ocx
2011-12-18 15:04 . 2011-12-18 15:04 ———— d——-w- c:\program files (x86)\Common Files\PC Tools
2011-12-18 15:04 . 2011-12-18 15:04 ———— d——-w- c:\program files (x86)\PC Tools
2011-12-18 15:00 . 2011-12-18 15:00 ———— d——-w- c:\programdata\PC Tools
2011-12-18 14:59 . 2011-12-18 14:59 ———— d——-w- c:\users\Nicolai Nielsen\AppData\Roaming\Product_RM
2011-12-18 14:58 . 2011-12-18 14:58 ———— d——-w- c:\program files (x86)\Common Files\Java
2011-12-18 14:58 . 2011-12-18 14:58 476904 ——a-w- c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2011-12-18 11:03 . 2011-12-18 11:03 ———— d——-w- c:\program files (x86)\Microsoft WSE
2011-12-18 11:03 . 2008-09-04 18:17 447752 ——a-w- c:\windows\SysWow64\vp6vfw.dll
2011-12-14 20:41 . 2011-12-22 20:39 ———— d——-w- c:\users\Nicolai Nielsen\AppData\Local\assembly
2011-12-14 20:36 . 2011-12-14 20:36 ———— d——-w- c:\users\Nicolai Nielsen\AppData\Roaming\Microsoft Corporation
2011-12-14 20:27 . 2009-07-22 08:17 78872 ——a-w- c:\windows\system32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll
2011-12-14 20:27 . 2009-07-22 08:17 50200 ——a-w- c:\windows\SysWow64\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll
2011-12-14 20:27 . 2009-07-22 08:17 79896 ——a-w- c:\windows\SysWow64\perf-MSSQL$SQLEXPRESS-sqlctr10.1.2531.0.dll
2011-12-14 20:27 . 2009-07-22 08:17 111640 ——a-w- c:\windows\system32\perf-MSSQL$SQLEXPRESS-sqlctr10.1.2531.0.dll
2011-12-14 20:27 . 2011-12-14 20:27 ———— d——-w- c:\windows\system32\RsFx
2011-12-14 20:27 . 2011-12-14 20:27 ———— d——-w- c:\program files\Microsoft Visual Studio 9.0
2011-12-14 20:26 . 2011-12-14 20:26 ———— d——-w- c:\program files\Microsoft.NET
2011-12-14 20:25 . 2011-12-14 20:27 ———— d——-w- c:\program files\Microsoft SQL Server
2011-12-14 20:20 . 2011-12-14 20:20 ———— d——-w- c:\windows\symbols
2011-12-14 20:20 . 2011-12-14 20:20 ———— d——-w- c:\program files\Microsoft Help Viewer
2011-12-14 10:33 . 2011-11-24 04:52 3145216 ——a-w- c:\windows\system32\win32k.sys
2011-12-14 10:33 . 2011-10-26 05:21 43520 ——a-w- c:\windows\system32\csrsrv.dll
2011-12-14 10:33 . 2011-10-15 06:31 723456 ——a-w- c:\windows\system32\EncDec.dll
2011-12-14 10:33 . 2011-10-15 05:38 534528 ——a-w- c:\windows\SysWow64\EncDec.dll
2011-12-14 10:33 . 2011-11-05 05:32 2048 ——a-w- c:\windows\system32\tzres.dll
2011-12-14 10:33 . 2011-11-05 04:26 2048 ——a-w- c:\windows\SysWow64\tzres.dll
2011-12-01 11:47 . 2011-12-01 11:47 ———— d——-w- c:\users\Default\AppData\Local\Microsoft Help
2011-11-30 12:35 . 2011-11-30 12:35 ———— d——-w- C:\found.000
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-24 14:02 . 2011-12-24 14:02 69000 ——a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BE4028D2-5F69-4D4C-800B-F448EFDF4EF9}\offreg.dll
2011-12-21 14:30 . 2011-05-29 16:29 404640 ——a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-12-18 14:58 . 2011-05-29 22:44 472808 ——a-w- c:\windows\SysWow64\deployJava1.dll
2011-11-26 11:43 . 2011-05-29 16:49 280904 ——a-w- c:\windows\SysWow64\PnkBstrB.xtr
2011-11-26 11:43 . 2011-05-29 16:48 280904 ——a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-11-26 11:41 . 2011-05-29 16:48 189248 ——a-w- c:\windows\SysWow64\PnkBstrB.ex0
2011-11-26 11:41 . 2011-05-29 16:47 75136 ——a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-11-15 13:29 . 2011-05-29 16:35 270720 ———w- c:\windows\system32\MpSigStub.exe
2011-10-24 13:29 . 2011-10-24 13:29 94208 ——a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2011-10-24 13:29 . 2011-10-24 13:29 69632 ——a-w- c:\windows\SysWow64\QuickTime.qts
2011-10-15 08:53 . 2011-10-25 13:12 8791360 ——a-w- c:\windows\system32\nvwgf2umx.dll
2011-10-15 08:53 . 2011-10-25 13:12 7581504 ——a-w- c:\windows\system32\nvcuda.dll
2011-10-15 08:53 . 2011-10-25 13:12 68928 ——a-w- c:\windows\system32\OpenCL.dll
2011-10-15 08:53 . 2011-10-25 13:12 61248 ——a-w- c:\windows\SysWow64\OpenCL.dll
2011-10-15 08:53 . 2011-10-25 13:12 5578560 ——a-w- c:\windows\SysWow64\nvcuda.dll
2011-10-15 08:53 . 2011-10-25 13:12 2542912 ——a-w- c:\windows\system32\nvcuvid.dll
2011-10-15 08:53 . 2011-10-25 13:12 24796992 ——a-w- c:\windows\system32\nvcompiler.dll
2011-10-15 08:53 . 2011-10-25 13:12 2401088 ——a-w- c:\windows\SysWow64\nvcuvid.dll
2011-10-15 08:53 . 2011-10-25 13:12 2232128 ——a-w- c:\windows\system32\nvcuvenc.dll
2011-10-15 08:53 . 2011-10-25 13:12 2099520 ——a-w- c:\windows\SysWow64\nvcuvenc.dll
2011-10-15 08:53 . 2011-10-25 13:12 18871616 ——a-w- c:\windows\SysWow64\nvoglv32.dll
2011-10-15 08:53 . 2011-10-25 13:12 17248576 ——a-w- c:\windows\SysWow64\nvcompiler.dll
2011-10-15 08:53 . 2011-10-25 13:12 12971840 ——a-w- c:\windows\system32\drivers\nvlddmkm.sys
2011-10-15 08:53 . 2011-09-11 21:04 1533248 ——a-w- c:\windows\system32\nvdispco64.dll
2011-10-15 08:53 . 2011-09-11 21:04 1454400 ——a-w- c:\windows\system32\nvgenco64.dll
2011-10-15 08:53 . 2011-07-14 20:59 24742720 ——a-w- c:\windows\system32\nvoglv64.dll
2011-10-15 08:53 . 2011-07-14 20:59 15693120 ——a-w- c:\windows\system32\nvd3dumx.dll
2011-10-15 08:53 . 2011-05-29 16:17 7041856 ——a-w- c:\windows\SysWow64\nvwgf2um.dll
2011-10-15 08:53 . 2011-05-29 16:17 2808128 ——a-w- c:\windows\system32\nvapi64.dll
2011-10-15 08:53 . 2011-05-29 16:17 2458432 ——a-w- c:\windows\SysWow64\nvapi.dll
2011-10-15 08:53 . 2011-05-29 16:17 13205312 ——a-w- c:\windows\SysWow64\nvd3dum.dll
2011-10-15 08:53 . 2011-04-07 21:19 222528 ——a-w- c:\windows\system32\nvmctray.dll
2011-10-15 08:53 . 2011-04-07 21:19 837952 ——a-w- c:\windows\system32\easyupdatusapiu64.dll
2011-10-15 08:53 . 2011-04-07 21:19 1640768 ——a-w- c:\windows\system32\nvvsvc.exe
2011-10-15 08:53 . 2011-04-07 21:19 137536 ——a-w- c:\windows\system32\nvshext.dll
2011-10-15 08:53 . 2011-04-07 21:19 10406208 ——a-w- c:\windows\system32\nvcpl.dll
2011-10-15 08:53 . 2011-04-07 21:19 5067584 ——a-w- c:\windows\system32\nvsvc64.dll
2011-10-14 22:54 . 2011-10-14 22:54 321856 ——a-w- c:\windows\SysWow64\nvStreaming.exe
2011-09-29 16:29 . 2011-11-09 11:01 1923952 ——a-w- c:\windows\system32\drivers\tcpip.sys
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- c:\windows\system32\drivers\CM10664.sys—-
Company: C-Media Electronics Inc
File Description: C-Media Audio WDM Driver
File Version: 7.12.8.2140
Product Name: C-Media USB Audio Driver (WDM)
Copyright: Copyright (C) C-Media Electronics Inc. 1998-2007
Original Filename: CM106.SYS
File size: 1307648
Created time: 2009-09-30 02:04
Modified time: 2009-09-30 02:04
MD5: F9B3054339A71F16430F6585EBC8BE96
SHA1: B9680F8953EEA8CA950E4658504E00AFC48DDB09
.
——Directory of c:\users\Nicolai Nielsen\AppData\Local\{2DE709AD-AAE5-4909-93CA-190BBA08FD5B}——
.
.
——Directory of c:\users\Nicolai Nielsen\AppData\Local\{772FAAF3-38B4-44CA-8DAD-BDFF6E26E188}——
.
.
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ccleaner”=“c:\program files\CCleaner\CCleaner64.exe” [2011-07-25 4389696]
“Steam”=“f:\steam\steam.exe” [2011-09-04 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
“NUSB3MON”=“c:\program files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe” [2010-01-22 106496]
“SSDMonitor”=“c:\program files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe” [2011-12-12 103896]
“Adobe ARM”=“c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe” [2011-06-06 937920]
.
c:\users\Nicolai Nielsen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
CurseClientStartup.ccip [2011-8-9 0]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Google Calendar Sync.lnk - c:\program files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe [2011-4-8 542264]
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2011-10-14 291896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“ConsentPromptBehaviorAdmin”= 0 (0x0)
“ConsentPromptBehaviorUser”= 3 (0x3)
“EnableLUA”= 0 (0x0)
“EnableUIADesktopToggle”= 0 (0x0)
“PromptOnSecureDesktop”= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
“mixer6”=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Tjeneste (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-10-25 136176]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
R3 gupdatem;Google Update Tjeneste (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-10-25 136176]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys [x]
R3 RzSynapse;Razer Driver;c:\windows\system32\DRIVERS\RzSynapse.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 USBMULCD;USB Multi-Channel Audio Device Interface;c:\windows\system32\drivers\CM10664.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\users\NICOLA~1\AppData\Local\Temp\Rar$EX79.064\WinRing0x64.sys [x]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976]
R4 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [2011-12-12 793048]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [x]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
S0 Si3124r5;SiI-3124 SoftRaid 5 Controller;c:\windows\system32\DRIVERS\Si3124r5.sys [x]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS [x]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20111221.003\BHDrvx64.sys [2011-12-10 1156216]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20111223.001\IDSvia64.sys [2011-12-20 488568]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS [x]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\N360x64\0501000.01D\SYMNETS.SYS [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 N360;Norton 360;c:\program files (x86)\Norton 360\Engine\5.1.0.29\ccSvcHst.exe [2011-04-17 130008]
S2 OODefragAgent;O&O Defrag;c:\program files\OO Software\Defrag\oodag.exe [2011-06-29 3246920]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2011-10-14 994360]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2011-10-14 399416]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-12-21 138360]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [x]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 USBPNPA;USB PnP Sound Device Interface;c:\windows\system32\drivers\CM10864.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Indhold af mappen ‘Planlagte Opgaver’
.
2011-12-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-10-25 09:04]
.
2011-12-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-10-25 09:04]
.
2011-12-22 c:\windows\Tasks\RMSchedule.job
- c:\program files (x86)\PC Tools\PC Tools Registry Mechanic\RegMech.exe [2011-12-18 13:06]
.
.
————- x86-64—————-
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Launch LCore”=“c:\program files\Logitech Gaming Software\LCore.exe” [2011-06-14 110360]
“OODefragTray”=“c:\program files\OO Software\Defrag\oodtray.exe” [2011-06-29 3992904]
.
———- Yderligere scanning———-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&ksporter; til Microsoft Excel - c:\progra~2\MIF5BA~1\OFFICE11\EXCEL.EXE/3000
IE: E&xport; to Microsoft Excel - c:\progra~2\MIF5BA~1\Office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~2\MIF5BA~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 85.233.224.20 85.233.228.2
FF - ProfilePath - c:\users\Nicolai Nielsen\AppData\Roaming\Mozilla\Firefox\Profiles\zxsovoul.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.dk/
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\N360]
“ImagePath”=”\“c:\program files (x86)\Norton 360\Engine\5.1.0.29\ccSvcHst.exe\” /s \“N360\” /m \“c:\program files (x86)\Norton 360\Engine\5.1.0.29\diMaster.dll\” /prefetch:1”
.
——————————- LÅSTE REGISTRERINGS NØGLER——————————-
.
[HKEY_USERS\S-1-5-21-3378476827-1488579091-87155459-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (S-1-5-21-3378476827-1488579091-87155459-1000)
@Denied: (2) (LocalSystem)
“Progid”=“Outlook.File.eml.14”
.
[HKEY_USERS\S-1-5-21-3378476827-1488579091-87155459-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (S-1-5-21-3378476827-1488579091-87155459-1000)
@Denied: (2) (LocalSystem)
“Progid”=“Outlook.File.vcf.14”
.
[HKEY_USERS\S-1-5-21-3378476827-1488579091-87155459-1000\Software\SecuROM\License information*]
“datasecu”=hex:90,43,ec,78,6d,75,9e,e8,01,b3,d3,5a,2e,14,60,87,13,76,27,75,5e,
6a,b1,08,0f,2d,2a,b6,da,ef,c4,c9,ac,81,7b,02,a5,fe,57,af,82,54,31,80,d2,0f,\
“rkeysecu”=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@=“FlashBroker”
“LocalizedString”=”@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10y_ActiveX.exe,-101”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
“Enabled”=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10y_ActiveX.exe”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@=”{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@=“Shockwave Flash Object”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10y.ocx”
“ThreadingModel”=“Apartment”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@=“0”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@=“ShockwaveFlash.ShockwaveFlash.10”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10y.ocx, 1”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@=”{D27CDB6B-AE6D-11cf-96B8-444553540000}”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@=“1.0”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@=“ShockwaveFlash.ShockwaveFlash”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@=“Macromedia Flash Factory Object”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10y.ocx”
“ThreadingModel”=“Apartment”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@=“FlashFactory.FlashFactory.1”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10y.ocx, 1”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@=”{D27CDB6B-AE6D-11cf-96B8-444553540000}”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@=“1.0”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@=“FlashFactory.FlashFactory”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@=“IFlashBroker4”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@=”{00020424-0000-0000-C000-000000000046}”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@=”{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”
“Version”=“1.0”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
“OODEFRAG12.00.00.01PROFESSIONAL”=“A283BF92D49D8483CC2FE905351F2BCE6CA6F8FEB8A6C3CAAF9A371B13F7E024689B4FA286022232EEF658F1A87B6269DB10ABEB098DB8D706588984960A4934DAD019D65E3BE6FC811AAC47173A81A75199D9C17FDD67D994AB6576092F57BF1AE377BA57F95D66A1E32566066588A90838CBCF4E99E533D14F37516C83548AFA7B9A60DE95A4B29E82572E722A0AD66C4219E81FE9D90C68653CF8B5C61C9C039F05DA5886EDEA7E082B86CA5E2DD89F7430638E9B81CEB57108D34D60A1C26EBF914498EB7F5B776CDF57F0772F1EF7ED531B2A9D2CAACEFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A6A0AC4980AC7933FEBC9E127BECC74CA6171C11EC38DE3D44047DE85FDE4A4097016F7DFE8EAA1CBFEA6BD0E4335CC3BFDA32F4485730EE0FA5A33901B5BA133674F180EF7913A607AC68F4FC4AA63AD829C07E9DAE915A62C28F13F6BF0FC114A8324D7D257D6492895A63BAE9613D328927580E988EF58E0FC2918E2E515BAA5722ACEED9AF202360C62F0010B3F473229603B3665068C49441C4BAC8499FD20EB85930F335D75D633462D14E8C3C2BE7CAF54C00C48A1CAF97AE93E90505CCAE7004D0635D3D481BAD7859C798A2C8A77F1AB95E9D660E91D1465383D7B53D6E49CF842C3B3951604464E1394F6C2403F34D0290CE3FF9BE81775A96D78DA95944562467A5E349628A0B5D6CE60F75EBEE614F381287A20FBCA0A83BDD9F7FC9E823ABC1398D632598C3E1C45BB9D9A9389DEF8CE3E92E301C15689C89318BF34135397AD2B639FC8ADC26376D48D4599BBB54D50740A523BF9B617ABBBA04DD5C02916517974718FE18884C22D0C86A6B6913757F9D783CC66F05A69BEAFEDECD701EEBEC99EBF19A280AA2401900A0FAC767DA16C5F825573FE48A92A27627AADDE80A7FDC6D5F0438CDE9D41D2992A3ED2D8D57B0DDD99CAEB89FCFF7CC370D182350BDB27486E7649E68AE8D55AE41E6E728960BC12A425459F5C43443E517E49E62DBA18CE2743E6977E3CC78B1B52EBCD7E735A13CFB3B48B0A754025BE6FB56784FE3A5415F4ABD04CA72EDB164B774602444E109FCE1A786F20B94172789E360536915C65E81510F01CAF095B7E87F166980C6DC01BCBDC4E3BBE9E9FEAD877868D313E82ED0FC2F65542518999CED6518667C574531F5487D825579A07BA5B551F9BB720F1A3D0C1E430FCBFC9F764B55A5116F8B9CDF85852C8FC03C7CC6A094E590824331B36390FE96915634725989A4766C184BAC8386B9328C082B95D47ED5748B13E025066A238BA21E906038637B02EBB502345ECD603DFDC1F762049DBCAF554AE3F95B9CFE9E0B4F5F6120D3F4705EB176F043EE89158BA44721F04342F07938EDBE5AD9”
“OODEFRAG14.00.00.01PROFESSIONAL”=“96BF17107A03141FB5AB35577CDF1CD793934A44E92AD2EBBBCEE18AC22A9A07AAEE23912FB67901A640DC5B62196766A193A12F85C4B1D43757EE20BB5CEF9E288AEC56A70004C4FDF3B4B692F82BC1A4B22AD0192AA5A0AA196B1BE25763630455C50B7AB54B3FDFF6C46EA7D38BA18FB1C7215B4CF80C7E7EB10B334C89B9360CA17005E44F987670B995FCB20D935D4180A9CC505C2A9BE9C38D6D1C5AD638581A5D67CB6E4BED7AE8D734511C770C8B008BAF8FE1DE70AEC4D7935D33460BDCEBB9845EF02976A2C5F3B22086029D2894798A17036571927C31ECDBD2E5B2AE788305C47ED3C4EAEA3C2145FC3C15A8B13BA52A194A145456F78415FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A6A0AC4980AC7933FEBC9E127BECC74CA6171C11EC38DE3D084F625DD3E8DFBC0BAB256A879BAD215435F177EF735C4F10D0E3D4C2B743A37DB0028FDF5035985AA74008743EFE48CDD3826039727642EF15B1B842E799B358D961BBCD9B3BD2C3340CFAB9C6412E45BF529977F078BA08E255CE9855E936A2CB9FA9E90AD2E47B5515B69D089A0BB625FE62057BE6C93D272042DBDDBBBF4C5BDC14236E23FB19666E23886D6E4883802E71E42D8BB859A8E537C7F4D61126B0BEA88A3015F99616AE9C04EFEB8570A685EDBBB6EF830AFD00C1389F49A566C96F8C594C58745564F07342A17F14A43D33F5D1DEE6585F12CA6D3079E228A9F41D55E94FDEB418A6536B15A55C7AACBF649A14FD811BCFA52638D53039796B59F78E3A5DDD388588F8BCF6B6FAF4F9FB4E6012829B63B5CCF6127184A62F90EE3636ED2FCFAFA9860892021E166FDF16A740836B4EFCCBEEA6E4F2CE47115D8292414B0EF30373F3AB0EF4BD2C0F17832D2741CF7A6636C7A186EAF8FB9A7E34C815BD5BC949377491C3B68980283C8F1EF6455A45D579E6584810016A7E00FA1D8E54881B522C82EDB9CD0A9BC6CF59BD04B24496AF7DAFBF6ABB797B1F569CD2F9419D6F9C6CECF66D65DA4629B5D254984D629911915BCF24EB875D17D6B7349DDB351560F7D4E5CE4EAD92C0B744ACEE7E193F49E674061EC2667F313C3D8F2D20001F07B3AF7BC17C4551B500C617BA54603B5C12DBE1F6856518EE257036562B4064ABE447789C077A1A61A1C9E621FDC686018CC369C01FE3A004136C7DB6414DFC22B83AA42E2BB9C8D20E90F338516DDC23B4B5A5021C5BD5DAEC9BBF61479248EFBC784AB547827CCC20309A1046893E61CA0C21B3B054B70E7D40595ECA10E7CC664A3865DFEA9745139639297B64ED1174F66EC430EC0E6E726E2DA7785743288BC7C1E89D194266077F33F630DA7538BCFAA01795585F00DF8FA0AC259182A2E85F3C584BCA661081FE”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
“Solution”=”{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
“Key”=“ActionsPane3”
“Location”=“c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd”
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
————————————Andre kørende processer————————————
.
c:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
Gennemført tid: 2011-12-24 15:04:01 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2011-12-24 14:04
ComboFix2.txt 2011-12-22 20:42
.
Pre-Kørsel: 13.472.071.680 bytes free
Post-Kørsel: 13.109.428.224 bytes free
.
- - End Of File - - 6D33D9E71ABCA091C137F44B4B47C7EE
