her er så mine log filer håber du/i kan bruge dem
"Jacob" - 2007-07-28 13:11:13 - ComboFix 07-07-23.6 - Service Pack 2 NTFS
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\Jacob\SKRIVE~1\internet.lnk
((((((((((((((((((((((((( Files Created from 2007-06-28 to 2007-07-28 )))))))))))))))))))))))))))))))
2007-07-28 13:10 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-28 11:54 <DIR> d-------- C:\Programmer\SUPERAntiSpyware
2007-07-28 11:54 <DIR> d-------- C:\Programmer\F‘lles filer\Wise Installation Wizard
2007-07-28 11:54 <DIR> d-------- C:\DOCUME~1\Jacob\APPLIC~1\SUPERAntiSpyware.com
2007-07-28 11:54 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SUPERAntiSpyware.com
2007-07-28 11:52 <DIR> d-------- C:\Programmer\CCleaner
2007-07-28 10:28 <DIR> d-------- C:\DOCUME~1\Jacob\DoctorWeb
2007-07-28 09:15 <DIR> d-------- C:\WINDOWS\pss
2007-07-27 21:45 <DIR> d-------- C:\Programmer\MSXML 4.0
2007-07-27 21:28 <DIR> d-------- C:\DOCUME~1\LOCALS~1.000\Menuen Start
2007-07-27 21:27 <DIR> d-------- C:\WINDOWS\Prefetch
2007-07-27 21:12 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-07-27 21:11 <DIR> d-------- C:\WINDOWS\provisioning
2007-07-27 21:11 <DIR> d-------- C:\WINDOWS\peernet
2007-07-27 21:10 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2007-07-27 21:04 <DIR> d-------- C:\WINDOWS\EHome
2007-07-27 20:51 4,569 --------- C:\WINDOWS\system32\secupd.dat
2007-07-27 20:51 11,776 --------- C:\WINDOWS\system32\spnpinst.exe
2007-07-27 20:06 614,912 --a------ C:\WINDOWS\system32\h323msp.dll
2007-07-27 20:06 40,960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-07-27 20:06 331,776 --a------ C:\WINDOWS\system32\ipnathlp.dll
2007-07-27 20:00 1,082,368 --a------ C:\WINDOWS\system32\esent.dll
2007-07-27 19:54 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Windows Genuine Advantage
2007-07-27 19:45 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-07-27 19:45 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-07-27 19:45 <DIR> d-------- C:\WINDOWS\system32\PreInstall
2007-07-27 19:45 <DIR> d-------- C:\WINDOWS\system32\bits
2007-07-27 19:43 8,192 --------- C:\WINDOWS\system32\bitsprx2.dll
2007-07-27 19:43 7,168 --------- C:\WINDOWS\system32\bitsprx3.dll
2007-07-27 19:43 351,232 --a------ C:\WINDOWS\system32\winhttp.dll
2007-07-27 19:43 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2007-07-27 19:42 <DIR> d---s---- C:\DOCUME~1\Jacob\UserData
2007-07-27 19:42 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-07-27 19:11 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2007-07-27 19:11 298,104 --a------ C:\WINDOWS\system32\imon.dll
2007-07-27 19:11 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2007-07-27 18:15 <DIR> d-------- C:\DOCUME~1\Jacob\APPLIC~1\Symantec
2007-07-26 16:26 <DIR> d-------- C:\DOCUME~1\Jacob\APPLIC~1\Politiken
2007-07-26 16:23 3,670,016 --a------ C:\DOCUME~1\Jacob\ntuser.dat
2007-07-26 16:23 <DIR> d-------- C:\Programmer\Polob32
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-28 10:33:40 809 --sha-w C:\WINDOWS\system32\mmf.sys
2007-07-28 09:54:06 -------- d-----w C:\Programmer\Fælles filer\Wise Installation Wizard
2007-07-28 09:54:06 -------- d-----w C:\Programmer\Fælles filer
2007-07-28 06:50:36 62,474 ----a-w C:\WINDOWS\system32\perfc006.dat
2007-07-28 06:50:36 394,772 ----a-w C:\WINDOWS\system32\perfh006.dat
2007-07-27 19:51:24 -------- d-----w C:\Programmer\Messenger
2007-07-27 19:46:30 -------- d-----w C:\Programmer\Fælles filer\System
2007-07-27 19:11:41 -------- d-----w C:\Programmer\Movie Maker
2007-07-27 19:09:57 -------- d-----w C:\Programmer\Windows NT
2007-07-27 18:37:53 -------- d-----w C:\Programmer\Fælles filer\Microsoft Shared
2007-07-27 16:39:01 -------- d-----w C:\Programmer\Fælles filer\Symantec Shared
2007-05-16 15:14:25 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2006-03-31 16:43:27 4,018,301 ----a-w C:\Programmer\FM 2006 v6.0.0.68542 (2006.03.31 18.43.26).dmp
2006-03-31 16:38:52 4,018,301 ----a-w C:\Programmer\FM 2006 v6.0.0.68542 (2006.03.31 18.38.52).dmp
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"nod32kui"="C:\Programmer\Eset\nod32kui.exe" [2007-07-27 19:10]
"Microsoft Windows Update"="msnserve.exe" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Programmer\Messenger\msmsgs.exe" [2004-10-13 18:24]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 02:53]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-04-23 15:46]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runservices]
"Ms Java for Windows NT"=msi32java.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"Microsoft Windows Update"=msnserve.exe
"Ms Java for Windows NT"=msi32java.exe
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runservices]
"Ms Java for Windows NT"=msi32java.exe
C:\Documents and Settings\All Users.WINDOWS\Menuen Start\Programmer\Start\
Microsoft Office.lnk - C:\Programmer\Microsoft Office\Office\OSA9.EXE [1999-02-17 20:05:56]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
R0 prohlp02;StarForce Protection Helper Driver v2;C:\WINDOWS\system32\drivers\prohlp02.sys
R0 prosync1;StarForce Protection Synchronization Driver v1;C:\WINDOWS\system32\drivers\prosync1.sys
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);C:\WINDOWS\system32\drivers\sfdrv01a.sys
R0 sfhlp01;StarForce Protection Helper Driver;C:\WINDOWS\system32\drivers\sfhlp01.sys
R0 sfsync04;StarForce Protection Synchronization Driver (version 4.x);C:\WINDOWS\system32\drivers\sfsync04.sys
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x);C:\WINDOWS\system32\drivers\sfvfs02.sys
R1 nod32drv;nod32drv;C:\WINDOWS\system32\drivers\nod32drv.sys
R1 prodrv06;StarForce Protection Environment Driver v6;C:\WINDOWS\system32\drivers\prodrv06.sys
R1 SASDIFSV;SASDIFSV;\??\C:\Programmer\SUPERAntiSpyware\SASDIFSV.SYS
R1 SASKUTIL;SASKUTIL;\??\C:\Programmer\SUPERAntiSpyware\SASKUTIL.sys
R2 CdaC15BA;CdaC15BA;\??\C:\WINDOWS\System32\drivers\CdaC15BA.SYS
R2 LicCtrlService;LicCtrl Service;C:\WINDOWS\runservice.exe
R3 E100B;Intel(R) PRO Adapter Driver;C:\WINDOWS\system32\DRIVERS\e100b325.sys
R3 SASENUM;SASENUM;\??\C:\Programmer\SUPERAntiSpyware\SASENUM.SYS
S2 netconf32;netconf32;"C:\WINDOWS\netconf32.exe"
S3 iMSPQMn;iMSPQMn;\??\C:\DOCUME~1\Jacob\LOKALE~1\Temp\iMSPQMn.sys
S3 wceusbsh;Windows CE USB Serial Host Driver;C:\WINDOWS\system32\DRIVERS\wceusbsh.sys
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-07-28 13:12:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-28 13:12:44
C:\ComboFix-quarantined-files.txt ... 2007-07-28 13:12
--- E O F ---
en mere
********************************* ROOTCHK-(21-07-07)-LOG, by ejvindh
28-07-2007 13:09:04,78
The rootkits that are detected by this tool were not found.
********************************* ROOTCHK-LOG-end
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-07-28 13:09:04
Windows 5.1.2600 Service Pack 2
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
hidden processes: 0
hidden files: 0
en mere
Logfile of HijackThis v1.99.1
Scan saved at 13:08:24, on 28-07-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe
C:\Programmer\Eset\nod32kui.exe
C:\Programmer\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\runservice.exe
C:\Programmer\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Programmer\Analog Devices\SoundMAX\spkrmon.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Documents and Settings\Jacob\Skrivebord\Ny mappe\alternativ.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.ni.dk/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
F2 - REG:system.ini: Shell=Explorer.exe msi32java.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,msi32java.exe
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Programmer\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Microsoft Windows Update] msnserve.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\RunServices: [Microsoft Windows Update] msnserve.exe
O4 - HKLM\..\RunServices: [Ms Java for Windows NT] msi32java.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\RunServices: [Ms Java for Windows NT] msi32java.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&ksporter til Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1185558137343O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: netconf32 - Unknown owner - C:\WINDOWS\netconf32.exe (file missing)
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Programmer\Eset\nod32krn.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: spkrmon - Unknown owner - C:\Programmer\Analog Devices\SoundMAX\spkrmon.exe
[code]
2006-08-31 17:25 104 --a------ C:\Qoobox\Quarantine\C\DOCUME~1\Jacob\SKRIVE~1\Internet.lnk.vir
Mappetr‘
Diskenhedens serienummer er 0806-9BE9
C:\QOOBOX
\---Quarantine
+---C
| \---DOCUME~1
| \---Jacob
| \---SKRIVE~1
| Internet.lnk.vir
|
\---Registry_backups
[/code]