COMBOFIX LOG:
ComboFix 08-12-14.03 - Ejer 2008-12-25 12:20:43.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1030.18.447.163 [GMT 1:00]
Kører fra: c:\documents and settings\Ejer\Skrivebord\ComboFix.exe
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((((((( Filer skabt fra 2008-11-25 til 2008-12-25 )))))))))))))))))))))))))))))))))))
.
2008-12-25 12:19 . 2008-12-25 12:19 <DIR> d-------- C:\32788R22FWJFW
2008-12-24 10:21 . 2008-12-24 10:21 0 --a------ c:\windows\nsreg.dat
2008-12-14 22:16 . 2008-12-14 22:16 <DIR> d-------- c:\programmer\Malwarebytes' Anti-Malware
2008-12-14 22:16 . 2008-12-03 19:59 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-14 22:16 . 2008-12-03 19:59 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-14 22:14 . 2008-12-14 22:14 <DIR> d-------- c:\programmer\CCleaner
2008-12-14 22:03 . 2008-12-14 22:03 <DIR> d-------- c:\programmer\Trend Micro
2008-12-14 20:34 . 2008-12-14 20:34 <DIR> d-------- c:\documents and settings\Ejer\Application Data\Malwarebytes
2008-12-14 20:34 . 2008-12-14 20:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-25 11:17 --------- d-----w c:\documents and settings\Ejer\Application Data\Skype
2008-12-14 21:08 --------- d-----w c:\programmer\Quiz Academy
2008-12-14 21:07 --------- d-----w c:\programmer\Mario
2008-12-13 14:15 --------- d-----w c:\programmer\MSN Messenger
2008-12-13 09:24 --------- d-----w c:\programmer\Fælles filer\Symantec Shared
2008-11-23 12:37 --------- d-----w c:\programmer\Skype
2008-11-23 12:37 --------- d-----w c:\documents and settings\Ejer\Application Data\skypePM
2008-11-23 12:37 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2008-11-23 12:36 --------- d-----w c:\programmer\Fælles filer\Skype
2008-11-22 09:38 --------- d-----w c:\documents and settings\Ejer\Application Data\AdobeUM
2008-10-23 12:41 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:18 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-03 10:03 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2004-11-22 16:55 31,640 ----a-w c:\documents and settings\Ejer\Application Data\GDIPFONTCACHEV1.DAT
2004-07-30 16:53 32 --sha-w c:\windows\{13414AE3-5A5F-46E0-9EA4-D66FE3ADED35}.dat
2004-07-30 16:53 32 --sha-w c:\windows\system32\{B6E70F76-C43F-44E1-9910-A04620AB148F}.dat
2008-09-17 03:49 32,768 --sha-w c:\windows\system32\config\systemprofile\Lokale indstillinger\Oversigt\History.IE5\MSHist012008091720080918\index.dat
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BackupNotify"="c:\programmer\HP\Digital Imaging\bin\backupnotify.exe" [2004-01-09 32768]
"Acme.PCHButton"="c:\progra~1\HPPAVI~1\Pavilion\XPHWWBP4\plugin\bin\PCHButton.exe" [2004-01-01 155648]
"OM_Monitor"="c:\programmer\OLYMPUS\OLYMPUS Master\Monitor.exe" [2005-07-19 57344]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Creative WebCam Tray"="c:\programmer\Creative\Shared Files\CamTray.exe" [2005-10-27 299008]
"BlazeServoTool"="c:\programmer\BlazeVideo\BlazeDTV 2.5a\MediaDetector.exe" [2007-03-07 270336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HPHUPD05"="c:\programmer\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-21 49152]
"HPHmon05"="c:\windows\System32\hphmon05.exe" [2003-08-21 483328]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-11 61440]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2003-11-03 221184]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2005-05-20 100056]
"hcenter"="c:\programmer\Support.com\bin\tgcmd.exe" [2005-04-08 1757184]
"QuickTime Task"="c:\programmer\QuickTime\qttask.exe" [2006-10-03 77824]
"OM_Monitor"="c:\programmer\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2005-07-19 40960]
"Adobe Photo Downloader"="c:\programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"PaperPort PTD"="c:\programmer\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-18 57393]
"IndexSearch"="c:\programmer\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-18 40960]
"BrMfcWnd"="c:\programmer\Brother\Brmfcmon\BrMfcWnd.exe" [2006-03-28 622592]
"SetDefPrt"="c:\programmer\Brother\Brmfl06a\BrStDvPt.exe" [2005-01-26 49152]
"ControlCenter3"="c:\programmer\Brother\ControlCenter3\brctrcen.exe" [2006-04-10 61440]
"Adobe Reader Speed Launcher"="c:\programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"VTTimer"="VTTimer.exe" [2003-08-20 c:\windows\system32\VTTimer.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [2003-04-03 c:\windows\ALCXMNTR.EXE]
c:\documents and settings\All Users\Menuen Start\Programmer\Start\
HP Digital Imaging Monitor.lnk - c:\programmer\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 237568]
Microsoft Office.lnk - c:\programmer\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
NETGEAR WG111v2 Smart Wizard.lnk - c:\programmer\NETGEAR\WG111v2\WG111v2.exe [2008-03-08 1261568]
WG111v2 Smart Wizard Wireless Setting.lnk - c:\programmer\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe [2007-09-29 745472]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\Messenger\\msmsgs.exe"=
"c:\\Programmer\\Support.com\\bin\\tgcmd.exe"=
"c:\\Programmer\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmer\\MSN Messenger\\livecall.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
R2 ccPxySvc;Symantec Proxy Service;"c:\programmer\Norton Personal Firewall\ccPxySvc.exe" [2004-08-13 34024]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\DRIVERS\EAPPkt.sys [2007-09-29 66048]
S1 as6eio;as6eio;c:\windows\system32\drivers\as6eio.sys []
S3 EC168BDA;EC168BDA service;c:\windows\system32\DRIVERS\EC168BDA.sys [2008-08-01 107264]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys [2008-03-08 272128]
S3 V0260VID;Live! Cam Vista IM;c:\windows\system32\DRIVERS\V0260Vid.sys [2006-10-22 162176]
.
Indhold af mappen 'Planlagte Opgaver'
2008-12-14 c:\windows\Tasks\Norton AntiVirus - Skan Denne computer - Ejer.job
- c:\progra~1\NORTON~1\NAVW32.EXE [2003-12-10 13:00]
2008-12-19 c:\windows\Tasks\Norton AntiVirus - Skan Denne computer.job
- c:\progra~1\NORTON~1\Navw32.exe [2003-12-10 13:00]
2008-12-25 c:\windows\Tasks\Symantec NetDetect.job
- c:\programmer\Symantec\LiveUpdate\NDETECT.EXE [2005-02-01 17:20]
2008-12-25 c:\windows\Tasks\User_Feed_Synchronization-{EB0578D7-D12F-4EE5-A9BD-2B99578A23D7}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 11:58]
.
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.dk/uInternet Settings,ProxyOverride = <local>
O16 -: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} -
hxxps://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exec:\windows\Downloaded Program Files\e-Safekey.dll - O16 -: {D8575CE3-3432-4540-88A9-85A1325D3375}
hxxps://netbank.bgbank.dk/html/activex/e-Safekey/BG/e-Safekey.cabc:\windows\Downloaded Program Files\e-Safekey.inf
FF - ProfilePath - c:\documents and settings\Ejer\Application Data\Mozilla\Firefox\Profiles\ux8x0o9v.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.dk/FF - plugin: c:\programmer\Java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\programmer\Java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\programmer\Java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\programmer\Java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\programmer\Java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\programmer\Java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\programmer\Java\j2re1.4.2_03\bin\NPOJI610.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-25 12:21:16
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
Gennemført tid: 2008-12-25 12:23:09
ComboFix-quarantined-files.txt 2008-12-25 11:22:39
ComboFix2.txt 2008-12-15 21:36:52
ComboFix3.txt 2008-12-14 21:02:59
Pre-Kørsel: 138.752.991.232 byte ledig
Post-Kørsel: 138,742,837,248 byte ledig
153 --- E O F --- 2008-12-13 00:07:23