Det jeg mente med at Combofix ikke virkede for mig var at den flere steder i processen meddelte at den ikke havde rettigheder til at tilgå visse filer. Også selvom jeg havde valgt at den skulle kører som administrator i Vista.
Men et eller andet må den jo have gjort må jeg jo konstatere
Har lige kørt combofix igen:
ComboFix 08-04-03.3 - Administrator 2008-04-03 19:53:07.1 - NTFSx86
Microsoft® Windows Vista™ Business 6.0.6000.0.1252.1.1030.18.880 [GMT 2:00]
Running from: C:\Users\Administrator\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((( Files Created from 2008-03-03 to 2008-04-03 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-03 17:58 --------- d-----w C:\Program Files\McAfee
2008-04-03 17:58 --------- d-----w C:\PROGRA~2\VMware
2008-04-03 17:29 --------- d-----w C:\Users\Administrator\AppData\Roaming\VMware
2008-04-03 16:46 --------- d-----w C:\Users\Administrator\AppData\Roaming\TeraCopy
2008-04-03 14:31 --------- d-----w C:\Users\Administrator\AppData\Roaming\Ahead
2008-04-02 22:02 --------- d-----w C:\Program Files\Yahoo!
2008-04-02 22:01 --------- d-----w C:\Program Files\CCleaner
2008-04-02 21:51 --------- d-----w C:\Program Files\Common Files\Ahead
2008-04-02 21:25 --------- d-----w C:\Program Files\Nero
2008-04-02 21:25 --------- d-----w C:\PROGRA~2\Nero
2008-04-02 13:39 --------- d-----w C:\Program Files\Siemens
2008-04-02 13:39 --------- d-----w C:\Program Files\Common Files\Siemens
2008-04-02 13:39 --------- d-----w C:\Program Files\Common Files\Plantronics
2008-04-02 13:39 --------- d-----w C:\PROGRA~2\Siemens
2008-04-02 13:35 --------- d-----w C:\Program Files\Microsoft WSE
2008-04-02 13:35 --------- d-----w C:\PROGRA~2\Microsoft Help
2008-04-01 20:10 --------- d-----w C:\Program Files\QuickTime
2008-04-01 19:50 --------- d-----w C:\Program Files\Trend Micro
2008-04-01 13:57 --------- d-----w C:\PROGRA~2\Symantec
2008-04-01 13:54 --------- d-----w C:\Users\Administrator\AppData\Roaming\Symantec
2008-04-01 13:54 --------- d-----w C:\Program Files\Symantec
2008-04-01 13:54 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-01 12:23 --------- d-----w C:\Program Files\CyberLink
2008-04-01 12:17 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-01 12:08 --------- d-----w C:\PROGRA~2\CyberLink
2008-04-01 11:52 --------- d-----w C:\Program Files\Microsoft.NET
2008-04-01 11:51 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-04-01 11:24 --------- d-----w C:\Program Files\Google
2008-04-01 10:17 --------- d-----w C:\PROGRA~2\Spybot - Search & Destroy
2008-04-01 09:54 --------- d-----w C:\Program Files\Safer Networking
2008-04-01 09:46 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-04-01 05:17 --------- d-----w C:\Users\Administrator\AppData\Roaming\Uniblue
2008-03-31 20:38 --------- d-----w C:\Program Files\Uniblue
2008-03-31 20:10 --------- d-----w C:\PROGRA~2\Kaspersky Lab
2008-03-19 09:13 --------- d-----w C:\Users\Administrator\AppData\Roaming\Nokia
2008-03-15 14:48 --------- d-----w C:\Program Files\Java
2008-03-13 14:19 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-03-12 08:03 --------- d-----w C:\Program Files\Windows Mail
2008-03-12 07:42 --------- d-----w C:\Program Files\Common Files\Nero
2008-03-05 12:46 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-02-15 07:32 --------- d-----w C:\Users\Administrator\AppData\Roaming\Nero
2008-02-13 10:20 --------- d-----w C:\Users\Administrator\AppData\Roaming\Barak's SignMe!
2008-02-13 10:19 --------- d-----w C:\Program Files\SignME
2008-02-12 21:03 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
2008-02-12 21:02 54,784 ----a-w C:\Windows\system32\drivers\i8042prt.sys
2008-02-12 21:02 495,160 ----a-w C:\Windows\system32\drivers\Wdf01000.sys
2008-02-12 21:02 35,384 ----a-w C:\Windows\system32\drivers\WdfLdr.sys
2008-02-12 21:02 35,384 ----a-w C:\Windows\system32\drivers\kbdclass.sys
2008-02-12 21:02 34,360 ----a-w C:\Windows\system32\drivers\mouclass.sys
2008-02-12 21:02 19,968 ----a-w C:\Windows\system32\drivers\sermouse.sys
2008-02-12 21:02 15,872 ----a-w C:\Windows\system32\drivers\mouhid.sys
2008-02-12 21:00 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
2008-02-12 21:00 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
2008-02-12 21:00 17,976 ----a-w C:\Windows\system32\drivers\intelide.sys
2008-02-12 21:00 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
2008-02-12 21:00 110,136 ----a-w C:\Windows\system32\drivers\ataport.sys
2008-02-12 20:59 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-02-12 20:59 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-12 20:59 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-12 20:59 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
2008-02-12 20:59 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-12 20:59 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-12 20:57 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-09 19:47 --------- d-----w C:\Program Files\Symbian OS Tools
2008-02-09 19:47 --------- d-----w C:\Program Files\Common Files\Symbian
2008-02-09 19:46 --------- d-----w C:\Users\Administrator\AppData\Roaming\InstallShield
2008-02-03 21:09 --------- d-----w C:\Program Files\SlySoft
2008-02-03 08:51 --------- d-----w C:\Users\Administrator\AppData\Roaming\SiteAdvisor
2008-01-25 20:40 2,923,520 ----a-w C:\Windows\explorer.exe
2008-01-25 19:00 319,456 ----a-w C:\Windows\DIFxAPI.dll
2008-01-25 19:00 315,392 ----a-w C:\Windows\HideWin.exe
2008-01-25 18:33 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 14:35 2159104 C:\Windows\System32\oobefldr.dll]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"DU Meter"="C:\Program Files\DU Meter\DUMeter.exe" [2007-10-17 03:54 2582288]
"FjWirSel"="C:\Program Files\Fujitsu\WirelessSelector\FJWSLauncher.exe" [2006-12-05 01:16 122880]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-04-09 15:32 154392]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-04-09 15:32 133912]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-01 09:38 4390912 C:\Windows\RtHDVCpl.exe]
"IndicatorUtility"="C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" [2006-11-07 15:45 97072]
"LoadFUJ02E3"="C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe" [2006-11-17 16:38 80688]
"LoadFujitsuQuickTouch"="C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe" [2006-11-25 18:09 260912]
"LoadBtnHnd"="C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe" [2006-11-12 17:13 68400]
"TvOutSwitch"="C:\Program Files\Fujitsu\DispSwitch\DispSwitchLauncher.exe" [2006-11-17 16:35 81920]
"SSUtility"="C:\Program Files\Fujitsu\SSUtility\FJSSDMN.exe" [2006-11-13 04:02 239144]
"PSUtility"="C:\Program Files\Fujitsu\PSUtility\TrayManager.exe" [2006-10-30 17:37 136744]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 23:33 582992]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" [2007-08-24 23:57 36640]
"McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [2007-11-30 06:42 1164576]
"vmware-tray"="C:\Program Files\VMware\VMware Workstation\vmware-tray.exe" [2007-10-08 10:27 72240]
"VMware hqtray"="C:\Program Files\VMware\VMware Workstation\hqtray.exe" [2007-10-08 10:26 55856]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 04:06 40048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 18:35 1294336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
PCANotify.dll 2007-04-27 12:10 18744 C:\Windows\System32\PCANotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\Windows\system32\cbXNHWOi.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2007-08-24 08:00 33648 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
--a------ 2007-05-11 03:08 2512392 C:\Windows\system32\oodtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
--a------ 2007-12-10 11:12 695808 C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{2E24F832-9329-412C-943B-DD2246397472}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{2842777B-2C07-404B-9814-9C5434EBBF34}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{F174DCAE-9C2D-4A82-8B22-2FCDA48249CC}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{82DC50D1-EF4C-4A5D-A2E4-55E400AE35F5}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{99E63319-442F-4A1F-B3EA-4AB101AEC7D1}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{081EF062-6DBF-418A-9335-96E608D651F8}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{72662E8F-2FD0-4898-98CA-E4371FFCB760}C:\\program files\\nokia\\nokia software updater\\nsu_ui_client.exe"= UDP:C:\program files\nokia\nokia software updater\nsu_ui_client.exe:Nokia Software Updater
"UDP Query User{A2C95B75-560F-4E6C-B3EF-DC000DD149F5}C:\\program files\\nokia\\nokia software updater\\nsu_ui_client.exe"= TCP:C:\program files\nokia\nokia software updater\nsu_ui_client.exe:Nokia Software Updater
"TCP Query User{0D694238-91D2-4C3C-9503-8D7077A6A6AE}C:\\program files\\common files\\nokia\\service layer\\a\\nsl_host_process.exe"= UDP:C:\program files\common files\nokia\service layer\a\nsl_host_process.exe:Nokia Service Layer Host Process
"UDP Query User{0E8BE770-4422-4208-A672-152F0F739663}C:\\program files\\common files\\nokia\\service layer\\a\\nsl_host_process.exe"= TCP:C:\program files\common files\nokia\service layer\a\nsl_host_process.exe:Nokia Service Layer Host Process
"{F50D3B75-B173-40B2-9F1E-EFC063920DB5}"= Profile=Private|Profile=Public|C:\Program Files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
"{A06B8B5D-0918-43C3-BD52-9C2F8EF560A5}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{66B3BC38-6BE8-4163-8AD2-5390FF593FB1}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 FJGSDisk;G-Sensor Application Filter Driver;C:\Windows\system32\DRIVERS\FJGSDisk.sys [2008-01-25 21:08]
R0 O2MDRDR;O2MDRDR;C:\Windows\system32\DRIVERS\o2media.sys [2006-10-03 16:23]
R0 O2SDRDR;O2SDRDR;C:\Windows\system32\DRIVERS\o2sd.sys [2006-10-12 13:47]
R2 DUMeterSvc;DU Meter Service;C:\Program Files\DU Meter\DUMeterSvc.exe [2007-10-15 16:19]
R2 PowerSavingUtilityService;PowerSavingUtilityService;C:\Program Files\Fujitsu\PSUtility\PSUService.exe [2006-10-30 17:37]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2006-10-31 23:40]
R2 WirelessSelectorService;WirelessSelectorService;C:\Program Files\Fujitsu\WirelessSelector\WSUService.exe [2006-12-05 01:06]
R3 AVMCOWAN;AVM ISDN CoNDIS WAN CAPI Driver;C:\Windows\system32\DRIVERS\AVMCOWAN.sys [2006-11-02 09:30]
R3 FPCMBASE;FRITZ!Card PCMCIA;C:\Windows\system32\DRIVERS\fpcmbase.sys [2006-11-02 09:30]
R3 FUJ02E3;Fujitsu FUJ02E3 Device Driver;C:\Windows\system32\DRIVERS\FUJ02E3.sys [2006-11-01 20:59]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-03-30 12:57]
R3 KeyScrambler;KeyScrambler;C:\Windows\system32\drivers\keyscrambler.sys [2007-12-29 16:35]
R3 SMSCIRDA;SMSC Infrared Device Driver;C:\Windows\system32\DRIVERS\SMSCirda.sys [2007-04-25 14:32]
S3 FMCardService;HiPath Cardserver;C:\Program Files\Siemens\HiPathCardManager\FMCardServ.exe [2007-02-14 19:58]
S3 USBAAPL;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl.sys [2008-01-15 03:39]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
GPSvcGroup REG_MULTI_SZ GPSvc
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-03 19:58:24
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\Windows\Explorer.exe
-> C:\Program Files\SiteAdvisor\6253\saHook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\VirusScan\McShield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Windows\system32\oodag.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\Windows\system32\vmnat.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\Program Files\RealVNC\VNC4\winvnc4.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
C:\Windows\system32\vmnetdhcp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
.
**************************************************************************
.
Completion time: 2008-04-03 20:00:55 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-03 18:00:47
ComboFix2.txt 2008-04-01 11:44:29
ComboFix3.txt 2008-04-01 10:58:16
Systemet kan ikke finde meddelelsesteksten for meddelelsesnummer 0x2379 i meddelelsesfilen for Application.
Systemet kan ikke finde meddelelsesteksten for meddelelsesnummer 0x2379 i meddelelsesfilen for Application.
.
2008-03-27 07:14:48 --- E O F ---