Jeg har netop kørt Combofix på computeren, og jeg fik følgende log:
ComboFix 09-02-21.01 - Andreas 2009-02-22 11:43:08.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1030.18.447.94 [GMT 1:00]
K°rer fra: c:\documents and settings\Andreas\Skrivebord\ComboFix.exe
AV: AVG 7.5.552 *On-access scanning enabled* (Updated)
AV: TDC Kabel TV Sikkerhedspakke 6.00 *On-access scanning enabled* (Updated)
FW: TDC Kabel TV Sikkerhedspakke 6.00 *enabled*
* Dannede nyt systemgendannelsespunkt
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Autorun.inf
.
((((((((((((((((((((((((((((( Filer skabt fra 2009-01-22 til 2009-02-22 )))))))))))))))))))))))))))))))))))
.
2009-02-22 11:14 . 2001-10-04 16:35 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2009-02-22 11:14 . 2001-10-04 16:35 12,160 --a--c--- c:\windows\system32\dllcache\mouhid.sys
2009-02-22 11:14 . 2008-04-13 20:45 10,368 --a------ c:\windows\system32\drivers\hidusb.sys
2009-02-22 11:14 . 2008-04-13 20:45 10,368 --a--c--- c:\windows\system32\dllcache\hidusb.sys
2009-02-20 09:58 . 2009-02-20 09:58 25,992 --a------ c:\windows\system32\pgdfgsvc.exe
2009-02-19 22:49 . 2009-02-19 23:22 <DIR> d-------- c:\documents and settings\Andreas\Application Data\RegTool
2009-02-18 15:26 . 2009-02-18 15:26 <DIR> d-------- c:\documents and settings\LocalService\Skrivebord
2009-02-18 14:47 . 2009-02-20 10:29 <DIR> d-------- c:\programmer\Lavasoft
2009-02-18 14:47 . 2009-02-20 10:29 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-18 12:50 . 2009-02-18 12:50 <DIR> d-------- c:\documents and settings\Andreas\Application Data\Malwarebytes
2009-02-16 15:25 . 2009-02-21 20:14 <DIR> d-------- c:\documents and settings\All Users\Application Data\Google Updater
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-22 10:21 --------- d-----w c:\documents and settings\Andreas\Application Data\F-Secure
2009-02-19 20:10 --------- d-----w c:\programmer\Malwarebytes' Anti-Malware
2009-02-18 11:50 --------- d--h--w c:\programmer\InstallShield Installation Information
2009-02-18 11:12 --------- d-----w c:\programmer\Picasa2
2009-02-16 14:26 --------- d-----w c:\programmer\Google
2009-02-11 09:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 09:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-02-10 17:57 --------- d-----w c:\programmer\Java
2009-01-18 18:31 --------- d-----w c:\documents and settings\Lars\Application Data\Malwarebytes
2009-01-18 18:31 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-16 18:50 --------- d-----w c:\programmer\TDC Kabel TV Sikkerhedspakke
2009-01-16 18:49 --------- d-----w c:\documents and settings\All Users\Application Data\fssg
2009-01-16 18:47 --------- d-----w c:\documents and settings\All Users\Application Data\F-Secure
2009-01-11 18:34 --------- d-----w c:\programmer\QuickTime
2009-01-11 17:41 --------- d-----w c:\programmer\CCleaner
2007-10-12 12:18 34,752 ----a-w c:\documents and settings\Lars\Application Data\GDIPFONTCACHEV1.DAT
2007-01-18 13:26 34,752 ----a-w c:\documents and settings\Louise\Application Data\GDIPFONTCACHEV1.DAT
2006-07-16 18:02 34,752 ----a-w c:\documents and settings\Andreas\Application Data\GDIPFONTCACHEV1.DAT
2008-10-02 15:32 32,768 --sha-w c:\windows\system32\config\systemprofile\Lokale indstillinger\Oversigt\History.IE5\MSHist012008100220081003\index.dat
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemµrk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HP Component Manager"="c:\programmer\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"HPHUPD05"="c:\programmer\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-21 49152]
"HPHmon05"="c:\windows\System32\hphmon05.exe" [2003-08-21 483328]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-11 61440]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"UpdateManager"="c:\programmer\Fælles filer\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"F-Secure Manager"="c:\programmer\TDC Kabel TV Sikkerhedspakke\Common\FSM32.EXE" [2005-05-09 118833]
"F-Secure TNB"="c:\programmer\TDC Kabel TV Sikkerhedspakke\TNB\TNBUtil.exe" [2005-06-02 700416]
"F-Secure Startup Wizard"="c:\programmer\TDC Kabel TV Sikkerhedspakke\FSGUI\FSSW.EXE" [2005-07-04 352256]
"News Service"="c:\programmer\TDC Kabel TV Sikkerhedspakke\FSGUI\ispnews.exe" [2005-05-31 356352]
"AVG7_CC"="c:\progra~1\Grisoft\AVG7\avgcc.exe" [2008-10-17 590848]
"SunJavaUpdateSched"="c:\programmer\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"VTTimer"="VTTimer.exe" [2004-01-16 c:\windows\system32\VTTimer.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [2003-04-03 c:\windows\ALCXMNTR.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="c:\progra~1\Grisoft\AVG7\avgw.exe" [2007-10-24 219136]
"Picasa Media Detector"="c:\programmer\Picasa2\PicasaMediaDetector.exe" [2008-08-21 443968]
c:\documents and settings\All Users\Menuen Start\Programmer\Start\
TDC Kabel TV Sikkerhedspakke.lnk - c:\programmer\TDC Kabel TV Sikkerhedspakke\backweb\7791805\Program\fspex.exe [2005-06-07 32807]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 c:\programmer\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BackupNotify]
--a------ 2004-01-09 01:34 32768 c:\programmer\HP\Digital Imaging\bin\BackupNotify.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
--a------ 2008-04-14 17:06 110592 c:\windows\system32\bthprops.cpl
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\TDC Kabel TV Sikkerhedspakke\\backweb\\7791805\\Program\\fspex.exe"=
"c:\\Programmer\\Messenger\\msmsgs.exe"=
"c:\\Programmer\\Grisoft\\AVG7\\avginet.exe"=
"c:\\Programmer\\Grisoft\\AVG7\\avgamsvr.exe"=
"c:\\Programmer\\Grisoft\\AVG7\\avgcc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmer\\MSN Messenger\\livecall.exe"=
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2005-06-07 70224]
R2 BackWeb Plug-in - 7791805;TDC Kabel TV Sikkerhedspakke;c:\progra~1\TDCKAB~1\backweb\7791805\Program\SERVIC~1.EXE [2005-06-07 32807]
R2 F-Secure Filter;F-Secure File System Filter;c:\programmer\TDC Kabel TV Sikkerhedspakke\Anti-Virus\win2k\FSfilter.sys [2005-06-07 48720]
R2 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\programmer\TDC Kabel TV Sikkerhedspakke\Anti-Virus\win2k\fsgk.sys [2005-06-07 62176]
R2 F-Secure Recognizer;F-Secure File System Recognizer;c:\programmer\TDC Kabel TV Sikkerhedspakke\Anti-Virus\win2k\FSrec.sys [2005-06-07 16848]
--- Andre Services/Drivers i Hukommelsen ---
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - srservice
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - TapiSrv
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - W32Time
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
.
Indhold af mappen 'Planlagte Opgaver'
2009-02-18 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\programmer\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []
2009-02-22 c:\windows\Tasks\Google Software Updater.job
- c:\programmer\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-16 15:24]
2009-02-20 c:\windows\Tasks\RegTool Scan.job
- c:\programmer\RegTool\RegTool.exe []
2009-02-20 c:\windows\Tasks\RegTool Scan.job
- c:\programmer\RegTool []
2009-02-22 c:\windows\Tasks\Scheduled scanning task.job
- c:\progra~1\TDCKAB~1\ANTI-V~1\fsav.exe [2005-05-24 15:42]
2009-02-19 c:\windows\Tasks\WebReg 20040912175908.job
- c:\programmer\HP\Digital Imaging\bin\hpqwrg.exe [2003-07-07 08:43]
.
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.com/mDefault_Search_URL =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=Q304&bd=pavilion&pf=desktopmSearch Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=Q304&bd=pavilion&pf=desktopmSearch Bar =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=Q304&bd=pavilion&pf=desktopIE: &Bloker dette pop up-vindue - c:\programmer\TDC Kabel TV Sikkerhedspakke\Anti-Spyware\blockpopups.htm
DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} -
hxxps://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-02-22 11:50:30
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemf°rt med succes
skjulte filer: 0
**************************************************************************
.
--------------------- DLLs startet under k°rende Processer ---------------------
- - - - - - - > 'winlogon.exe'(668)
c:\windows\system32\igfxsrvc.dll
c:\windows\system32\hccutils.DLL
.
Gennemf°rt tid: 2009-02-22 11:56:32
ComboFix-quarantined-files.txt 2009-02-22 10:56:24
Pre-K°rsel: 97.945.088.000 byte ledig
Post-K°rsel: 98,531,155,968 byte ledig
170 --- E O F --- 2009-02-21 19:38:37