Adware. Tracking Cookie!!
Hey alle i kloge hoveder!Jeg har desvaerre faaet mig lidt virus paa min computer. Jeg haaber i har mulighed for at hjaelpe mig.
Jeg har loggen for SAS, Hijack og Combofix her:
SAS:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 08/09/2008 at 01:59 AM
Application Version : 4.15.1000
Core Rules Database Version : 3530
Trace Rules Database Version: 1520
Scan type : Complete Scan
Total Scan Time : 01:07:14
Memory items scanned : 183
Memory threats detected : 0
Registry items scanned : 5064
Registry threats detected : 10
File items scanned : 18258
File threats detected : 1
Browser Hijacker.Internet Explorer Settings Hijack
HKU\S-1-5-21-746137067-1935655697-839522115-1003\Software\Microsoft\Internet Explorer\Main#Search Page [ http://internetsearchservice.com ]
HKLM\Software\Microsoft\Internet Explorer\Main#Search Page [ http://internetsearchservice.com ]
HKU\S-1-5-21-746137067-1935655697-839522115-1003\Software\Microsoft\Internet Explorer\Main#Default_Search_URL [ http://internetsearchservice.com ]
HKLM\Software\Microsoft\Internet Explorer\Main#Default_Search_URL [ http://internetsearchservice.com ]
HKU\S-1-5-21-746137067-1935655697-839522115-1003\Software\Microsoft\Internet Explorer\Main#Search Bar [ http://internetsearchservice.com/ie6.html ]
HKLM\Software\Microsoft\Internet Explorer\Main#Search Bar [ http://internetsearchservice.com/ie6.html ]
Trojan.Media-Codec
HKU\S-1-5-21-746137067-1935655697-839522115-1003\Software\Web Technologies
Adware.E404 Helper/Hij
HKCR\CLSID\e405.e405mgr
HKCR\CLSID\e405.e405mgr#UserId
Rogue.AntiSpyCheck
HKU\S-1-5-21-746137067-1935655697-839522115-1003\Software\ASpyC
Adware.E404 Helper/Variant-E
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9275ED1F-C7CE-449C-B5E0-6CBC868399AC}\RP86\A0057755.DLL
Hijack:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:04:01 AM, on 8/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\ProxyPlus\ProxyPlus.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Expedience.exe
C:\Documents and Settings\gaby\Desktop\Clean PC\HiJackThis.exe
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.truehomepages.com/?cm=95685<=1&it=2008-07-28%2015%3A27%3A13&dt=2008-08-07%2017%3A16%3A38&q=about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://internetsearchservice.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://internetsearchservice.com
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Expedience.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://plugin.driveragent.com/files/driveragent.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Fortech Proxy+ (ProxyPlus) - FORTECH Ltd. - C:\Program Files\ProxyPlus\ProxyPlus.exe
--
End of file - 5416 bytes
Combofix:
ComboFix 08-08-08.04 - gaby 2008-08-09 2:06:47.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1575 [GMT 3:00]
Running from: C:\Documents and Settings\gaby\Desktop\Clean PC\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\gaby\My Documents\My Documents.url
C:\Documents and Settings\gaby\My Documents\My Music\My Music.url
C:\Documents and Settings\gaby\My Documents\My Pictures\My Pictures.url
C:\WINDOWS\system32\kdbup.exe
C:\WINDOWS\system32\x64
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-07-08 to 2008-08-08 )))))))))))))))))))))))))))))))
.
2008-08-08 23:22 . 2008-08-08 23:22 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-08-08 23:09 . 2008-08-08 23:09 <DIR> d-------- C:\Program Files\CCleaner
2008-08-08 21:09 . 2008-08-08 21:09 0 --a------ C:\WINDOWS\nsreg.dat
2008-08-08 20:26 . 2008-08-08 20:26 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-08-08 20:26 . 2008-08-08 20:26 <DIR> d-------- C:\Documents and Settings\gaby\Application Data\SUPERAntiSpyware.com
2008-08-08 20:26 . 2008-08-08 20:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-08-07 22:21 . 2008-08-07 22:21 <DIR> d-------- C:\Program Files\ReflexiveArcade
2008-08-01 06:31 . 2008-08-01 06:31 <DIR> d-------- C:\WINDOWS\system32\734914
2008-07-30 07:27 . 2008-07-30 07:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-07-30 01:47 . 2006-09-05 19:03 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-07-30 01:36 . 2006-01-01 11:04 10,027 --a------ C:\WINDOWS\system32\mspriv32.dll
2008-07-30 01:32 . 2008-07-30 01:29 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-07-30 01:32 . 2008-07-30 01:30 298,104 --a------ C:\WINDOWS\system32\imon.dll
2008-07-30 01:32 . 2008-07-30 01:28 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2008-07-30 01:30 . 2008-08-08 21:52 <DIR> d-------- C:\Program Files\TrojanHunter 4.6
2008-07-30 01:30 . 2008-07-30 01:30 <DIR> d-------- C:\Documents and Settings\gaby\Application Data\TrojanHunter
2008-07-30 01:27 . 2008-08-09 02:06 <DIR> d-------- C:\Program Files\ESET
2008-07-30 00:08 . 2008-07-30 00:09 <DIR> d-------- C:\Program Files\ProxyPlus
2008-07-29 23:47 . 2008-07-29 23:47 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-29 23:47 . 2008-07-29 23:47 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-07-29 23:47 . 2008-07-29 23:47 2,162 --a------ C:\WINDOWS\system32\tmmute.ini
2008-07-29 02:40 . 2008-07-29 02:40 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-07-29 01:27 . 2008-08-09 00:33 <DIR> d-------- C:\WINDOWS\system32\804031
2008-07-28 01:36 . 2008-07-28 01:36 219,952 --a------ C:\utorrent.exe
2008-07-28 01:33 . 2008-07-28 02:41 <DIR> d-------- C:\Program Files\Ares Vista
2008-07-28 01:31 . 2008-07-28 01:31 1,717,638 --a------ C:\Ares_Installer.exe
2008-07-27 00:38 . 2008-07-27 00:38 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-07-25 21:59 . 2008-07-25 21:59 <DIR> d-------- C:\Program Files\Motorola
2008-07-25 16:12 . 2004-08-04 10:56 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-07-25 16:12 . 2004-08-04 08:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-07-25 16:12 . 2004-08-04 08:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-07-25 16:12 . 2001-08-18 08:36 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-07-25 12:23 . 2008-07-25 12:23 223,128 --a------ C:\WINDOWS\system32\drivers\dtscsi.sys
2008-07-25 12:20 . 2008-07-25 12:20 664,064 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-07-25 12:20 . 2008-07-25 12:20 96,256 --a------ C:\WINDOWS\system32\drivers\sptd8797.sys
2008-07-25 12:04 . 2008-07-25 12:04 <DIR> d-------- C:\AFTER
2008-07-25 04:35 . 2008-07-25 04:35 <DIR> d-------- C:\Program Files\Common Files\DirectX
2008-07-24 22:34 . 2008-04-14 17:51 54,272 --a------ C:\Program Files\keygen.exe
2008-07-24 21:40 . 2008-07-24 21:40 137,344 --a------ C:\WINDOWS\system32\drivers\hwpsgt.sys
2008-07-24 21:40 . 2008-07-24 21:40 9,472 --a------ C:\WINDOWS\system32\drivers\lemsgt.sys
2008-07-23 16:35 . 2008-04-23 07:16 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-07-23 16:35 . 2007-04-17 12:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-07-23 16:35 . 2007-03-08 08:10 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-07-23 16:35 . 2008-04-23 07:16 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-07-23 16:35 . 2008-04-23 07:16 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-07-23 16:35 . 2008-04-23 07:16 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-07-23 16:35 . 2008-04-23 07:16 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-07-23 16:35 . 2008-04-23 07:16 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-07-23 16:35 . 2008-04-22 10:39 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-07-15 21:43 . 2008-07-15 21:43 <DIR> d-------- C:\Program Files\AVerMedia
2008-07-13 22:15 . 2008-07-13 22:15 0 --a------ C:\copy
2008-07-13 22:14 . 2008-07-13 22:14 0 --a------ C:\new
2008-07-13 22:11 . 2008-07-01 02:20 7,551,392 --a------ C:\MetacafeSetup1.3.28.0.r.exe
2008-07-13 22:11 . 2008-07-10 03:28 5,004,557 --a------ C:\Mr Bean At The Pool [from www.metacafe.com].avi
2008-07-13 22:11 . 862,407 C:\[from www.metacafe.com].swf
2008-07-13 10:12 . 2008-07-13 10:12 35 --a------ C:\WINDOWS\Worldbuilder.INI
2008-07-11 02:49 . 2000-03-29 17:17 5,824 --a------ C:\WINDOWS\system32\drivers\ASUSHWIO.SYS
2008-07-11 00:40 . 2005-01-28 23:44 5,525,504 --a------ C:\WINDOWS\system32\setb6.tmp
2008-07-11 00:37 . 2008-07-11 00:37 <DIR> d-------- C:\K-Lite Codec Pack
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-08 23:12 --------- d-----w C:\Program Files\Common Files\Akamai
2008-08-08 17:25 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-08 14:32 65,536 ----a-w C:\WINDOWS\DUMPde98.tmp
2008-08-08 14:29 65,536 ----a-w C:\WINDOWS\DUMPb90f.tmp
2008-08-08 14:28 65,536 ----a-w C:\WINDOWS\DUMPb7f5.tmp
2008-08-08 14:26 65,536 ----a-w C:\WINDOWS\DUMPb778.tmp
2008-08-08 14:25 65,536 ----a-w C:\WINDOWS\DUMPb815.tmp
2008-08-08 14:24 65,536 ----a-w C:\WINDOWS\DUMPbdb2.tmp
2008-08-07 19:06 --------- d-----w C:\Documents and Settings\gaby\Application Data\Metacafe
2008-08-07 19:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Metacafe
2008-07-29 20:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-24 19:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-21 19:28 --------- d-----w C:\Documents and Settings\gaby\Application Data\My Battle for Middle-earth(tm) II Files
2008-07-06 21:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-06-30 23:21 --------- d-----w C:\Program Files\Metacafe
2008-06-28 16:46 --------- d-----w C:\Program Files\AutoCAD 2002
2008-06-20 18:45 --------- d-----w C:\Documents and Settings\gaby\Application Data\Media Player Classic
2008-06-20 18:44 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-08 18:37 --------- d-----w C:\Documents and Settings\gaby\Application Data\CyberLink
2008-06-08 18:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-06-08 18:25 --------- d-----w C:\Program Files\CyberLink
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2006-11-06 22:46 2854912 --a------ C:\Program Files\Protector Suite QL\farchns.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2006-11-06 22:46 2854912 --a------ C:\Program Files\Protector Suite QL\farchns.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-01-01 03:00 15360]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-03-24 05:20 185896]
"ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2006-11-30 18:50 112216]
"McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 23:39 136768]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-07-30 01:28 949376]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2008-07-30 06:23 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-01-01 03:00 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Expedience.exe [2007-07-11 06:11:08 2052096]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2006-11-06 22:34 52224 C:\WINDOWS\system32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"msacm.ac3filter"= ac3filter.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Monitor.lnk
backup=C:\WINDOWS\pss\Bluetooth Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Expedience.exe]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Expedience.exe
backup=C:\WINDOWS\pss\Expedience.exeCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^gaby^Start Menu^Programs^Startup^Trend Micro Anti-Spyware.lnk]
path=C:\Documents and Settings\gaby\Start Menu\Programs\Startup\Trend Micro Anti-Spyware.lnk
backup=C:\WINDOWS\pss\Trend Micro Anti-Spyware.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACU]
--a------ 2005-12-09 04:49 323584 C:\Program Files\Atheros\ACU.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-01-01 03:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-27 11:47 31016 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2008-02-15 23:46 159744 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2008-02-15 23:46 135168 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
--a------ 2006-08-02 11:32 696320 C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
--a------ 2006-08-02 11:38 802816 C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--------- 2007-03-15 07:01 54832 C:\Program Files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 22:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
--a------ 2001-07-09 21:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
--a------ 2008-02-15 23:46 131072 C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PINGER]
--a------ 2006-07-20 23:45 151552 C:\Toshiba\IVP\ISM\pinger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSQLLauncher]
--a------ 2006-11-06 22:13 49168 C:\Program Files\Protector Suite QL\launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 2007-03-15 07:01 71216 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-03-24 05:20 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinDVR SchSvr]
--a------ 2004-09-09 06:51 106496 C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=3 (0x3)
"wscsvc"=2 (0x2)
"WLSetupSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"Swupdtmr"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"Microsoft Office Groove Audit Service"=3 (0x3)
"IDriverT"=3 (0x3)
"gusvc"=3 (0x3)
"crd"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"ACS"=2 (0x2)
"TODDSrv"=2 (0x2)
"S24EventMonitor"=2 (0x2)
"RegSrvc"=2 (0x2)
"EvtEng"=2 (0x2)
"RichVideo"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"C:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"D:\\Program Files\\half life on 192.168.0.1 on 172.17.0.98\\cstrike.exe"=
"D:\\Program Files\\Warcraft III\\War3.exe"=
"D:\\TrackMania Nations ESWC\\TmNationsESWC.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9420:TCP"= 9420:TCP:Red Swoosh
"5000:UDP"= 5000:UDP:Red Swoosh
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\000.fcl [2007-09-20 07:37]
R2 Akamai;Akamai;C:\WINDOWS\System32\svchost.exe [2004-01-01 03:00]
R2 ProxyPlus;Fortech Proxy+;C:\Program Files\ProxyPlus\ProxyPlus.exe [2008-07-30 00:08]
R3 BoiHwsetup;Access 32bits INT15 routine;C:\WINDOWS\system32\drivers\BoiHwSetup.sys [2006-10-12 20:18]
R3 expedience-service;Expedience Wireless Broadband Non-line-of-sight (NLOS) Internet Access Device;C:\WINDOWS\system32\DRIVERS\nnmeriden.sys [2007-06-22 21:57]
R3 qkbfiltr;Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\qkbfiltr.sys [2006-11-21 05:14]
S3 Cap7134;SinoVideo PCI 2309 Cap7134 Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys [2005-08-21 06:11]
S3 PhTVTune;SinoVideo WDM TVTuner;C:\WINDOWS\system32\DRIVERS\Silicon.sys [2005-08-21 06:11]
S4 crd;crd;C:\DOCUME~1\gaby\LOCALS~1\Temp\IXP001.TMP\poststp.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{421d2781-3e22-11dd-ad25-001302d259fc}]
\Shell\AutoRun\command - F:\8de.bat
\Shell\explore\Command - F:\8de.bat
\Shell\open\Command - F:\8de.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e556e5ce-08be-11dd-aca0-001302d259fc}]
\Shell\AutoRun\command - F:\gjn2pjlw.exe
\Shell\explore\Command - F:\gjn2pjlw.exe
\Shell\open\Command - F:\gjn2pjlw.exe
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-Advanced DHTML Enable - C:\document.exe
MSConfigStartUp-Antivirus - C:\Program Files\WAV\wav.exe
MSConfigStartUp-ASpyC - C:\Program Files\ASpyC\ASpyC.exe
MSConfigStartUp-AVG7_CC - C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
MSConfigStartUp-CLHomeMediaServer - d:\Program Files\CyberLink\CyberLink Live\CLHomeMediaServer.exe
MSConfigStartUp-Client Server Runtime Process - C:\WINDOWS\system32\csrs.exe
MSConfigStartUp-Load - C:\WINDOWS\svchost.exe
MSConfigStartUp-Power DVD Player - C:\Program Files\Power DVD Player\PowerDVDPlayer.exe
MSConfigStartUp-wblogon - C:\WINDOWS\system32\ubpr01.exe
MSConfigStartUp-High Definition Audio Property Page Shortcut - CHDAudPropShortcut.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\gaby\Application Data\Mozilla\Firefox\Profiles\9ud3towi.default\
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjava11.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjava12.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjava13.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjava14.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjava32.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npoji610.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-09 02:12:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Akamai]
"ServiceDll"="C:/Program Files/Common Files/Akamai/rswin_3333.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Akamai]
"ServiceDll"="C:/Program Files/Common Files/Akamai/rswin_3333.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\C:\Program Files\CyberLink\PowerDVD\000.fcl"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\ESET\nod32krn.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\McAfee\Common Framework\Mctray.exe
.
**************************************************************************
.
Completion time: 2008-08-09 2:19:16 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-08 23:19:13
Pre-Run: 96,810,217,472 bytes free
Post-Run: 96,894,128,128 bytes free
305 --- E O F --- 2008-07-29 20:47:10
Haaber i kan hjaelpe.
Med Venlig Hilsen
Rob