This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ping.exe at 100% CPU usage

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OS: Windows XP Pro SP3 32-bit
CPU: Intel Pentium D CPU 3,40 GHz
Browser: Opera 11.51.1087.0
AntiVirus: AVG Free 10.0.1392
Firewall: ZoneAlarm Free 9.2.106.0




Hello everyone at WhatTheTech.

Lately, ping.exe has begun to continuosly pop up and use 100% of my CPU, causing my PC to run slowly and, eventually, crash. Ending it in Task Manager does not help as it just pops back up again after a few seconds. I have run CCleaner and Malwarebyte's AntiMalware and of course a scan with AVG, but to no avail.

I hope one of you can help me.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:21:03, on 17-09-2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Programmer\AVG\AVG10\avgwdsvc.exe
C:\Programmer\Bonjour\mDNSResponder.exe
C:\Programmer\Uniblue\RegistryBooster\rbmonitor.exe
C:\Programmer\Canon\IJPLM\IJPLMSVC.EXE
C:\Programmer\Java\jre6\bin\jqs.exe
C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
C:\Programmer\Nero\Update\NASvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\TomTom HOME 2\TomTomHOMEService.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\MouseWare\system\em_exec.exe
C:\Programmer\AVG\AVG10\avgtray.exe
C:\Programmer\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programmer\Siemens\Gigaset USB Adapter 300\GUI.exe
C:\Programmer\AVG\AVG10\avgnsx.exe
C:\Programmer\AVG\AVG10\avgemcx.exe
C:\Programmer\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Programmer\AVG\AVG10\avgcsrvx.exe
C:\Programmer\Opera\opera.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\msiexec.exe
C:\Programmer\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Programmer\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmer\AVG\AVG10\avgssie.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmer\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [nwiz] C:\Programmer\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG_TRAY] C:\Programmer\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Smart File Advisor] "C:\Programmer\Smart File Advisor\sfa.exe" /checkassoc
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Fælles filer\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Programmer\Fælles filer\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Gigaset WLAN Adapter Monitor.lnk = C:\Programmer\Siemens\Gigaset USB Adapter 300\GUI.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1299919826410
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmer\AVG\AVG10\avgpp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmer\Fælles filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Programmer\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Programmer\AVG\AVG10\avgwdsvc.exe
O23 - Service: Bonjour tjeneste (Bonjour Service) - Apple Inc. - C:\Programmer\Bonjour\mDNSResponder.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Programmer\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmer\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
O23 - Service: @C:\Programmer\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Programmer\Nero\Update\NASvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Programmer\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 7041 bytes


Thank you for your time.
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)










  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Hello mowman.

I have run TDSSKiller:

2011/09/18 16:33:38.0078 1960 TDSS rootkit removing tool 2.5.22.0 Sep 13 2011 15:55:17
2011/09/18 16:33:38.0859 1960 ================================================================================
2011/09/18 16:33:38.0859 1960 SystemInfo:
2011/09/18 16:33:38.0859 1960
2011/09/18 16:33:38.0859 1960 OS Version: 5.1.2600 ServicePack: 3.0
2011/09/18 16:33:38.0859 1960 Product type: Workstation
2011/09/18 16:33:38.0859 1960 ComputerName: PANIC
2011/09/18 16:33:38.0859 1960 UserName: Nicole & Paw
2011/09/18 16:33:38.0859 1960 Windows directory: C:\WINDOWS
2011/09/18 16:33:38.0859 1960 System windows directory: C:\WINDOWS
2011/09/18 16:33:38.0859 1960 Processor architecture: Intel x86
2011/09/18 16:33:38.0859 1960 Number of processors: 2
2011/09/18 16:33:38.0859 1960 Page size: 0x1000
2011/09/18 16:33:38.0859 1960 Boot type: Normal boot
2011/09/18 16:33:38.0859 1960 ================================================================================
2011/09/18 16:33:39.0281 1960 Initialize success
2011/09/18 16:33:51.0796 3088 ================================================================================
2011/09/18 16:33:51.0796 3088 Scan started
2011/09/18 16:33:51.0796 3088 Mode: Manual;
2011/09/18 16:33:51.0796 3088 ================================================================================
2011/09/18 16:33:53.0250 3088 ACPI (991b6d6fe2a4d70caf76c41334e60926) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/09/18 16:33:53.0312 3088 ACPIEC (6f99fe216de8c4875dbb12937620da0c) C:\WINDOWS\system32\drivers\ACPIEC.sys
2011/09/18 16:33:53.0406 3088 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/09/18 16:33:53.0453 3088 AegisP (15e655baa989444f56787ef558823643) C:\WINDOWS\system32\DRIVERS\AegisP.sys
2011/09/18 16:33:53.0515 3088 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
2011/09/18 16:33:54.0062 3088 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/09/18 16:33:54.0109 3088 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/09/18 16:33:54.0203 3088 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/09/18 16:33:54.0281 3088 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/09/18 16:33:54.0359 3088 AVGIDSDriver (2d18221aab3db2d408d6c55c0f23090a) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys
2011/09/18 16:33:54.0421 3088 AVGIDSEH (1af676db3f3d4cc709cfab2571cf5fc3) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys
2011/09/18 16:33:54.0468 3088 AVGIDSFilter (4c51e233c87f9ec7598551de554bc99d) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys
2011/09/18 16:33:54.0531 3088 AVGIDSShim (c3fc426e54f55c1cc3219e415b88e10c) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys
2011/09/18 16:33:54.0593 3088 Avgldx86 (4e796d3d2c3182b13b3e3b5a2ad4ef0a) C:\WINDOWS\system32\DRIVERS\avgldx86.sys
2011/09/18 16:33:54.0640 3088 Avgmfx86 (5639de66b37d02bd22df4cf3155fba60) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
2011/09/18 16:33:54.0687 3088 Avgrkx86 (d1baf652eda0ae70896276a1fb32c2d4) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
2011/09/18 16:33:54.0765 3088 Avgtdix (aaf0ebcad95f2164cffb544e00392498) C:\WINDOWS\system32\DRIVERS\avgtdix.sys
2011/09/18 16:33:54.0875 3088 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/09/18 16:33:54.0937 3088 BIOS (be5d50529799b9bab6be879ec768b6cf) C:\WINDOWS\System32\drivers\BIOS.sys
2011/09/18 16:33:55.0312 3088 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/09/18 16:33:55.0437 3088 CBPSp50 (1961590aa191b6b7dcf18a6a693af7b8) C:\WINDOWS\system32\Drivers\CBPSp50.sys
2011/09/18 16:33:55.0578 3088 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/09/18 16:33:55.0625 3088 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/09/18 16:33:55.0687 3088 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/09/18 16:33:56.0125 3088 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/09/18 16:33:56.0218 3088 dmboot (8a3088f97b2caa3340bbb068f314e596) C:\WINDOWS\system32\drivers\dmboot.sys
2011/09/18 16:33:56.0281 3088 dmio (6d152a2781ffbd6a63a1e58801240e8e) C:\WINDOWS\system32\drivers\dmio.sys
2011/09/18 16:33:56.0328 3088 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/09/18 16:33:56.0421 3088 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/09/18 16:33:56.0578 3088 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/09/18 16:33:56.0656 3088 dtsoftbus01 (555e54ac2f601a8821cef58961653991) C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys
2011/09/18 16:33:56.0953 3088 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/09/18 16:33:57.0015 3088 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
2011/09/18 16:33:57.0078 3088 FET5X86V (4580f83e94774aa1724179a6a97e25e6) C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys
2011/09/18 16:33:57.0109 3088 FETND5BV (4580f83e94774aa1724179a6a97e25e6) C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys
2011/09/18 16:33:57.0187 3088 FETNDIS (e9648254056bce81a85380c0c3647dc4) C:\WINDOWS\system32\DRIVERS\fetnd5.sys
2011/09/18 16:33:57.0250 3088 Fips (bb52a20854cf3e8e0474ee7167c7a3a5) C:\WINDOWS\system32\drivers\Fips.sys
2011/09/18 16:33:57.0281 3088 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
2011/09/18 16:33:57.0343 3088 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/09/18 16:33:57.0406 3088 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/09/18 16:33:57.0468 3088 Ftdisk (0a58505b5d0aba661d2ff59cd8cf79b9) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/09/18 16:33:57.0546 3088 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
2011/09/18 16:33:57.0625 3088 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/09/18 16:33:57.0687 3088 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2011/09/18 16:33:57.0765 3088 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/09/18 16:33:57.0921 3088 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/09/18 16:33:58.0093 3088 i8042prt (42f890598efb480076558ca3cc151107) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/09/18 16:33:58.0187 3088 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/09/18 16:33:58.0453 3088 IntcAzAudAddService (60d7460b07012d364ced11dd9fd83e1f) C:\WINDOWS\system32\drivers\RtkHDAud.sys
2011/09/18 16:33:58.0687 3088 intelppm (d1cd31b6cd4a99f3b82aec84cfdd4cba) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/09/18 16:33:58.0750 3088 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/09/18 16:33:58.0812 3088 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/09/18 16:33:58.0875 3088 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/09/18 16:33:58.0937 3088 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/09/18 16:33:59.0000 3088 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/09/18 16:33:59.0046 3088 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/09/18 16:33:59.0109 3088 isapnp (3ce6ec5903c59223b61f6a0b9b84b022) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/09/18 16:33:59.0171 3088 Kbdclass (32e823dfd0a7f18cf3b024f78c7aa7dd) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/09/18 16:33:59.0218 3088 kbdhid (530d40f58095397b6b8aa5a0fdd074a5) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
2011/09/18 16:33:59.0281 3088 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/09/18 16:33:59.0343 3088 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/09/18 16:33:59.0500 3088 LHidFlt2 (63b00a26f62572e0d58e6c8d3b32bf59) C:\WINDOWS\system32\DRIVERS\LHidFlt2.Sys
2011/09/18 16:33:59.0562 3088 LHidUsb (ac05a1b5c66d693b1598fd83617d1820) C:\WINDOWS\system32\Drivers\LHidUsb.Sys
2011/09/18 16:33:59.0640 3088 LMouFlt2 (03abef1a29addc98c32ed0f336b98e90) C:\WINDOWS\system32\DRIVERS\LMouFlt2.Sys
2011/09/18 16:33:59.0718 3088 MBAMSwissArmy (b18225739ed9caa83ba2df966e9f43e8) C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011/09/18 16:33:59.0796 3088 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/09/18 16:33:59.0859 3088 Modem (67ac997db66fdfd07738df58b45cd1b9) C:\WINDOWS\system32\drivers\Modem.sys
2011/09/18 16:33:59.0906 3088 Mouclass (22774a2ab832972eca2ce227819f5af0) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/09/18 16:33:59.0968 3088 mouhid (39f0a46109b167707018e8889d5fec93) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/09/18 16:34:00.0000 3088 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/09/18 16:34:00.0093 3088 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/09/18 16:34:00.0156 3088 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/09/18 16:34:00.0250 3088 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/09/18 16:34:00.0328 3088 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/09/18 16:34:00.0375 3088 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/09/18 16:34:00.0421 3088 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/09/18 16:34:00.0500 3088 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/09/18 16:34:00.0546 3088 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
2011/09/18 16:34:00.0671 3088 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/09/18 16:34:00.0734 3088 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/09/18 16:34:00.0781 3088 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/09/18 16:34:00.0812 3088 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/09/18 16:34:00.0859 3088 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/09/18 16:34:00.0921 3088 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/09/18 16:34:00.0968 3088 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/09/18 16:34:01.0109 3088 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/09/18 16:34:01.0187 3088 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/09/18 16:34:01.0265 3088 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/09/18 16:34:01.0578 3088 nv (bccced4253057e51782eee166d2ced3c) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/09/18 16:34:01.0859 3088 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/09/18 16:34:01.0890 3088 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/09/18 16:34:01.0968 3088 Parport (9e048790f33fe5f4fa9d27b5650a1dd5) C:\WINDOWS\system32\DRIVERS\parport.sys
2011/09/18 16:34:02.0000 3088 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/09/18 16:34:02.0109 3088 ParVdm (48e97af5b876301131e9d1b0c43212c3) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/09/18 16:34:02.0171 3088 PCI (5d756da95bd1e2f6e495704715532fdc) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/09/18 16:34:02.0265 3088 PCIIde (69ce0d409c11347196147ea4c6c02364) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/09/18 16:34:02.0343 3088 Pcmcia (e980b6d0ca6acba679a0ac810ab9a57c) C:\WINDOWS\system32\drivers\Pcmcia.sys
2011/09/18 16:34:02.0750 3088 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/09/18 16:34:02.0812 3088 Processor (ed3cc89af43fb4baa963da18f7474681) C:\WINDOWS\system32\DRIVERS\processr.sys
2011/09/18 16:34:02.0875 3088 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/09/18 16:34:02.0921 3088 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/09/18 16:34:02.0984 3088 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/09/18 16:34:03.0453 3088 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/09/18 16:34:03.0515 3088 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/09/18 16:34:03.0640 3088 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/09/18 16:34:03.0734 3088 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/09/18 16:34:03.0843 3088 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/09/18 16:34:03.0890 3088 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/09/18 16:34:03.0953 3088 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/09/18 16:34:04.0093 3088 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/09/18 16:34:04.0187 3088 redbook (d2ea9dae9a9f1bf40c0ea1d1d7c5592c) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/09/18 16:34:04.0328 3088 rt2870 (8d9e1bcb72eec1d2f9496c8b28da70b2) C:\WINDOWS\system32\DRIVERS\rt2870.sys
2011/09/18 16:34:04.0437 3088 SCDEmu (20b2751cd4c8f3fd989739ca661b9f30) C:\WINDOWS\system32\drivers\SCDEmu.sys
2011/09/18 16:34:04.0531 3088 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/09/18 16:34:04.0656 3088 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2011/09/18 16:34:04.0687 3088 Serial (680ed46039ebd4c23eb708f1af6b9e5d) C:\WINDOWS\system32\DRIVERS\serial.sys
2011/09/18 16:34:04.0812 3088 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/09/18 16:34:05.0031 3088 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/09/18 16:34:05.0093 3088 sr (b3ecb8b07f7991132c71c1b16a82ffe3) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/09/18 16:34:05.0156 3088 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/09/18 16:34:05.0234 3088 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/09/18 16:34:05.0281 3088 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/09/18 16:34:05.0546 3088 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/09/18 16:34:05.0671 3088 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/09/18 16:34:05.0781 3088 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/09/18 16:34:05.0843 3088 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/09/18 16:34:05.0906 3088 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/09/18 16:34:06.0281 3088 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/09/18 16:34:06.0796 3088 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/09/18 16:34:07.0125 3088 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/09/18 16:34:07.0468 3088 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/09/18 16:34:07.0812 3088 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/09/18 16:34:07.0890 3088 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2011/09/18 16:34:07.0953 3088 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/09/18 16:34:08.0015 3088 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/09/18 16:34:08.0062 3088 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/09/18 16:34:08.0125 3088 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/09/18 16:34:08.0171 3088 viaagp1 (4b039bbd037b01f5db5a144c837f283a) C:\WINDOWS\system32\DRIVERS\viaagp1.sys
2011/09/18 16:34:08.0218 3088 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
2011/09/18 16:34:08.0265 3088 videX32 (4cc623591204acd5fc89bd0dad70e838) C:\WINDOWS\system32\DRIVERS\videX32.sys
2011/09/18 16:34:08.0312 3088 VolSnap (69d9e1de5f897580f8b1d1957528b0b2) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/09/18 16:34:08.0375 3088 vsdatant (050c38ebb22512122e54b47dc278bccd) C:\WINDOWS\system32\vsdatant.sys
2011/09/18 16:34:08.0500 3088 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/09/18 16:34:08.0609 3088 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/09/18 16:34:08.0875 3088 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/09/18 16:34:08.0921 3088 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/09/18 16:34:09.0000 3088 xfilt (a1b2b0211441f9c822f8cbc0c2d1b41e) C:\WINDOWS\system32\DRIVERS\xfilt.sys
2011/09/18 16:34:09.0093 3088 MBR (0x1B8) (d2e8e277fd7d1ba18a24f713136056ad) \Device\Harddisk0\DR0
2011/09/18 16:34:09.0109 3088 \Device\Harddisk0\DR0 - detected Rootkit.Win32.TDSS.tdl4 (0)
2011/09/18 16:34:09.0140 3088 Boot (0x1200) (60ba5e00e27d688edb4a9d78c7292e08) \Device\Harddisk0\DR0\Partition0
2011/09/18 16:34:09.0203 3088 Boot (0x1200) (d89408675bfbab1541b91077539e2e4b) \Device\Harddisk0\DR0\Partition1
2011/09/18 16:34:09.0218 3088 ================================================================================
2011/09/18 16:34:09.0218 3088 Scan finished
2011/09/18 16:34:09.0218 3088 ================================================================================
2011/09/18 16:34:09.0265 1332 Detected object count: 1
2011/09/18 16:34:09.0265 1332 Actual detected object count: 1
2011/09/18 16:34:47.0875 1332 \Device\Harddisk0\DR0 (Rootkit.Win32.TDSS.tdl4) - will be cured after reboot
2011/09/18 16:34:47.0875 1332 \Device\Harddisk0\DR0 - ok
2011/09/18 16:34:47.0875 1332 Rootkit.Win32.TDSS.tdl4(\Device\Harddisk0\DR0) - User select action: Cure
2011/09/18 16:35:00.0515 0176 Deinitialize success


And OTL:

OTL logfile created on: 18-09-2011 16:43:18 - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Nicole & Paw\Skrivebord\Ny mappe\Diverse
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000406 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy

2,00 Gb Total Physical Memory | 1,37 Gb Available Physical Memory | 68,70% Memory free
3,85 Gb Paging File | 3,29 Gb Available in Paging File | 85,53% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmer
Drive C: | 127,99 Gb Total Space | 66,66 Gb Free Space | 52,08% Space Free | Partition Type: NTFS
Drive G: | 170,10 Gb Total Space | 170,02 Gb Free Space | 99,95% Space Free | Partition Type: NTFS

Computer Name: PANIC | User Name: Nicole & Paw | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Nicole & Paw\Skrivebord\Ny mappe\Diverse\OTL.exe (OldTimer Tools)
PRC - C:\Programmer\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Programmer\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Programmer\Opera\opera.exe (Opera Software)
PRC - C:\Programmer\Uniblue\RegistryBooster\rbmonitor.exe (Uniblue Systems Limited)
PRC - C:\Programmer\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Programmer\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Programmer\Fælles filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Programmer\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Programmer\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Programmer\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Programmer\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Programmer\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
PRC - C:\Programmer\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Programmer\Nero\Update\NASvc.exe (Nero AG)
PRC - C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Programmer\Siemens\Gigaset USB Adapter 300\GUI.exe ()
PRC - C:\Programmer\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Programmer\MouseWare\system\EM_EXEC.EXE (Logitech Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\PDFShell.DAN ()
MOD - C:\Programmer\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
MOD - C:\Programmer\Siemens\Gigaset USB Adapter 300\GUI.exe ()
MOD - C:\Programmer\Siemens\Gigaset USB Adapter 300\WPSdll.dll ()
MOD - C:\Programmer\Siemens\Gigaset USB Adapter 300\Ralink.dll ()
MOD - C:\Programmer\Siemens\Gigaset USB Adapter 300\PcaNdis.dll ()
MOD - C:\Programmer\Siemens\Gigaset USB Adapter 300\Helper.dll ()
MOD - C:\Programmer\Siemens\Gigaset USB Adapter 300\GenChip.dll ()
MOD - C:\Programmer\Canon\IJPLM\ijplmsvc.exe ()
MOD - C:\Programmer\Siemens\Gigaset USB Adapter 300\DHook.dll ()
MOD - C:\Programmer\Siemens\Gigaset USB Adapter 300\acAuth.dll ()


========== Win32 Services (SafeList) ==========

SRV - (helpsvc) – File not found
SRV - (AppMgmt) – File not found
SRV - (AVGIDSAgent) – C:\Programmer\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (Apple Mobile Device) – C:\Programmer\Fælles filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (TomTomHOMEService) – C:\Programmer\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (vsmon) – C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (avgwd) – C:\Programmer\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (NAUpdate) – C:\Programmer\Nero\Update\NASvc.exe (Nero AG)
SRV - (LightScribeService) – C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (IJPLMSVC) – C:\Programmer\Canon\IJPLM\ijplmsvc.exe ()


========== Driver Services (SafeList) ==========

DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (dtsoftbus01) – C:\WINDOWS\system32\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (SCDEmu) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (xfilt) – C:\WINDOWS\System32\DRIVERS\xfilt.sys (VIA Technologies,Inc)
DRV - (videX32) – C:\WINDOWS\System32\DRIVERS\videX32.sys (VIA Technologies, Inc.)
DRV - (rt2870) – C:\WINDOWS\system32\drivers\rt2870.sys (Ralink Technology, Corp.)
DRV - (CBPSp50) – C:\WINDOWS\system32\drivers\CBPSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (BIOS) – C:\WINDOWS\system32\drivers\BIOS.sys (BIOSTAR Group)
DRV - (viaagp1) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (LMouFlt2) – C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (LHidUsb) – C:\WINDOWS\system32\drivers\LHidUsb.sys (Logitech, Inc.)
DRV - (LHidFlt2) – C:\WINDOWS\system32\drivers\LHidFlt2.Sys (Logitech, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.7.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0.2

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Programmer\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Programmer\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Programmer\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programmer\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programmer\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Programmer\AVG\AVG10\Firefox4\ [2011-09-17 13:06:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Programmer\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011-06-26 13:15:54 | 000,000,000 | —D | M]

[2011-06-08 09:09:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Nicole & Paw\Application Data\Mozilla\Extensions
[2011-06-08 09:09:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Nicole & Paw\Application Data\Mozilla\Extensions\[removed]
[2011-06-08 09:09:30 | 000,000,000 | —D | M] (Map status indicator) – C:\PROGRAMMER\TOMTOM HOME 2\XUL\EXTENSIONS\[removed]

Hosts file not found
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Programmer\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmer\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Adobe ARM] C:\Programmer\Fælles filer\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG_TRAY] C:\Programmer\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Logitech Utility] C:\WINDOWS\LOGI_MWX.EXE (Logitech Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Programmer\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [Smart File Advisor] C:\Programmer\Smart File Advisor\sfa.exe (Filefacts.net)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programmer\Fælles filer\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - Startup: C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Gigaset WLAN Adapter Monitor.lnk = C:\Programmer\Siemens\Gigaset USB Adapter 300\GUI.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programmer\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1299919826410 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E06429AA-174A-4F29-8932-E378FAF8D011}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmer\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Min aktuelle startside) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Landskab.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Landskab.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011-03-11 23:28:38 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: helpsvc - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011-09-17 17:20:14 | 000,000,000 | —D | C] – C:\Programmer\Trend Micro
[2011-09-17 17:20:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Nicole & Paw\Menuen Start\Programmer\HiJackThis
[2011-09-12 22:25:13 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011-09-12 17:34:52 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011-09-12 17:34:52 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011-09-12 17:34:52 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011-09-12 17:34:52 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011-09-12 17:34:33 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011-09-12 17:16:39 | 000,000,000 | —D | C] – C:\Qoobox
[2011-09-12 17:16:30 | 000,000,000 | R–D | C] – C:\Documents and Settings\Nicole & Paw\Menuen Start\Programmer\Administration
[2011-09-12 17:15:46 | 004,203,777 | R— | C] (Swearware) – C:\Documents and Settings\Nicole & Paw\Skrivebord\Agurk.exe
[2011-09-11 12:32:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Nicole & Paw\Application Data\Malwarebytes
[2011-09-11 12:32:42 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011-09-11 12:32:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menuen Start\Programmer\Malwarebytes' Anti-Malware
[2011-09-11 12:32:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011-09-11 12:32:38 | 000,022,712 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011-09-11 12:32:38 | 000,000,000 | —D | C] – C:\Programmer\Malwarebytes' Anti-Malware
[2011-09-11 12:20:29 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Nicole & Paw\Recent
[2011-09-11 12:14:04 | 000,000,000 | —D | C] – C:\Programmer\CCleaner
[2011-09-10 11:37:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Nicole & Paw\Application Data\Uniblue
[2011-09-10 11:37:53 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2011-09-10 11:37:52 | 000,000,000 | —D | C] – C:\Programmer\Uniblue
[2011-09-10 11:37:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menuen Start\Programmer\Uniblue
[2011-09-10 11:37:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Nicole & Paw\Lokale indstillinger\Application Data\PackageAware
[2011-09-10 10:28:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menuen Start\Programmer\ZoneAlarm
[2011-09-10 10:28:25 | 000,058,368 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vsregexp.dll
[2011-09-10 10:28:19 | 000,104,448 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\zlcommdb.dll
[2011-09-10 10:28:19 | 000,069,120 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\zlcomm.dll
[2011-09-10 10:28:14 | 000,043,008 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vswmi.dll
[2011-09-10 10:28:12 | 001,238,528 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\zpeng25.dll
[2011-09-10 10:28:12 | 000,302,592 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vspubapi.dll
[2011-09-10 10:28:12 | 000,110,080 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vsxml.dll
[2011-09-10 10:28:12 | 000,108,032 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vsmonapi.dll
[2011-09-10 10:28:12 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ZoneLabs
[2011-09-10 10:28:10 | 000,532,224 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vsdatant.sys
[2011-09-10 10:28:09 | 000,000,000 | —D | C] – C:\Programmer\Zone Labs
[2011-09-10 10:27:27 | 000,000,000 | —D | C] – C:\WINDOWS\Internet Logs
[2011-09-10 10:27:26 | 000,715,264 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vsutil.dll
[2011-09-10 10:27:26 | 000,228,864 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vsinit.dll
[2011-09-10 10:27:26 | 000,112,128 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vsdata.dll
[2011-09-03 12:17:20 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\crypt32.dll
[2011-08-28 19:57:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Nicole & Paw\Application Data\TrojanHunter
[2011-08-28 12:07:40 | 000,000,000 | —D | C] – C:\Programmer\TrojanHunter 5.3
[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011-09-18 16:40:23 | 000,447,596 | —- | M] () – C:\WINDOWS\System32\perfh006.dat
[2011-09-18 16:40:23 | 000,432,492 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011-09-18 16:40:23 | 000,077,994 | —- | M] () – C:\WINDOWS\System32\perfc006.dat
[2011-09-18 16:40:23 | 000,067,448 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011-09-18 16:38:09 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011-09-18 16:36:17 | 000,000,272 | —- | M] () – C:\WINDOWS\tasks\RegistryBooster.job
[2011-09-18 16:36:08 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011-09-18 16:02:45 | 132,815,236 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011-09-17 17:20:42 | 000,002,443 | —- | M] () – C:\Documents and Settings\Nicole & Paw\Skrivebord\HiJackThis.lnk
[2011-09-17 16:30:02 | 000,183,808 | —- | M] () – C:\Documents and Settings\Nicole & Paw\Lokale indstillinger\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011-09-12 17:15:46 | 004,203,777 | R— | M] (Swearware) – C:\Documents and Settings\Nicole & Paw\Skrivebord\Agurk.exe
[2011-09-10 11:37:53 | 000,001,457 | —- | M] () – C:\Documents and Settings\Nicole & Paw\Application Data\Microsoft\Internet Explorer\Quick Launch\Uniblue RegistryBooster.lnk
[2011-09-10 10:28:57 | 000,420,800 | —- | M] () – C:\WINDOWS\System32\vsconfig.xml
[2011-09-10 10:28:30 | 000,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2011-09-09 11:11:57 | 000,602,112 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\crypt32.dll
[2011-09-05 07:40:26 | 000,002,133 | —- | M] () – C:\Documents and Settings\Nicole & Paw\Skrivebord\Direktørsamtale.rtf
[2011-08-30 19:36:16 | 000,193,537 | —- | M] () – C:\Documents and Settings\Nicole & Paw\Skrivebord\Nicole.GIF
[2011-08-30 19:32:23 | 000,183,289 | —- | M] () – C:\Documents and Settings\Nicole & Paw\Skrivebord\Paw.GIF
[2011-08-28 12:07:51 | 000,059,392 | R— | M] () – C:\WINDOWS\System32\streamhlp.dll
[2011-08-24 08:21:04 | 000,017,180 | —- | M] () – C:\Documents and Settings\Nicole & Paw\Skrivebord\Lønspecifikation2.pdf
[2011-08-23 18:40:30 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011-08-21 18:52:58 | 000,030,692 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011-09-17 17:20:14 | 000,002,443 | —- | C] () – C:\Documents and Settings\Nicole & Paw\Skrivebord\HiJackThis.lnk
[2011-09-12 17:34:52 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011-09-12 17:34:52 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011-09-12 17:34:52 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011-09-12 17:34:52 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011-09-12 17:34:52 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011-09-10 11:37:59 | 000,000,272 | —- | C] () – C:\WINDOWS\tasks\RegistryBooster.job
[2011-09-10 11:37:53 | 000,001,457 | —- | C] () – C:\Documents and Settings\Nicole & Paw\Application Data\Microsoft\Internet Explorer\Quick Launch\Uniblue RegistryBooster.lnk
[2011-09-10 10:28:30 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2011-09-10 10:28:10 | 000,420,800 | —- | C] () – C:\WINDOWS\System32\vsconfig.xml
[2011-09-05 07:40:26 | 000,002,133 | —- | C] () – C:\Documents and Settings\Nicole & Paw\Skrivebord\Direktørsamtale.rtf
[2011-08-30 19:36:13 | 000,193,537 | —- | C] () – C:\Documents and Settings\Nicole & Paw\Skrivebord\Nicole.GIF
[2011-08-30 19:32:21 | 000,183,289 | —- | C] () – C:\Documents and Settings\Nicole & Paw\Skrivebord\Paw.GIF
[2011-08-28 12:07:40 | 000,059,392 | R— | C] () – C:\WINDOWS\System32\streamhlp.dll
[2011-08-24 17:21:29 | 000,017,180 | —- | C] () – C:\Documents and Settings\Nicole & Paw\Skrivebord\Lønspecifikation2.pdf
[2011-08-19 20:25:08 | 000,242,333 | —- | C] () – C:\Documents and Settings\Nicole & Paw\Skrivebord\FRPaymentReceipt16144225.pdf
[2011-07-13 19:10:51 | 000,000,127 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2011-06-05 12:09:34 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\SI.bin
[2011-03-16 21:49:58 | 000,319,488 | —- | C] () – C:\WINDOWS\AegisI5.exe
[2011-03-15 21:03:19 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2011-03-15 20:01:09 | 000,183,808 | —- | C] () – C:\Documents and Settings\Nicole & Paw\Lokale indstillinger\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011-03-15 18:50:41 | 000,232,968 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011-03-15 18:50:39 | 000,232,968 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011-03-15 18:50:39 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2011-03-12 12:20:32 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011-03-12 11:23:27 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2011-03-12 10:07:22 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\vuins32.dll
[2011-03-11 23:30:00 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011-03-11 23:26:29 | 000,021,644 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011-03-11 23:18:17 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011-03-11 23:17:28 | 000,095,864 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010-07-30 09:47:00 | 002,195,030 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2004-08-02 15:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2001-10-09 13:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001-10-09 13:00:00 | 000,447,596 | —- | C] () – C:\WINDOWS\System32\perfh006.dat
[2001-10-09 13:00:00 | 000,432,492 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001-10-09 13:00:00 | 000,284,912 | —- | C] () – C:\WINDOWS\System32\perfi006.dat
[2001-10-09 13:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001-10-09 13:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001-10-09 13:00:00 | 000,077,994 | —- | C] () – C:\WINDOWS\System32\perfc006.dat
[2001-10-09 13:00:00 | 000,067,448 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001-10-09 13:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001-10-09 13:00:00 | 000,034,026 | —- | C] () – C:\WINDOWS\System32\perfd006.dat
[2001-10-09 13:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001-10-09 13:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2001-10-09 13:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2001-08-23 14:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001-08-23 14:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat

========== LOP Check ==========

[2011-09-09 22:15:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2011-03-25 10:54:49 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011-08-26 19:29:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2011-03-15 20:01:21 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011-03-26 14:12:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2011-03-12 12:41:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Driver Whiz
[2011-06-06 09:52:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2011-05-21 07:20:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011-03-15 20:53:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2011-06-27 18:39:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2011-06-08 09:10:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2011-09-10 11:37:53 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2011-06-25 15:02:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011-03-15 20:05:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Nicole & Paw\Application Data\AVG10
[2011-09-10 22:15:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Nicole & Paw\Application Data\BitComet
[2011-09-11 12:21:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Nicole & Paw\Application Data\DAEMON Tools Lite
[2011-03-12 11:07:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Nicole & Paw\Application Data\DeviceDoctorSoftware
[2011-03-15 20:50:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Nicole & Paw\Application Data\DriverCure
[2011-03-15 20:16:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Nicole & Paw\Application Data\Easeware
[2011-05-31 15:07:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Nicole & Paw\Application Data\iWin
[2011-03-26 13:13:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Nicole & Paw\Application Data\Kalypso Media
[2011-06-26 22:20:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Nicole & Paw\Application Data\Mount&Blade; With Fire and Sword
[2011-03-15 19:03:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Nicole & Paw\Application Data\Opera
[2011-03-15 20:50:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Nicole & Paw\Application Data\ParetoLogic
[2011-07-01 20:29:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Nicole & Paw\Application Data\Sports Interactive
[2011-06-08 09:09:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Nicole & Paw\Application Data\TomTom
[2011-08-28 19:57:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Nicole & Paw\Application Data\TrojanHunter
[2011-09-10 11:55:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Nicole & Paw\Application Data\Uniblue
[2011-09-18 16:36:17 | 000,000,272 | —- | M] () – C:\WINDOWS\Tasks\RegistryBooster.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011-03-11 23:28:38 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011-03-12 11:46:55 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2001-10-09 13:00:00 | 000,004,952 | RHS- | M] () – C:\Bootfont.bin
[2011-09-12 18:35:57 | 000,011,937 | —- | M] () – C:\ComboFix.txt
[2011-03-11 23:28:38 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011-03-11 23:28:38 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011-03-11 23:28:38 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011-03-12 11:44:12 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2011-03-15 19:28:19 | 000,250,576 | RHS- | M] () – C:\ntldr
[2011-09-18 16:36:05 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2011-09-18 16:35:00 | 000,040,622 | —- | M] () – C:\TDSSKiller.2.5.22.0_18.09.2011_16.33.38_log.txt

< %systemroot%\Fonts\*.com >
[2006-04-18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006-06-29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006-04-18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006-06-29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2011-03-11 23:28:24 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006-11-06 07:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD8O.DLL
[2006-11-06 07:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP8O.DLL
[2008-07-06 14:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008-07-06 12:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2011-03-12 00:15:52 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2011-03-12 00:15:52 | 000,606,208 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2011-03-12 00:15:52 | 000,430,080 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011-03-12 12:05:04 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Nicole & Paw\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2011-03-11 23:32:58 | 000,000,079 | —- | M] () – C:\Documents and Settings\Nicole & Paw\Application Data\Microsoft\Internet Explorer\Quick Launch\Vis skrivebord.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2011-09-18 16:36:13 | 000,065,536 | —- | M] () – C:\Documents and Settings\Nicole & Paw\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-09-17 11:16:57

< End of report >


OTL Extras logfile created on: 18-09-2011 16:43:18 - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Nicole & Paw\Skrivebord\Ny mappe\Diverse
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000406 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy

2,00 Gb Total Physical Memory | 1,37 Gb Available Physical Memory | 68,70% Memory free
3,85 Gb Paging File | 3,29 Gb Available in Paging File | 85,53% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmer
Drive C: | 127,99 Gb Total Space | 66,66 Gb Free Space | 52,08% Space Free | Partition Type: NTFS
Drive G: | 170,10 Gb Total Space | 170,02 Gb Free Space | 99,95% Space Free | Partition Type: NTFS

Computer Name: PANIC | User Name: Nicole & Paw | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = Opera.HTML] – C:\Programmer\Opera\Opera.exe (Opera Software)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = Opera.HTML] – C:\Programmer\Opera\Opera.exe (Opera Software)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
https [open] – "C:\Programmer\Opera\Opera.exe" "%1" (Opera Software)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Programmer\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Programmer\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"13116:TCP" = 13116:TCP:*:Enabled:BitComet 13116 TCP
"13116:UDP" = 13116:UDP:*:Enabled:BitComet 13116 UDP

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Programmer\Opera\opera.exe" = C:\Programmer\Opera\opera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
"C:\Programmer\AVG\AVG10\avgmfapx.exe" = C:\Programmer\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG-installationsprogram – (AVG Technologies CZ, s.r.o.)
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe" = C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:vsmon – (Check Point Software Technologies LTD)
"C:\Programmer\AVG\AVG10\avgdiagex.exe" = C:\Programmer\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnose 2011 – (AVG Technologies CZ, s.r.o.)
"C:\Programmer\AVG\AVG10\avgnsx.exe" = C:\Programmer\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Programmer\AVG\AVG10\avgemcx.exe" = C:\Programmer\AVG\AVG10\avgemcx.exe:*:Enabled:Personlig e-mail-scanner – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP1800_series" = Canon iP1800 series
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{20EAC554-95F9-4926-8D9A-C4FF3EC44C72}" = AVG 2011
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java™ 6 Update 26
"{350C97C6-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4D53090A-CE35-42BD-B377-831000018301}" = Fable III
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{555868C6-49FB-484F-BB43-8980651A1B00}" = Nero BurnRights 10 Help (CHM)
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = MouseWare 9.76
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{695B13B2-7919-4EC5-8601-092F0D2DE069}" = AVG 2011
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{727DAFCB-E3AF-46E3-8A38-EB9C3EAA0A88}" = AVG 2011
"{7A5D731D-B4B3-490E-B339-75685712BAAB}" = Nero Burning ROM 10
"{82EF29B1-9B60-4142-A155-0599216DD053}" = LightScribe System Software
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{943CFD7D-5336-47AF-9418-E02473A5A517}" = Nero BurnRights 10
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B6B24BE-80E7-46C4-9FA5-B167D5E0F345}" = Nero BurningROM 10 Help (CHM)
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1030-7B44-AA1000000001}" = Adobe Reader X (10.1.0) - Dansk
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{BBB51C33-8D83-4B6C-84F8-CD6700B54463}" = Gigaset USB Adapter 300
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update
"{C897FCB3-2F8B-4185-8035-79E2AF3A92A4}" = iTunes
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DBB1F4ED-3212-4F58-A427-9C01DE4A24A5}_is1" = Uniblue SystemTweaker
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FE83F463-7E61-4B18-9FA0-B94B90A0B6B9}" = Nero Burning ROM 10
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AIDA64 Extreme Edition_is1" = AIDA64 Extreme Edition v1.60
"AVG" = AVG 2011
"CANONIJPLM100" = PIXMA Extended Survey Program
"CCleaner" = CCleaner
"DAEMON Tools Lite" = DAEMON Tools Lite
"DivX Setup.divx.com" = DivX Setup
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"Opera 11.51.1087" = Opera 11.51
"PowerISO" = PowerISO
"Smart File Advisor_is1" = Smart File Advisor
"SystemRequirementsLab" = System Requirements Lab
"TomTom HOME" = TomTom HOME 2.8.2.2264
"Uniblue RegistryBooster" = Uniblue RegistryBooster
"VLC media player" = VLC media player 1.1.11
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast-Ethernet Adapter
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR 4.00 (32-bit)
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"ZoneAlarm" = ZoneAlarm

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 17-09-2011 07:00:29 | Computer Name = PANIC | Source = Userenv | ID = 1090
Description = Sessionsstatus for gældende politikindstilling kunne ikke logføres.
Et forsøg på at oprette forbindelse til WMI mislykkedes. Logføring for gældende
politikindstilling udføres ikke længere for denne politiks program.

Error - 17-09-2011 07:06:55 | Computer Name = PANIC | Source = MsiInstaller | ID = 1013
Description = SA_Error1709: StandardAction(0xC00706AD): Produkt: AVG 2011 – SA_Error25101:
StandardAction(0xC007620D): Vi har registreret, at ZoneAlarm allerede kører på
dit system, og installationen kan derfor ikke fortsættes. Vi anbefaler, at du først
afinstallerer dette produkt, og derefter forsøger at køre installationen igen.

Error - 17-09-2011 07:31:28 | Computer Name = PANIC | Source = Userenv | ID = 1090
Description = Sessionsstatus for gældende politikindstilling kunne ikke logføres.
Et forsøg på at oprette forbindelse til WMI mislykkedes. Logføring for gældende
politikindstilling udføres ikke længere for denne politiks program.

Error - 17-09-2011 07:31:28 | Computer Name = PANIC | Source = Userenv | ID = 1090
Description = Sessionsstatus for gældende politikindstilling kunne ikke logføres.
Et forsøg på at oprette forbindelse til WMI mislykkedes. Logføring for gældende
politikindstilling udføres ikke længere for denne politiks program.

Error - 17-09-2011 10:10:43 | Computer Name = PANIC | Source = Userenv | ID = 1090
Description = Sessionsstatus for gældende politikindstilling kunne ikke logføres.
Et forsøg på at oprette forbindelse til WMI mislykkedes. Logføring for gældende
politikindstilling udføres ikke længere for denne politiks program.

Error - 17-09-2011 10:10:43 | Computer Name = PANIC | Source = Userenv | ID = 1090
Description = Sessionsstatus for gældende politikindstilling kunne ikke logføres.
Et forsøg på at oprette forbindelse til WMI mislykkedes. Logføring for gældende
politikindstilling udføres ikke længere for denne politiks program.

Error - 18-09-2011 09:58:42 | Computer Name = PANIC | Source = Userenv | ID = 1090
Description = Sessionsstatus for gældende politikindstilling kunne ikke logføres.
Et forsøg på at oprette forbindelse til WMI mislykkedes. Logføring for gældende
politikindstilling udføres ikke længere for denne politiks program.

Error - 18-09-2011 09:58:43 | Computer Name = PANIC | Source = Userenv | ID = 1090
Description = Sessionsstatus for gældende politikindstilling kunne ikke logføres.
Et forsøg på at oprette forbindelse til WMI mislykkedes. Logføring for gældende
politikindstilling udføres ikke længere for denne politiks program.

Error - 18-09-2011 10:38:09 | Computer Name = PANIC | Source = Userenv | ID = 1090
Description = Sessionsstatus for gældende politikindstilling kunne ikke logføres.
Et forsøg på at oprette forbindelse til WMI mislykkedes. Logføring for gældende
politikindstilling udføres ikke længere for denne politiks program.

Error - 18-09-2011 10:38:09 | Computer Name = PANIC | Source = Userenv | ID = 1090
Description = Sessionsstatus for gældende politikindstilling kunne ikke logføres.
Et forsøg på at oprette forbindelse til WMI mislykkedes. Logføring for gældende
politikindstilling udføres ikke længere for denne politiks program.

[ System Events ]
Error - 12-09-2011 16:11:14 | Computer Name = PANIC | Source = Service Control Manager | ID = 7023
Description = Tjenesten Hjælp og support blev afbrudt med følgende fejl: %%126

Error - 14-09-2011 16:59:08 | Computer Name = PANIC | Source = Service Control Manager | ID = 7023
Description = Tjenesten Hjælp og support blev afbrudt med følgende fejl: %%126

Error - 14-09-2011 16:59:32 | Computer Name = PANIC | Source = System Error | ID = 1003
Description = Fejlkode 10000050, parameter 1 bad0b0f8, parameter 2 00000000, parameter
3 805c0775, parameter 4 00000000.

Error - 17-09-2011 06:59:03 | Computer Name = PANIC | Source = Service Control Manager | ID = 7023
Description = Tjenesten Hjælp og support blev afbrudt med følgende fejl: %%126

Error - 17-09-2011 07:01:41 | Computer Name = PANIC | Source = W32Time | ID = 39452689
Description = Tidsprovideren NtpClient: Der opstod en fejl under DNS-opslag af den
manuelt konfigurerede peer 'time.windows.com,0x1'. NtpClient forsøger DNS-opslaget
igen om 15 minutter. Fejlen var: En socket-handling blev forsøgt til en vært, der
ikke kunne nås. (0x80072751)

Error - 17-09-2011 07:01:41 | Computer Name = PANIC | Source = W32Time | ID = 39452701
Description = Tidsprovideren NtpClient er konfigureret til at hente tid fra en eller
flere tidskilder, men ingen af kilderne er tilgængelige i øjeblikket. Der forsøges
ikke at oprette forbindelse til en kilde i 14 minutter. NtpClient har ingen kilde
til korrekt tid.

Error - 17-09-2011 07:29:58 | Computer Name = PANIC | Source = Service Control Manager | ID = 7023
Description = Tjenesten Hjælp og support blev afbrudt med følgende fejl: %%126

Error - 17-09-2011 10:09:06 | Computer Name = PANIC | Source = Service Control Manager | ID = 7023
Description = Tjenesten Hjælp og support blev afbrudt med følgende fejl: %%126

Error - 18-09-2011 09:57:03 | Computer Name = PANIC | Source = Service Control Manager | ID = 7023
Description = Tjenesten Hjælp og support blev afbrudt med følgende fejl: %%126

Error - 18-09-2011 10:36:38 | Computer Name = PANIC | Source = Service Control Manager | ID = 7023
Description = Tjenesten Hjælp og support blev afbrudt med følgende fejl: %%126


< End of report >

OTL Extras logfile created on: 18-09-2011 16:43:18 - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Nicole & Paw\Skrivebord\Ny mappe\Diverse
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000406 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 17-09-2011 07:00:29 | Computer Name = PANIC | Source = Userenv | ID = 1090
Description = Sessionsstatus for gældende politikindstilling kunne ikke logføres.
Et forsøg på at oprette forbindelse til WMI mislykkedes. Logføring for gældende
politikindstilling udføres ikke længere for denne politiks program.

Error - 17-09-2011 07:06:55 | Computer Name = PANIC | Source = MsiInstaller | ID = 1013
Description = SA_Error1709: StandardAction(0xC00706AD): Produkt: AVG 2011 – SA_Error25101:
StandardAction(0xC007620D): Vi har registreret, at ZoneAlarm allerede kører på
dit system, og installationen kan derfor ikke fortsættes. Vi anbefaler, at du først
afinstallerer dette produkt, og derefter forsøger at køre installationen igen.

Error - 17-09-2011 07:31:28 | Computer Name = PANIC | Source = Userenv | ID = 1090
Description = Sessionsstatus for gældende politikindstilling kunne ikke logføres.
Et forsøg på at oprette forbindelse til WMI mislykkedes. Logføring for gældende
politikindstilling udføres ikke længere for denne politiks program.

Error - 17-09-2011 07:31:28 | Computer Name = PANIC | Source = Userenv | ID = 1090
Description = Sessionsstatus for gældende politikindstilling kunne ikke logføres.
Et forsøg på at oprette forbindelse til WMI mislykkedes. Logføring for gældende
politikindstilling udføres ikke længere for denne politiks program.

Error - 17-09-2011 10:10:43 | Computer Name = PANIC | Source = Userenv | ID = 1090
Description = Sessionsstatus for gældende politikindstilling kunne ikke logføres.
Et forsøg på at oprette forbindelse til WMI mislykkedes. Logføring for gældende
politikindstilling udføres ikke længere for denne politiks program.

Error - 17-09-2011 10:10:43 | Computer Name = PANIC | Source = Userenv | ID = 1090
Description = Sessionsstatus for gældende politikindstilling kunne ikke logføres.
Et forsøg på at oprette forbindelse til WMI mislykkedes. Logføring for gældende
politikindstilling udføres ikke længere for denne politiks program.

Error - 18-09-2011 09:58:42 | Computer Name = PANIC | Source = Userenv | ID = 1090
Description = Sessionsstatus for gældende politikindstilling kunne ikke logføres.
Et forsøg på at oprette forbindelse til WMI mislykkedes. Logføring for gældende
politikindstilling udføres ikke længere for denne politiks program.

Error - 18-09-2011 09:58:43 | Computer Name = PANIC | Source = Userenv | ID = 1090
Description = Sessionsstatus for gældende politikindstilling kunne ikke logføres.
Et forsøg på at oprette forbindelse til WMI mislykkedes. Logføring for gældende
politikindstilling udføres ikke længere for denne politiks program.

Error - 18-09-2011 10:38:09 | Computer Name = PANIC | Source = Userenv | ID = 1090
Description = Sessionsstatus for gældende politikindstilling kunne ikke logføres.
Et forsøg på at oprette forbindelse til WMI mislykkedes. Logføring for gældende
politikindstilling udføres ikke længere for denne politiks program.

Error - 18-09-2011 10:38:09 | Computer Name = PANIC | Source = Userenv | ID = 1090
Description = Sessionsstatus for gældende politikindstilling kunne ikke logføres.
Et forsøg på at oprette forbindelse til WMI mislykkedes. Logføring for gældende
politikindstilling udføres ikke længere for denne politiks program.

[ System Events ]
Error - 12-09-2011 16:11:14 | Computer Name = PANIC | Source = Service Control Manager | ID = 7023
Description = Tjenesten Hjælp og support blev afbrudt med følgende fejl: %%126

Error - 14-09-2011 16:59:08 | Computer Name = PANIC | Source = Service Control Manager | ID = 7023
Description = Tjenesten Hjælp og support blev afbrudt med følgende fejl: %%126

Error - 14-09-2011 16:59:32 | Computer Name = PANIC | Source = System Error | ID = 1003
Description = Fejlkode 10000050, parameter 1 bad0b0f8, parameter 2 00000000, parameter
3 805c0775, parameter 4 00000000.

Error - 17-09-2011 06:59:03 | Computer Name = PANIC | Source = Service Control Manager | ID = 7023
Description = Tjenesten Hjælp og support blev afbrudt med følgende fejl: %%126

Error - 17-09-2011 07:01:41 | Computer Name = PANIC | Source = W32Time | ID = 39452689
Description = Tidsprovideren NtpClient: Der opstod en fejl under DNS-opslag af den
manuelt konfigurerede peer 'time.windows.com,0x1'. NtpClient forsøger DNS-opslaget
igen om 15 minutter. Fejlen var: En socket-handling blev forsøgt til en vært, der
ikke kunne nås. (0x80072751)

Error - 17-09-2011 07:01:41 | Computer Name = PANIC | Source = W32Time | ID = 39452701
Description = Tidsprovideren NtpClient er konfigureret til at hente tid fra en eller
flere tidskilder, men ingen af kilderne er tilgængelige i øjeblikket. Der forsøges
ikke at oprette forbindelse til en kilde i 14 minutter. NtpClient har ingen kilde
til korrekt tid.

Error - 17-09-2011 07:29:58 | Computer Name = PANIC | Source = Service Control Manager | ID = 7023
Description = Tjenesten Hjælp og support blev afbrudt med følgende fejl: %%126

Error - 17-09-2011 10:09:06 | Computer Name = PANIC | Source = Service Control Manager | ID = 7023
Description = Tjenesten Hjælp og support blev afbrudt med følgende fejl: %%126

Error - 18-09-2011 09:57:03 | Computer Name = PANIC | Source = Service Control Manager | ID = 7023
Description = Tjenesten Hjælp og support blev afbrudt med følgende fejl: %%126

Error - 18-09-2011 10:36:38 | Computer Name = PANIC | Source = Service Control Manager | ID = 7023
Description = Tjenesten Hjælp og support blev afbrudt med følgende fejl: %%126


< End of report >


By the way, since these error descriptions are in Danish, feel free to ask for translations - unless there is some way of getting them in English?
It seems that my problem has been solved! ping.exe does not bother me anymore. I guess the Malicious object removed by TDSSKiller must have been the source? Anything else I should be aware of based on the logs i posted?
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
ComboFix 11-09-19.01 - Nicole & Paw 19-09-2011 17:50:29.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1030.18.2046.1491 [GMT 2:00]
Kører fra: c:\documents and settings\Nicole & Paw\Skrivebord\Ny mappe\Diverse\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\d3d9caps.dat
.
.
((((((((((((((((((((((((((((( Filer skabt fra 2011-08-19 til 2011-09-19 )))))))))))))))))))))))))))))))))))
.
.
2011-09-18 15:06 . 2011-09-18 15:06 ——– d—–w- c:\documents and settings\Nicole & Paw\.oces
2011-09-17 15:20 . 2011-09-17 15:20 388096 —-a-r- c:\documents and settings\Nicole & Paw\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-09-17 15:20 . 2011-09-17 15:20 ——– d—–w- c:\programmer\Trend Micro
2011-09-11 10:32 . 2011-09-11 10:32 ——– d—–w- c:\documents and settings\Nicole & Paw\Application Data\Malwarebytes
2011-09-11 10:32 . 2011-07-06 17:52 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-09-11 10:32 . 2011-09-11 10:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-09-11 10:32 . 2011-09-11 10:32 ——– d—–w- c:\programmer\Malwarebytes' Anti-Malware
2011-09-11 10:32 . 2011-07-06 17:52 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-09-11 10:14 . 2011-09-11 10:14 ——– d—–w- c:\programmer\CCleaner
2011-09-10 09:37 . 2011-09-10 09:55 ——– d—–w- c:\documents and settings\Nicole & Paw\Application Data\Uniblue
2011-09-10 09:37 . 2011-09-10 09:37 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
2011-09-10 09:37 . 2011-09-10 09:55 ——– d—–w- c:\programmer\Uniblue
2011-09-10 09:37 . 2011-09-10 09:37 ——– d—–w- c:\documents and settings\Nicole & Paw\Lokale indstillinger\Application Data\PackageAware
2011-09-10 08:28 . 2011-03-17 23:24 69120 —-a-w- c:\windows\system32\zlcomm.dll
2011-09-10 08:28 . 2011-03-17 23:24 104448 —-a-w- c:\windows\system32\zlcommdb.dll
2011-09-10 08:28 . 2011-09-10 08:28 ——– d—–w- c:\windows\system32\ZoneLabs
2011-09-10 08:28 . 2011-03-17 23:24 1238528 —-a-w- c:\windows\system32\zpeng25.dll
2011-09-10 08:28 . 2011-09-10 08:28 ——– d—–w- c:\programmer\Zone Labs
2011-09-10 08:27 . 2011-09-19 15:48 ——– d—–w- c:\windows\Internet Logs
2011-09-03 10:17 . 2011-09-09 09:11 602112 -c—-w- c:\windows\system32\dllcache\crypt32.dll
2011-08-28 17:57 . 2011-08-28 17:57 ——– d—–w- c:\documents and settings\Nicole & Paw\Application Data\TrojanHunter
2011-08-28 10:07 . 2011-08-28 17:58 ——– d—–w- c:\programmer\TrojanHunter 5.3
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-09 09:11 . 2002-09-23 14:11 602112 —-a-w- c:\windows\system32\crypt32.dll
2011-08-23 16:40 . 2011-05-14 14:17 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-15 13:29 . 2001-10-09 11:00 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2001-10-09 11:00 10496 —-a-w- c:\windows\system32\drivers\ndistapi.sys
2011-06-24 14:10 . 2011-03-11 21:25 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:31 . 2001-10-09 11:00 916480 —-a-w- c:\windows\system32\wininet.dll
2011-06-23 18:31 . 2001-10-09 11:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-06-23 18:31 . 2001-10-09 11:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05 . 2011-03-12 09:46 385024 —-a-w- c:\windows\system32\html.iec
.
.
((((((((((((((((((((((((((((( SnapShot@2011-09-12_16.30.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-09-19 15:44 . 2011-09-19 15:44 16384 c:\windows\Temp\Perflib_Perfdata_568.dat
- 2001-10-09 11:00 . 2011-09-12 16:09 67448 c:\windows\system32\perfc009.dat
+ 2001-10-09 11:00 . 2011-09-19 15:49 67448 c:\windows\system32\perfc009.dat
+ 2001-10-09 11:00 . 2011-09-19 15:49 77994 c:\windows\system32\perfc006.dat
- 2001-10-09 11:00 . 2011-09-12 16:09 77994 c:\windows\system32\perfc006.dat
+ 2001-10-09 11:00 . 2011-09-19 15:49 432492 c:\windows\system32\perfh009.dat
- 2001-10-09 11:00 . 2011-09-12 16:09 432492 c:\windows\system32\perfh009.dat
- 2001-10-09 11:00 . 2011-09-12 16:09 447596 c:\windows\system32\perfh006.dat
+ 2001-10-09 11:00 . 2011-09-19 15:49 447596 c:\windows\system32\perfh006.dat
+ 2010-08-03 14:23 . 2011-05-27 17:05 134480 c:\windows\system32\drivers\AVGIDSDriver.sys
- 2010-08-03 14:23 . 2011-04-14 19:28 134480 c:\windows\system32\drivers\AVGIDSDriver.sys
+ 2011-04-22 17:37 . 2011-04-22 17:37 736608 c:\windows\Installer\$PatchCache$\Managed\455CAE029F596294D8A94CFFE34CC427\10.0.1392\avgvvx.dll
+ 2011-02-15 03:38 . 2011-02-15 03:38 610656 c:\windows\Installer\$PatchCache$\Managed\455CAE029F596294D8A94CFFE34CC427\10.0.1392\avgsched.dll
+ 2011-02-08 03:33 . 2011-02-08 03:33 658784 c:\windows\Installer\$PatchCache$\Managed\455CAE029F596294D8A94CFFE34CC427\10.0.1392\avgrsx.exe
+ 2011-04-15 18:29 . 2011-04-15 18:29 548192 c:\windows\Installer\$PatchCache$\Managed\455CAE029F596294D8A94CFFE34CC427\10.0.1392\avgrktx.dll
+ 2011-02-08 03:33 . 2011-02-08 03:33 748384 c:\windows\Installer\$PatchCache$\Managed\455CAE029F596294D8A94CFFE34CC427\10.0.1392\avgpostinstx.dll
+ 2011-02-08 03:33 . 2011-02-08 03:33 731488 c:\windows\Installer\$PatchCache$\Managed\455CAE029F596294D8A94CFFE34CC427\10.0.1392\avgoff2kx.dll
+ 2011-02-08 03:32 . 2011-02-08 03:32 334688 c:\windows\Installer\$PatchCache$\Managed\455CAE029F596294D8A94CFFE34CC427\10.0.1392\avgclitx.dll
+ 2011-03-16 14:05 . 2011-03-16 14:05 656736 c:\windows\Installer\$PatchCache$\Managed\455CAE029F596294D8A94CFFE34CC427\10.0.1392\avgchsvx.exe
+ 2011-03-16 14:05 . 2011-03-16 14:05 543584 c:\windows\Installer\$PatchCache$\Managed\455CAE029F596294D8A94CFFE34CC427\10.0.1392\avgchjwx.dll
+ 2011-09-17 11:06 . 2011-09-17 11:06 3504640 c:\windows\Installer\62dc4.msi
+ 2011-09-17 15:20 . 2011-09-17 15:20 1094656 c:\windows\Installer\422d3c.msi
+ 2011-06-15 03:50 . 2011-06-15 03:50 1859424 c:\windows\Installer\$PatchCache$\Managed\455CAE029F596294D8A94CFFE34CC427\10.0.1392\avgxpl.dll
+ 2011-04-28 05:19 . 2011-04-28 05:19 2035976 c:\windows\Installer\$PatchCache$\Managed\455CAE029F596294D8A94CFFE34CC427\10.0.1392\avgwd.dll
+ 2011-04-14 19:30 . 2011-04-14 19:30 3588960 c:\windows\Installer\$PatchCache$\Managed\455CAE029F596294D8A94CFFE34CC427\10.0.1392\avgui.exe
+ 2011-04-18 15:40 . 2011-04-18 15:40 2334560 c:\windows\Installer\$PatchCache$\Managed\455CAE029F596294D8A94CFFE34CC427\10.0.1392\avgtray.exe
+ 2011-08-05 11:20 . 2011-08-05 11:20 2274144 c:\windows\Installer\$PatchCache$\Managed\455CAE029F596294D8A94CFFE34CC427\10.0.1392\avgssie.dll
+ 2011-06-20 14:52 . 2011-06-20 14:52 1799008 c:\windows\Installer\$PatchCache$\Managed\455CAE029F596294D8A94CFFE34CC427\10.0.1392\avgssff5.dll
+ 2011-05-05 03:55 . 2011-05-05 03:55 1799008 c:\windows\Installer\$PatchCache$\Managed\455CAE029F596294D8A94CFFE34CC427\10.0.1392\avgssff4.dll
+ 2011-04-14 03:36 . 2011-04-14 03:36 1080672 c:\windows\Installer\$PatchCache$\Managed\455CAE029F596294D8A94CFFE34CC427\10.0.1392\avgnsx.exe
+ 2011-04-18 15:39 . 2011-04-18 15:39 7398752 c:\windows\Installer\$PatchCache$\Managed\455CAE029F596294D8A94CFFE34CC427\10.0.1392\AVGIDSAgent.exe
+ 2011-04-13 03:39 . 2011-04-13 03:39 3832672 c:\windows\Installer\$PatchCache$\Managed\455CAE029F596294D8A94CFFE34CC427\10.0.1392\avgdiagex.exe
+ 2011-04-13 03:38 . 2011-04-13 03:38 1128288 c:\windows\Installer\$PatchCache$\Managed\455CAE029F596294D8A94CFFE34CC427\10.0.1392\avgcfgx.dll
+ 2011-04-14 03:36 . 2011-04-14 03:36 4193632 c:\windows\Installer\$PatchCache$\Managed\455CAE029F596294D8A94CFFE34CC427\10.0.1392\avgapix.dll
+ 2011-03-15 16:56 . 2011-09-17 11:14 46249416 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Utility"="Logi_MwX.Exe" [2003-03-04 19968]
"nwiz"="c:\programmer\NVIDIA Corporation\nView\nwiz.exe" [2010-07-28 1753192]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-07-29 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-07-29 13923432]
"AVG_TRAY"="c:\programmer\AVG\AVG10\avgtray.exe" [2011-09-10 2338656]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 16270848]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"Smart File Advisor"="c:\programmer\Smart File Advisor\sfa.exe" [2011-03-02 280312]
"SunJavaUpdateSched"="c:\programmer\Fælles filer\Java\Java Update\jusched.exe" [2011-04-08 254696]
"Adobe ARM"="c:\programmer\Fælles filer\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"ZoneAlarm Client"="c:\programmer\Zone Labs\ZoneAlarm\zlclient.exe" [2011-03-17 1043968]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Menuen Start\Programmer\Start\
Gigaset WLAN Adapter Monitor.lnk - c:\programmer\Siemens\Gigaset USB Adapter 300\GUI.exe [2011-3-16 815104]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-03-21 18:56 1230704 —-a-w- c:\programmer\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-06-07 15:51 421160 —-a-w- c:\programmer\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 15:38 421888 —-a-w- c:\programmer\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\Opera\\opera.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\AVG\\AVG10\\avgmfapx.exe"=
"c:\\Programmer\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmer\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Programmer\\AVG\\AVG10\\avgdiagex.exe"=
"c:\\Programmer\\AVG\\AVG10\\avgnsx.exe"=
"c:\\Programmer\\AVG\\AVG10\\avgemcx.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"13116:TCP"= 13116:TCP:BitComet 13116 TCP
"13116:UDP"= 13116:UDP:BitComet 13116 UDP
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [13-09-2010 16:27 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [07-09-2010 04:48 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [08-12-2010 05:12 248656]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [12-11-2010 14:19 297168]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [12-03-2011 09:55 13696]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [27-03-2011 12:22 218688]
R2 avgwd;AVG WatchDog;c:\programmer\AVG\AVG10\avgwdsvc.exe [08-02-2011 05:33 269520]
R2 NAUpdate;@c:\programmer\Nero\Update\NASvc.exe,-200;c:\programmer\Nero\Update\NASvc.exe [04-05-2010 12:07 503080]
R2 TomTomHOMEService;TomTomHOMEService;c:\programmer\TomTom HOME 2\TomTomHOMEService.exe [22-04-2011 14:21 92592]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [03-08-2010 16:23 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [03-08-2010 16:23 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [03-08-2010 16:23 27216]
R3 CBPSp50;CBPSp50 NDIS Protocol Driver;c:\windows\system32\drivers\CBPSp50.sys [11-03-2011 23:35 27072]
S1 ethfuagd;ethfuagd; [x]
S2 AVGIDSAgent;AVGIDSAgent;c:\programmer\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [18-08-2011 01:33 7390560]
S3 CBPMp50;CBPMp50 NDIS Protocol Driver;c:\windows\system32\Drivers\CBPMp50.sys –> c:\windows\system32\Drivers\CBPMp50.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [11-09-2011 12:32 41272]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 10:11 451872 —-a-w- c:\programmer\Fælles filer\LightScribe\LSRunOnce.exe
.
Indhold af mappen 'Planlagte Opgaver'
.
2011-06-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmer\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2011-09-19 c:\windows\Tasks\RegistryBooster.job
- c:\programmer\Uniblue\RegistryBooster\rbmonitor.exe [2011-09-10 09:48]
.
.
——- Yderligere scanning ——-
.
uStart Page = hxxp://www.google.dk/
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = [removed] [removed]
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-09-19 17:54
Windows 5.1.2600 Service Pack 3 NTFS
.
scanner skjulte processer …
.
scanner skjulte autostarter …
.
scanner skjulte filer …
.
scanning gennemført med succes
skjulte filer: 0
.
**************************************************************************
.
Gennemført tid: 2011-09-19 17:55:59
ComboFix-quarantined-files.txt 2011-09-19 15:55
ComboFix2.txt 2011-09-12 16:35
.
Pre-Kørsel: 71.552.864.256 byte ledig
Post-Kørsel: 71.542.751.232 byte ledig
.
- - End Of File - - 5266BEACFFCE9B33F3B120A7441C52B9
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.









Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.





Also tell me how the computer is running now.
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 7751

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

20-09-2011 07:27:35
mbam-log-2011-09-20 (07-27-35).txt

Skanningstype: Hurtig skanning
Objekter skannet: 156189
Tid gået: 2 minut(ter), 28 sekund(er)

Hukommelses Processorer Inficeret: 0
Hukommelses Moduler Inficeret: 0
Registreringsdatabasenøgler Inficeret: 0
Registreringsdatabaseværdier Inficeret: 0
Registreringsdatabasedata Objekter Inficeret: 0
Inficerede Mapper: 0
Inficerede Filer: 0

Hukommelses Processorer Inficeret:
(Ingen skadelige objekter blev fundet)

Hukommelses Moduler Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabasenøgler Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabaseværdier Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabasedata Objekter Inficeret:
(Ingen skadelige objekter blev fundet)

Inficerede Mapper:
(Ingen skadelige objekter blev fundet)

Inficerede Filer:
(Ingen skadelige objekter blev fundet)



ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6528
# api_version=3.0.2
# EOSSerial=91c11c613e7a2247b1af9b943dd66f0e
# end=stopped
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-09-20 05:42:32
# local_time=2011-09-20 07:42:32 (+0100, Rom, sommertid)
# country="Denmark"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 224138 224138 0 0
# compatibility_mode=1032 16777173 100 95 51432 59664696 0 0
# compatibility_mode=8192 67108863 100 0 259 259 0 0
# compatibility_mode=9217 16777214 75 70 853580 16097864 0 0
# scanned=7258
# found=0
# cleaned=0
# scan_time=402
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6528
# api_version=3.0.2
# EOSSerial=91c11c613e7a2247b1af9b943dd66f0e
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-09-20 06:06:48
# local_time=2011-09-20 08:06:48 (+0100, Rom, sommertid)
# country="Denmark"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 266652 266652 0 0
# compatibility_mode=1032 16777173 100 95 2114 59707210 0 0
# compatibility_mode=8192 67108863 100 0 42773 42773 0 0
# compatibility_mode=9217 16777214 75 70 896094 16140378 0 0
# scanned=59995
# found=13
# cleaned=13
# scan_time=2544
C:\Programmer\Uniblue\RegistryBooster\Launcher.exe Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Programmer\Uniblue\RegistryBooster\rbmonitor.exe Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Programmer\Uniblue\RegistryBooster\rbnotifier.exe Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Programmer\Uniblue\RegistryBooster\rb_move_serial.exe Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Programmer\Uniblue\RegistryBooster\rb_ubm.exe Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Programmer\Uniblue\RegistryBooster\registrybooster.exe Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{B822ED63-3035-48C3-B5C0-17B6BCF00C24}\RP182\A0062594.exe Win32/RegistryBooster application (deleted - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{B822ED63-3035-48C3-B5C0-17B6BCF00C24}\RP187\A0072236.exe Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{B822ED63-3035-48C3-B5C0-17B6BCF00C24}\RP187\A0072237.exe Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{B822ED63-3035-48C3-B5C0-17B6BCF00C24}\RP187\A0072238.exe Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{B822ED63-3035-48C3-B5C0-17B6BCF00C24}\RP187\A0072239.exe Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{B822ED63-3035-48C3-B5C0-17B6BCF00C24}\RP187\A0072240.exe Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{B822ED63-3035-48C3-B5C0-17B6BCF00C24}\RP187\A0072241.exe Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C


My PC seems to be running ok now.
You appear clean of infections,please do the following.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.











Download TFC to your desktop

Close any open windows.
Double click the TFC icon to run the program
TFC will close all open programs itself in order to run,
Click the Start button to begin the process.
Allow TFC to run uninterrupted.
The program should not take long to finish it's job
Once its finished it should automatically reboot your machine,
if it doesn't, manually reboot to ensure a complete clean











Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI