rense sønnens computer
Efter jeg med held fik renset datterens pc i sidste uge vil sønnen nu også gerne have sådan en "hovedrengøring".Jeg har fulgt samme procedure og har nu en Combo.fix fil, hvis der er en der gider kigge på denne og gøre det fornødne:
ComboFix 08-06-20.4 - Yoggi 2008-07-01 18:02:20.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1030.18.1977 [GMT 2:00]
Running from: C:\Users\Yoggi\Downloads\Protection\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-06-01 to 2008-07-01 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-01 16:01 --------- d-----w C:\Users\Yoggi\AppData\Roaming\DNA
2008-07-01 14:57 --------- d-----w C:\Users\Yoggi\AppData\Roaming\Malwarebytes
2008-07-01 14:57 --------- d-----w C:\ProgramData\Malwarebytes
2008-07-01 14:57 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-07-01 11:05 --------- d-----w C:\Program Files\Password Agent
2008-06-30 23:34 --------- d-----w C:\Program Files\Cheat Engine
2008-06-30 17:37 --------- d-----w C:\ProgramData\iOpus-i-M
2008-06-30 17:37 --------- d-----w C:\Program Files\iMacros
2008-06-30 16:38 --------- d-----w C:\ProgramData\Yahoo! Companion
2008-06-30 16:11 --------- d-----w C:\Users\Yoggi\AppData\Roaming\SUPERAntiSpyware.com
2008-06-30 16:11 --------- d-----w C:\ProgramData\SUPERAntiSpyware.com
2008-06-30 16:11 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-06-30 16:11 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-30 16:08 --------- d-----w C:\Program Files\Yahoo!
2008-06-30 16:08 --------- d-----w C:\Program Files\CCleaner
2008-06-30 15:34 --------- d-----w C:\ProgramData\Lavasoft
2008-06-30 15:33 --------- d-----w C:\Program Files\Lavasoft
2008-06-30 15:32 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-06-30 14:47 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-30 12:31 --------- d-----w C:\Users\Yoggi\AppData\Roaming\BitTorrent
2008-06-29 19:08 --------- d-----w C:\Users\Yoggi\AppData\Roaming\LimeWire
2008-06-28 12:16 34,296 ----a-w C:\Windows\system32\drivers\mbamcatchme.sys
2008-06-28 12:16 17,144 ----a-w C:\Windows\system32\drivers\mbam.sys
2008-06-27 22:56 --------- d-----w C:\Program Files\7-Zip
2008-06-27 14:13 --------- d-----w C:\Program Files\PicLensIE
2008-06-18 18:39 --------- d-----w C:\Program Files\Intel Corporation
2008-06-16 16:57 --------- d-----w C:\Program Files\AC3Filter
2008-06-15 00:12 --------- d-----w C:\Users\Yoggi\AppData\Roaming\EVEMon
2008-06-13 18:13 --------- d-----w C:\Program Files\Xilisoft
2008-06-13 17:45 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-13 17:44 --------- d-----w C:\Program Files\Google
2008-06-13 17:27 --------- d-----w C:\Program Files\DNA
2008-06-13 17:27 --------- d-----w C:\Program Files\BitTorrent
2008-06-12 19:13 --------- d-----w C:\Program Files\Windows Mail
2008-06-10 15:57 --------- d-----w C:\ProgramData\NVIDIA
2008-06-09 18:41 --------- d-----w C:\Users\Yoggi\AppData\Roaming\vlc
2008-06-09 18:33 --------- d-----w C:\Program Files\VideoLAN
2008-06-08 11:16 --------- d-----w C:\ProgramData\Messenger Plus!
2008-06-08 10:05 --------- d-----w C:\Program Files\CCP
2008-06-07 23:28 --------- d-----w C:\Program Files\EVEMon
2008-06-07 20:10 --------- d---a-w C:\ProgramData\TEMP
2008-06-07 15:17 --------- d-----w C:\Users\Yoggi\AppData\Roaming\DivX
2008-06-07 15:16 --------- d-----w C:\Program Files\DivX
2008-06-07 15:15 --------- d-----w C:\Program Files\Common Files\PX Storage Engine
2008-06-07 11:29 174 --sha-w C:\Program Files\desktop.ini
2008-06-07 11:24 --------- d-----w C:\Program Files\Windows Sidebar
2008-06-07 11:24 --------- d-----w C:\Program Files\Windows Defender
2008-06-07 11:24 --------- d-----w C:\Program Files\Windows Calendar
2008-06-07 01:01 87,040 ----a-w C:\Windows\System32\msoert2.dll
2008-06-07 01:01 39,424 ----a-w C:\Windows\System32\ACCTRES.dll
2008-06-07 01:01 205,824 ----a-w C:\Windows\System32\msoeacct.dll
2008-06-07 01:00 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2008-06-07 01:00 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2008-06-07 01:00 542,720 ----a-w C:\Windows\System32\sysmain.dll
2008-06-07 01:00 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2008-06-07 01:00 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2008-06-07 01:00 297,984 ----a-w C:\Windows\System32\wlansec.dll
2008-06-07 01:00 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
2008-06-07 01:00 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2008-06-07 01:00 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2008-06-07 01:00 2,923,520 ----a-w C:\Windows\explorer.exe
2008-06-07 00:59 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-06-07 00:59 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
2008-06-07 00:58 49,664 ----a-w C:\Windows\System32\csrsrv.dll
2008-06-07 00:58 376,320 ----a-w C:\Windows\System32\winsrv.dll
2008-06-07 00:55 41,984 ----a-w C:\Windows\system32\drivers\monitor.sys
2008-06-07 00:55 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
2008-06-07 00:54 374,456 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll
2008-06-07 00:53 414,208 ----a-w C:\Windows\System32\msscp.dll
2008-06-07 00:52 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
2008-06-07 00:52 7,680 ----a-w C:\Windows\System32\spwmp.dll
2008-06-07 00:52 4,096 ----a-w C:\Windows\System32\dxmasf.dll
2008-06-07 00:52 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll
2008-06-07 00:51 86,016 ----a-w C:\Windows\System32\icfupgd.dll
2008-06-07 00:51 63,488 ----a-w C:\Windows\system32\drivers\mpsdrv.sys
2008-06-07 00:51 61,952 ----a-w C:\Windows\System32\cmifw.dll
2008-06-07 00:51 396,800 ----a-w C:\Windows\System32\MPSSVC.dll
2008-06-07 00:51 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll
2008-06-07 00:51 23,040 ----a-w C:\Windows\system32\drivers\tunnel.sys
2008-06-07 00:51 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll
2008-06-07 00:51 16,896 ----a-w C:\Windows\System32\wfapigp.dll
2008-06-07 00:51 15,360 ----a-w C:\Windows\system32\drivers\TUNMP.SYS
2008-06-07 00:50 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
2008-06-07 00:50 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-06-07 00:50 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-06-07 00:50 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
2008-06-07 00:50 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
2008-06-07 00:50 17,464 ----a-w C:\Windows\system32\drivers\intelide.sys
2008-06-07 00:50 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
2008-06-07 00:50 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys
2008-06-07 00:50 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
2008-06-07 00:49 2,048 ----a-w C:\Windows\System32\msxml3r.dll
2008-06-07 00:49 104,448 ----a-w C:\Windows\System32\DWWIN.EXE
2008-06-07 00:49 1,191,936 ----a-w C:\Windows\System32\msxml3.dll
2008-06-07 00:48 8,704 ----a-w C:\Windows\System32\hcrstco.dll
2008-06-07 00:48 8,704 ----a-w C:\Windows\System32\hccoin.dll
2008-06-07 00:48 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys
2008-06-07 00:48 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys
2008-06-07 00:48 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys
2008-06-07 00:48 23,040 ----a-w C:\Windows\system32\drivers\usbuhci.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA}]
2008-06-13 17:24 2084864 --a------ C:\Program Files\PicLensIE\PicLens.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-06-07 02:37 1232896]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"BitTorrent DNA"="C:\Users\Yoggi\Program Files\DNA\btdna.exe" [2008-06-13 19:49 289088]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-16 01:19 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2008-06-09 23:22 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-06-09 23:22 8530464]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-06-09 23:22 81920]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 10:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{CC7CDC43-AC8C-4C52-897D-48A5C09AA7DE}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{ADEAF152-4E74-46E2-ADC8-E50514DB3F19}C:\\program files\\ccp\\eve\\bin\\exefile.exe"= UDP:C:\program files\ccp\eve\bin\exefile.exe:CCP ExeFile
"UDP Query User{B6B6CDF2-91EC-4E24-BC1D-49362136F5C3}C:\\program files\\ccp\\eve\\bin\\exefile.exe"= TCP:C:\program files\ccp\eve\bin\exefile.exe:CCP ExeFile
"TCP Query User{9339CB30-7B43-42BB-8712-D565A718F6FA}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{A59F5263-9AAC-488D-842C-74954D52AE27}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{12D06FAA-089C-492C-9A6F-C8401BC87EB2}C:\\eve2\\bin\\exefile.exe"= UDP:C:\eve2\bin\exefile.exe:CCP ExeFile
"UDP Query User{F771BE93-C544-4769-A4A9-2E228A393766}C:\\eve2\\bin\\exefile.exe"= TCP:C:\eve2\bin\exefile.exe:CCP ExeFile
"{53412CCD-2026-4E1F-A2DA-F31DB902CCBF}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{D05F5423-8061-4707-9BE2-6AF456C87159}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
"{C765EA13-1D0A-4276-8739-5ED7501DCC93}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{288B8C84-D405-48CC-9873-1BC49DC0F2AA}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{9E4764C2-C83D-4494-9535-4D6AC22C7CF7}C:\\users\\yoggi\\program files\\dna\\btdna.exe"= UDP:C:\users\yoggi\program files\dna\btdna.exe:btdna.exe
"UDP Query User{5E3207DD-A9A6-4C71-88D4-62EE8EE62682}C:\\users\\yoggi\\program files\\dna\\btdna.exe"= TCP:C:\users\yoggi\program files\dna\btdna.exe:btdna.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-05-16 01:18]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;C:\Windows\system32\DRIVERS\atl01v32.sys [2006-11-15 16:24]
R3 rt61x86;Linksys Wireless-G PCI Adapter Driver;C:\Windows\system32\DRIVERS\WMP54Gv41x86.sys [2007-03-12 10:00]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd780fb9-3eb8-11dd-baee-001a92bd0550}]
\shell\AutoRun\command - patty.exe
\shell\explore\Command - patty.exe
\shell\find\Command - patty.exe
\shell\open\Command - patty.exe
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-01 18:04:12
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-01 18:05:00
ComboFix-quarantined-files.txt 2008-07-01 16:04:54
ComboFix2.txt 2008-07-01 16:00:33
Systemet kan ikke finde meddelelsesteksten for meddelelsesnummer 0x2379 i meddelelsesfilen for Application.
Systemet kan ikke finde meddelelsesteksten for meddelelsesnummer 0x2379 i meddelelsesfilen for Application.
180 --- E O F --- 2008-06-26 10:55:24