Her er en log fra combofix - håber nogen vil tjekke den (samt hijackthisloggen) (dette er gjort ud fra Fromsejs artikel).
Den siger at der er ikke er genoprettelseskonsol på pc'en, og undervejs spurgte den om jeg ville installere det (jeg trykkede nej). Hvad er genoprettelseskonsol, og er det noget der er god at have?
Jeg har fået IE explorer til at virke igen, efter at have slettet version 8 helt i Ccleaner.
ComboFix 08-10-30.12 - Jørgen V 2008-10-31 15:35:30.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1030.18.1382 [GMT 1:00]
Kører fra: C:\Documents and Settings\Jørgen V\Skrivebord\Oprydning 28 okober 2008\ComboFix.exe
* Dannede nyt systemgendannelsespunkt
* Resident AV is active
[COLOR=RED][B]advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !![/B][/COLOR]
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Lisbeth Baggesen\Lokale indstillinger\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\WINDOWS\system32\x64
.
((((((((((((((((((((((((((((( Filer skabt fra 2008-09-28 til 2008-10-31 )))))))))))))))))))))))))))))))))))
.
2008-10-31 15:17 . 2008-10-31 15:17 <DIR> d-------- C:\WINDOWS\LastGood
2008-10-29 18:21 . 2008-10-29 18:21 1,393 --a------ C:\WINDOWS\imsins.BAK
2008-10-29 17:44 . 2008-10-29 17:44 61,440 --a------ C:\WINDOWS\system32\drivers\nfzm.sys
2008-10-29 06:25 . 2008-10-29 06:25 <DIR> d-------- C:\Programmer\Trend Micro
2008-10-28 22:00 . 2008-10-28 22:00 <DIR> d-------- C:\Programmer\Malwarebytes' Anti-Malware
2008-10-28 22:00 . 2008-10-22 16:10 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-28 22:00 . 2008-10-22 16:10 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-25 14:42 . 2008-10-25 14:42 <DIR> d-------- C:\Programmer\RocketDock
2008-10-24 15:17 . 2008-10-15 17:37 337,408 -----c--- C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-23 19:59 . 2008-10-23 19:58 410,976 --a------ C:\WINDOWS\system32\deploytk.dll
2008-10-21 17:29 . 2008-10-25 22:20 <DIR> d-------- C:\Documents and Settings\Jørgen V\Application Data\dvdcss
2008-10-16 19:56 . 2008-10-29 20:26 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-10-16 19:56 . 2008-10-16 19:56 1,409 --a------ C:\WINDOWS\QTFont.for
2008-10-16 18:13 . 2008-09-08 11:41 333,824 -----c--- C:\WINDOWS\system32\dllcache\srv.sys
2008-10-16 18:12 . 2008-08-14 14:25 2,191,744 -----c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-16 18:12 . 2008-08-14 14:25 2,147,840 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-16 18:12 . 2008-08-14 14:25 2,068,608 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-16 18:12 . 2008-08-14 14:25 2,026,496 -----c--- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-16 18:12 . 2008-09-15 16:27 1,846,400 -----c--- C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-12 11:39 . 2008-10-12 11:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WinZip
2008-10-09 21:30 . 2008-10-09 21:30 <DIR> d-------- C:\Documents and Settings\Jørgen V\Application Data\TomTom
2008-10-09 21:29 . 2008-10-09 21:29 <DIR> d-------- C:\Programmer\TomTom HOME 2
2008-10-09 21:03 . 2008-10-09 21:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TomTom
2008-10-09 21:02 . 2008-10-09 21:29 <DIR> d-------- C:\Programmer\TomTom HOME
2008-10-05 11:08 . 2008-10-05 11:08 <DIR> d-------- C:\105d34ca6e8fa9de33
2008-10-04 22:21 . 2008-10-04 22:21 <DIR> d-------- C:\Documents and Settings\Lisbeth Baggesen\PrivacIE
2008-10-04 12:56 . 2008-10-04 12:56 <DIR> d-------- C:\Documents and Settings\Jørgen V\PrivacIE
2008-10-04 12:56 . 2008-10-04 12:56 <DIR> d-------- C:\Documents and Settings\Jørgen V\PrivacIE
2008-09-14 15:54 . 2008-09-14 15:54 76,512 --ah----- C:\WINDOWS\system32\mlfcache.dat
2008-09-08 17:25 . 2008-09-08 17:25 <DIR> d-------- C:\Programmer\CyberLink
2008-09-08 17:25 . 2008-09-08 17:25 <DIR> d-------- C:\MyWorks
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-31 14:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-31 13:34 --------- d-----w C:\Documents and Settings\Jørgen V\Application Data\OnlineArmor
2008-10-31 09:02 --------- d-----w C:\Documents and Settings\Lisbeth Baggesen\Application Data\OpenOffice.org2
2008-10-31 09:02 --------- d-----w C:\Documents and Settings\Lisbeth Baggesen\Application Data\OnlineArmor
2008-10-29 17:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-29 16:44 138 ----a-w C:\Programmer\autut.txt
2008-10-27 15:47 --------- d-----w C:\Documents and Settings\Jørgen V\Application Data\Vso
2008-10-26 21:12 --------- d-----w C:\Documents and Settings\Jørgen V\Application Data\Skype
2008-10-25 13:30 --------- d-----w C:\Programmer\DVDFab 5
2008-10-23 18:58 --------- d-----w C:\Programmer\Java
2008-10-22 21:07 --------- d-----w C:\Programmer\Google
2008-10-22 21:04 --------- d-----w C:\Documents and Settings\Jørgen V\Application Data\Ashampoo Photo Commander 4
2008-10-22 16:07 --------- d-----w C:\Programmer\Microsoft Silverlight
2008-10-21 19:24 --------- d-----w C:\Programmer\Yahoo!
2008-10-14 14:42 --------- d-----w C:\Programmer\Windows Live Safety Center
2008-10-14 13:53 --------- d--h--w C:\Programmer\InstallShield Installation Information
2008-10-14 12:00 --------- d-----w C:\Programmer\Apple Software Update
2008-10-14 11:59 --------- d-----w C:\Programmer\Fælles filer\Wise Installation Wizard
2008-10-11 10:08 --------- d-----w C:\Programmer\nLite
2008-10-09 23:18 --------- d-----w C:\Documents and Settings\Gæst\Application Data\OnlineArmor
2008-10-05 10:10 --------- d-----w C:\Programmer\Spybot - Search & Destroy
2008-09-15 15:27 1,846,400 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-08 16:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-30 11:29 --------- d-----w C:\Programmer\Microsoft System Center Configuration Manager 2007 R2 Client Security Configuration Pack
2008-08-28 20:05 97,928 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-26 08:27 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 13:25 2,191,744 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:25 2,068,608 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-05 15:55 265,720 ----a-w C:\WINDOWS\system32\msdbg2.dll
2008-07-25 20:21 10,520 ----a-w C:\WINDOWS\system32\avgrsstx.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-18 18:39 586,752 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-07-07 20:29 253,952 ----a-w C:\WINDOWS\system32\es.dll
2007-05-07 21:38 284 ----a-w C:\Documents and Settings\Jørgen V\Application Data\ViewerApp.dat
2007-05-04 19:48 87,520 ----a-w C:\Documents and Settings\Jørgen V\Application Data\GDIPFONTCACHEV1.DAT
2007-04-18 17:21 87,608 ----a-w C:\Documents and Settings\Jørgen V\Application Data\ezpinst.exe
2007-04-18 17:21 47,360 ----a-w C:\Documents and Settings\Jørgen V\Application Data\pcouffin.sys
2008-06-01 09:54 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Lokale indstillinger\Oversigt\History.IE5\MSHist012008060120080602\index.dat
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-29 68856]
"SpybotSD TeaTimer"="C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"SODCPreLoad"="C:\Programmer\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.0.1.20080130-2132\preload.exe" [2008-02-11 40960]
"Google Update"="C:\Documents and Settings\Jørgen V\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe" [2008-10-23 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Programmer\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"SynTPLpr"="C:\Programmer\Synaptics\SynTP\SynTPLpr.exe" [2005-03-10 98394]
"SynTPEnh"="C:\Programmer\Synaptics\SynTP\SynTPEnh.exe" [2005-03-10 688218]
"ControlCenter3"="C:\Programmer\Brother\ControlCenter3\brctrcen.exe" [2006-04-10 61440]
"BrMfcWnd"="C:\Programmer\Brother\Brmfcmon\BrMfcWnd.exe" [2006-03-28 622592]
"IntelZeroConfig"="C:\Programmer\Intel\Wireless\bin\ZCfgSvc.exe" [2006-11-08 802816]
"IntelWireless"="C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe" [2006-11-08 696320]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-29 1234712]
"OnlineArmor GUI"="C:\Programmer\Tall Emu\Online Armor\oaui.exe" [2008-04-17 5545536]
"SunJavaUpdateSched"="C:\Programmer\Java\jre6\bin\jusched.exe" [2008-10-23 144792]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2007-12-11 286720]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\FLLESF~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
C:\Documents and Settings\Lisbeth Baggesen\Menuen Start\Programmer\Start\
OpenOffice.org 2.1.lnk - C:\Programmer\OpenOffice.org 2.1\program\quickstart.exe [2006-12-01 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"NoDispCPL"= 0 (0x0)
"NoDispSettingsPage"= 0 (0x0)
"NoDispScrSavPage"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
"NoResolveTrack"= 0 (0x0)
"NoViewContextMenu"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoFind"= 0 (0x0)
"NoRun"= 0 (0x0)
"NoClose"= 0 (0x0)
"StartMenuLogoff"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "C:\PROGRA~1\TALLEM~1\ONLINE~1\oaevent.dll" [2008-04-17 671432]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Windows SteadyState]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MPFExe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"swg"=C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" -atboottime
"Genvej til egenskabsside for High Definition Audio"=HDAShCut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"!AVG Anti-Spyware"="C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
"Persistence"=C:\WINDOWS\system32\igfxpers.exe
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe
"SecurDisc"=C:\Programmer\Nero\Nero 7\InCD\NBHGui.exe
"AGRSMMSG"=AGRSMMSG.exe
"Alcmtr"=ALCMTR.EXE
"FLMOFFICE4DMOUSE"=C:\Programmer\Trust\MI-4550XP WIRELESS OPTICAL MINI MOUSE\Mouse32a.exe
"IMEKRMIG6.1"=C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
"RTHDCPL"=RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Programmer\\Messenger\\msmsgs.exe"=
"C:\\Programmer\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmer\\Windows Live\\Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmer\\iTunes\\iTunes.exe"=
"C:\\Programmer\\AVG\\AVG8\\avgupd.exe"=
"C:\\Programmer\\Skype\\Phone\\Skype.exe"=
R0 hotcore2;hotcore2;C:\WINDOWS\system32\drivers\hotcore2.sys [2007-02-03 30808]
R0 hotcore3;hotcore3;C:\WINDOWS\system32\drivers\hotcore3.sys [2007-05-04 38448]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-28 97928]
R1 OADevice;OADriver;C:\WINDOWS\system32\drivers\OADriver.sys [2008-04-17 80584]
R1 OAmon;OAmon;C:\WINDOWS\system32\drivers\OAmon.sys [2008-04-17 32456]
R1 OAnet;OAnet;C:\WINDOWS\system32\drivers\OAnet.sys [2008-04-17 28872]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-28 231704]
R2 JavaQuickStarterService;Java Quick Starter;C:\Programmer\Java\jre6\bin\jqs.exe [2008-10-23 147456]
R2 SvcOnlineArmor;Online Armor;C:\Programmer\Tall Emu\Online Armor\oasrv.exe [2008-04-17 5435968]
R2 Windows SteadyState;Windows SteadyState Service;C:\Programmer\Windows SteadyState\SCTSvc.exe [2007-06-05 97280]
S3 mxInsMon;mxInsMon;C:\PROGRA~1\ALADDI~1\INTERN~1\mxInsMon.sys [ ]
S3 UMSSSTOR;C-Media Storage;C:\WINDOWS\system32\DRIVERS\UMSS.SYS [2004-07-13 48512]
S3 USBAAPL;Apple Mobile USB Driver;C:\WINDOWS\system32\Drivers\usbaapl.sys [2007-10-31 30464]
.
Indhold af mappen 'Planlagte Opgaver'
2008-10-31 C:\WINDOWS\Tasks\GoogleUpdateTaskUser.job
- C:\Documents and Settings\J []
2008-10-31 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Programmer\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
2008-10-31 C:\WINDOWS\Tasks\User_Feed_Synchronization-{D13F4B85-70FA-433B-9FD8-23C6B85D3069}.job
- C:\WINDOWS\system32\msfeedssync.exe [2007-08-13 18:36]
.
- - - - TOMME GENVEJE FJERNET - - - -
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
Notify-!SASWinLogon - (no file)
.
------- Yderligere scanning -------
.
FireFox -: Profile - C:\Documents and Settings\Jørgen V\Application Data\Mozilla\Firefox\Profiles\
0h82g4d6.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:da:officialFF -: plugin - C:\Documents and Settings\Jørgen V\Lokale indstillinger\Application Data\Google\Update\1.2.131.25\npGoogleOneClick6.dll
FF -: plugin - C:\Programmer\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Programmer\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - C:\Programmer\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - c:\Programmer\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30716.0.dll
FF -: plugin - c:\Programmer\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF -: plugin - C:\Programmer\Mozilla Firefox\plugins\npdeploytk.dll
FF -: plugin - C:\Programmer\Mozilla Firefox\plugins\NPZoneSB.dll
FF -: plugin - C:\Programmer\Yahoo!\Common\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-31 15:47:49
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\C:\WINDOWS\TEMP\mc21.tmp"
.
Gennemført tid: 2008-10-31 15:53:47
ComboFix-quarantined-files.txt 2008-10-31 14:52:48
ComboFix2.txt 2007-07-24 05:24:31
Pre-Kørsel: 9.491.386.368 byte ledig
Post-Kørsel: 9,883,557,888 byte ledig
239 --- E O F --- 2008-10-29 18:48:33