Så har jeg kørt programmerne og her logs fra begge to :)
Combofix log:
ComboFix 07-11-08.1 - Michael 2007-11-16 18:30:10.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.636 [GMT -8:00]
Running from: E:\Documents and Settings\Michael\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-10-17 to 2007-11-17 )))))))))))))))))))))))))))))))
.
2007-11-19 18:28 51,200 --a------ E:\WINDOWS\NirCmd.exe
2007-11-19 18:25 401,720 --a------ E:\Program Files\HJTrenamed.exe
2007-11-19 18:24 <DIR> d-------- E:\Program Files\CCleaner
2007-11-06 21:06 <DIR> d-------- E:\Program Files\DivX
2007-11-02 11:36 <DIR> d-------- E:\Program Files\Gertrudis Pro
2007-11-02 11:36 <DIR> d-a------ E:\Documents and Settings\All Users\Application Data\TEMP
2007-11-01 20:11 26,496 --a--c--- E:\WINDOWS\system32\dllcache\usbstor.sys
2007-10-19 16:56 1,044,480 --a------ E:\WINDOWS\system32\libdivx.dll
2007-10-19 16:56 200,704 --a------ E:\WINDOWS\system32\ssldivx.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-20 02:27 7,008 ----a-w E:\Program Files\hijackthis.log
2007-10-16 01:01 --------- d-----w E:\Documents and Settings\Michael\Application Data\Winamp
2007-10-15 22:38 --------- d-----w E:\Program Files\Winamp
2007-10-15 22:35 --------- d-----w E:\Program Files\Winamp Remote
2007-10-15 22:35 --------- d-----w E:\Documents and Settings\All Users\Application Data\OrbNetworks
2007-10-15 18:36 --------- d-----w E:\Documents and Settings\All Users\Application Data\Logishrd
2007-10-15 10:03 --------- d-----w E:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-10-15 00:35 --------- d-----w E:\Program Files\Common Files\LogiShrd
2007-10-15 00:34 --------- d-----w E:\Program Files\Logitech
2007-10-15 00:34 --------- d-----w E:\Documents and Settings\All Users\Application Data\Logitech
2007-10-13 21:38 --------- d--h--w E:\Program Files\InstallShield Installation Information
2007-10-11 06:44 --------- d-----w E:\Program Files\Windows Media Connect 2
2007-10-11 06:43 --------- d-----w E:\Documents and Settings\All Users\Application Data\FLEXnet
2007-10-11 06:23 --------- d-----w E:\Program Files\Bonjour
2007-10-11 06:22 --------- d-----w E:\Program Files\Common Files\Adobe
2007-10-11 06:16 --------- d-----w E:\Program Files\Common Files\Macrovision Shared
2007-10-11 06:10 --------- d-----w E:\Program Files\MagicISO
2007-10-10 22:55 --------- d-----w E:\Program Files\Common Files\Corel
2007-10-10 22:55 --------- d-----w E:\Documents and Settings\Michael\Application Data\Corel
2007-10-10 22:55 --------- d-----w E:\Documents and Settings\All Users\Application Data\InstallShield
2007-10-10 22:54 --------- d-----w E:\Program Files\Corel
2007-10-10 22:54 --------- d-----w E:\Program Files\Common Files\InstallShield
2007-10-09 15:16 --------- d-----w E:\Documents and Settings\Michael\Application Data\Apple Computer
2007-10-07 08:03 --------- d-----w E:\Documents and Settings\Michael\Application Data\PC Suite
2007-10-07 08:03 --------- d-----w E:\Documents and Settings\Michael\Application Data\Nokia
2007-10-07 08:03 --------- d-----w E:\Documents and Settings\All Users\Application Data\PC Suite
2007-10-07 08:02 --------- d-----w E:\Program Files\PC Connectivity Solution
2007-10-07 08:02 --------- d-----w E:\Program Files\Nokia
2007-10-07 08:02 --------- d-----w E:\Program Files\DIFX
2007-10-07 08:02 --------- d-----w E:\Program Files\Common Files\PCSuite
2007-10-07 08:02 --------- d-----w E:\Program Files\Common Files\Nokia
2007-10-07 08:01 --------- d-----w E:\Documents and Settings\All Users\Application Data\Downloaded Installations
2007-10-05 17:12 --------- d-----w E:\Program Files\iTunes
2007-10-05 17:11 --------- d-----w E:\Program Files\iPod
2007-10-05 17:11 --------- d-----w E:\Program Files\Common Files\Apple
2007-10-05 17:11 --------- d-----w E:\Documents and Settings\All Users\Application Data\Apple Computer
2007-10-05 17:10 --------- d-----w E:\Program Files\Apple Software Update
2007-10-05 17:10 --------- d-----w E:\Documents and Settings\All Users\Application Data\Apple
2007-10-02 22:00 --------- d-----w E:\Program Files\Microsoft.NET
2007-10-01 05:44 --------- d-----w E:\Program Files\Java
2007-10-01 05:44 --------- d-----w E:\Program Files\Common Files\Java
2007-09-30 23:19 --------- d-----w E:\Program Files\QuickTime
2007-09-30 06:22 --------- d-----w E:\Program Files\Common Files\Blizzard Entertainment
2007-09-29 21:16 --------- d-----w E:\Documents and Settings\Michael\Application Data\dvdcss
2007-09-29 02:39 --------- d-----w E:\Program Files\Real
2007-09-29 02:39 --------- d-----w E:\Program Files\Common Files\xing shared
2007-09-29 02:39 --------- d-----w E:\Program Files\Common Files\Real
2007-09-29 02:38 --------- d-----w E:\Program Files\Google
2007-09-29 02:19 --------- d-----w E:\Program Files\WinAVI Video Converter
2007-09-28 23:34 --------- d-----w E:\Program Files\PowerISO
2007-09-28 21:28 --------- d-----w E:\Program Files\Realtek Sound Manager
2007-09-28 21:28 --------- d-----w E:\Program Files\AvRack
2007-09-28 21:16 --------- d-----w E:\Program Files\DAEMON Tools
2007-09-28 21:14 --------- d-----w E:\Program Files\MSXML 6.0
2007-09-28 21:13 --------- d-----w E:\Program Files\MSXML 4.0
2007-09-28 20:54 --------- d-----w E:\Program Files\VideoLAN
2007-09-28 20:54 --------- d-----w E:\Documents and Settings\Michael\Application Data\vlc
2007-09-28 20:48 --------- d-----w E:\Program Files\Alwil Software
2007-09-28 20:46 --------- d-----w E:\Program Files\MSN Messenger
2007-09-28 20:45 685,816 ----a-w E:\WINDOWS\system32\drivers\sptd.sys
2007-09-28 20:34 --------- d-----w E:\Program Files\microsoft frontpage
2007-09-06 10:09 801,144 ----a-w E:\WINDOWS\system32\aswBoot.exe
2007-09-06 10:00 95,608 ----a-w E:\WINDOWS\system32\AvastSS.scr
2007-08-21 06:25 683,520 ----a-w E:\WINDOWS\system32\inetcomm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 02:06]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="E:\WINDOWS\system32\ctfmon.exe" [2004-08-03 17:56]
"MsnMsgr"="E:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54]
"DAEMON Tools"="E:\Program Files\DAEMON Tools\daemon.exe" [2007-09-18 06:16]
"swg"="E:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-01 18:24]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"ShowDeskFix"=regsvr32 /s /n /i:u shell32
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"PcSync"=E:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"E:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"E:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
"E:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
"E:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
"E:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
E:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
E:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"E:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"E:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
E:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"E:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
"E:\Program Files\Winamp\winampa.exe"
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-11-17 18:35:01 E:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-11-16 18:31:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-16 18:31:48
.
--- E O F ---
Hijack Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:27:34, on 19-11-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20661)
Boot mode: Normal
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
E:\Program Files\Alwil Software\Avast4\ashServ.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
E:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
E:\Program Files\Bonjour\mDNSResponder.exe
E:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
E:\WINDOWS\system32\svchost.exe
E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
E:\Program Files\Alwil Software\Avast4\ashWebSv.exe
E:\Program Files\MSN Messenger\usnsvc.exe
E:\WINDOWS\Explorer.EXE
E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Program Files\MSN Messenger\MsnMsgr.Exe
E:\Program Files\DAEMON Tools\daemon.exe
E:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
E:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Program Files\HJTrenamed.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - e:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - E:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - e:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [avast!] E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "E:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "E:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [swg] E:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O8 - Extra context menu item: E&ksporter til Microsoft Excel -
res://E:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://s3.travian.dkO16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://a1540.g.akamai.net/7/1540/52/20070711/qtinstall.info.apple.com/qtactivex/qtplugin.cabO16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/FacebookPhotoUploader.cabO16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -
http://download.divx.com/player/DivXBrowserPlugin.cabO16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://javadl-esd.sun.com/update/1.6.0/jinstall-6-windows-i586.cabO23 - Service: Apple Mobile Device - Apple, Inc. - E:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - E:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - E:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - E:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - E:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LVCOMSer - Logitech Inc. - E:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - E:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - E:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: ServiceLayer - Nokia. - E:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 7007 bytes