Det er tilladt at *SUKKE* der er plads til det . . . ta' en smiley !!!
OBS: advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !! --> OG DET LYKKEDES MIG IKKE AT INSTALLERE DEN UNDER KØRSEL MED COMBOFIX. Jeg kunne ikke få netadgang.
KAN JEG MANUELT INSTALLERE GENOPRETTELSESKONSOL ?????
COMBOFIX log er her
ComboFix 09-02-04.01 - Torben Haslund 2009-02-06 23:21:12.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.45.1030.18.1013.559 [GMT 1:00]
Kører fra: c:\documents and settings\Torben Haslund\Skrivebord\Spywarefri\combofix\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\Torben Haslund\Skrivebord\Spywarefri\combofix\CFScript.txt
AV: F-Secure Anti-Virus Client Security 6.03 *On-access scanning disabled* (Updated)
* Dannede nyt systemgendannelsespunkt
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Torben Haslund\Application Data\.#
c:\windows\system32\bcacce4_d.dll
c:\windows\system32\bcfba0_g.dll
.
((((((((((((((((((((((((((((( Filer skabt fra 2009-01-06 til 2009-02-06 )))))))))))))))))))))))))))))))))))
.
2009-02-04 15:22 . 2009-02-04 15:22 <DIR> d-------- c:\documents and settings\Torben Haslund\Application Data\Malwarebytes
2009-02-04 15:21 . 2009-02-04 17:05 <DIR> d-------- c:\programmer\Malwarebytes' Anti-Malware
2009-02-04 15:21 . 2009-02-04 15:21 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-04 15:21 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-04 15:21 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-03 22:08 . 2009-02-03 22:09 <DIR> d-------- c:\programmer\Fighters
2009-02-03 22:08 . 2009-02-03 22:08 <DIR> d-------- c:\documents and settings\All Users\Application Data\Fighters
2009-02-03 21:45 . 2009-02-03 21:45 <DIR> d-------- c:\programmer\Secunia
2009-02-03 17:32 . 2009-02-06 17:12 <DIR> d-------- c:\programmer\Exterminate It!
2009-02-02 14:16 . 2009-02-02 14:16 <DIR> d-------- C:\fsaua.data
2009-02-02 13:35 . 2009-02-02 13:35 <DIR> d-------- c:\documents and settings\LocalService\Application Data\SACore
2009-02-02 12:54 . 2009-02-02 12:54 <DIR> d-------- c:\programmer\Fælles filer\McAfee
2009-02-02 12:53 . 2009-02-02 14:10 <DIR> d-------- c:\programmer\McAfee
2009-02-02 12:42 . 2009-02-02 13:29 <DIR> d-------- c:\documents and settings\Torben Haslund\Application Data\SiteAdvisor
2009-02-02 12:42 . 2009-02-02 12:42 <DIR> d-------- c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-02-02 12:42 . 2009-02-02 12:54 <DIR> d-------- c:\documents and settings\All Users\Application Data\McAfee
2009-02-01 22:26 . 2009-02-01 21:22 15,688 --a------ c:\windows\system32\lsdelete.exe
2009-02-01 21:22 . 2009-02-01 21:22 64,160 --a------ c:\windows\system32\drivers\Lbd.sys
2009-02-01 21:19 . 2009-02-01 21:19 <DIR> d-------- c:\programmer\Lavasoft
2009-02-01 21:19 . 2009-02-01 21:19 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-01-18 18:36 . 2009-01-18 18:36 <DIR> d-------- c:\programmer\Bonjour
2009-01-18 18:36 . 2009-01-18 18:36 <DIR> d-------- c:\programmer\Apple Software Update
2009-01-18 18:36 . 2009-01-18 18:36 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple
2009-01-16 12:39 . 2009-01-16 12:39 <DIR> d-------- c:\documents and settings\Torben Haslund\Application Data\Sync App Settings
2009-01-16 12:37 . 2009-01-16 12:37 <DIR> d-------- c:\documents and settings\All Users\Application Data\Sync App Settings
2009-01-16 12:36 . 2009-01-16 12:37 <DIR> d-------- c:\programmer\Allway Sync
2009-01-12 12:27 . 2009-01-12 13:42 83 --a------ c:\windows\topocr.INI
2009-01-12 12:20 . 2009-01-12 12:20 <DIR> d-------- c:\programmer\TopOCR
2009-01-12 11:20 . 2009-01-12 11:20 <DIR> d-------- c:\programmer\ToniArts
2009-01-12 10:50 . 2009-01-12 10:50 <DIR> d-------- c:\programmer\MSECache
2009-01-10 23:45 . 2009-01-10 23:46 2,622 --a------ c:\windows\DevMgr.ini
2009-01-10 23:44 . 2001-10-04 17:07 324,608 --a------ c:\windows\system32\hpojwia.dll
2009-01-10 23:44 . 2001-10-04 17:07 324,608 --a--c--- c:\windows\system32\dllcache\hpojwia.dll
2009-01-10 23:44 . 2008-04-13 11:39 206,976 --a------ c:\windows\system32\drivers\Dot4.sys
2009-01-10 23:44 . 2008-04-13 11:39 206,976 --a--c--- c:\windows\system32\dllcache\dot4.sys
2009-01-10 23:44 . 2001-10-04 16:40 23,936 --a------ c:\windows\system32\drivers\Dot4usb.sys
2009-01-10 23:44 . 2001-10-04 16:40 23,936 --a--c--- c:\windows\system32\dllcache\dot4usb.sys
2009-01-10 23:44 . 2001-08-17 21:47 12,928 --a------ c:\windows\system32\drivers\Dot4Prt.sys
2009-01-10 23:44 . 2001-08-17 21:47 12,928 --a--c--- c:\windows\system32\dllcache\dot4prt.sys
2009-01-10 23:44 . 2001-08-17 21:47 8,704 --a------ c:\windows\system32\drivers\Dot4scan.sys
2009-01-10 23:44 . 2001-08-17 21:47 8,704 --a--c--- c:\windows\system32\dllcache\dot4scan.sys
2009-01-10 23:38 . 2002-11-20 18:52 90,112 --a------ c:\windows\system32\hpocon09.exe
2009-01-10 23:38 . 2002-11-20 18:52 22,139 --a------ c:\windows\system32\hpocoi08.dll
2009-01-10 23:38 . 2009-01-10 23:38 20 --a------ c:\windows\Hposcv07.INI
2009-01-10 22:35 . 2001-07-22 04:27 18,411 --a------ c:\windows\system32\hpo5500a.aio
2009-01-10 22:35 . 2001-07-22 04:27 18,411 --a------ c:\windows\system32\hpo5400a.aio
2009-01-10 22:35 . 2001-07-22 04:27 18,411 --a------ c:\windows\system32\hpo5300a.aio
2009-01-10 22:07 . 2009-01-10 22:07 <DIR> d-------- c:\programmer\Hewlett-Packard
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-03 08:42 --------- d-----w c:\programmer\Mplus
2009-01-15 10:48 --------- d-----w c:\programmer\SkoleKom
2009-01-12 10:20 --------- d--h--w c:\programmer\InstallShield Installation Information
2009-01-08 10:24 --------- d-----w c:\programmer\Java
2008-12-29 12:41 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-28 19:00 118,842 ------r c:\windows\bwUnin-6.3.2.116-7681197L.exe
2008-12-28 19:00 --------- d-----w c:\programmer\F-Secure
2008-12-28 19:00 --------- d-----w c:\documents and settings\All Users\Application Data\F-Secure
2008-12-28 17:05 --------- d-----w c:\programmer\CCleaner
2008-12-27 10:54 --------- d-----w c:\programmer\RegSupreme Pro
2008-12-27 10:53 --------- d-----w c:\programmer\Windows Media Connect 2
2008-12-27 10:53 --------- d-----w c:\programmer\GeoGebra
2008-12-17 09:29 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-12-12 10:18 87,336 ----a-w c:\windows\system32\dns-sd.exe
2008-12-12 10:11 65,536 ----a-w c:\windows\system32\jdns_sd.dll
2008-12-12 10:11 61,440 ----a-w c:\windows\system32\dnssd.dll
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-10 14:17 7,808 ----a-w c:\windows\system32\drivers\psi_mf.sys
2008-12-07 08:46 --------- d-----w c:\programmer\Yahoo!
2008-11-10 04:43 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-11-15 19:25 122,880 ----a-w c:\programmer\mozilla firefox\components\GoogleDesktopMozilla.dll
2008-08-23 09:37 8 --sh--r c:\windows\system32\3901020172.sys
2008-11-03 17:10 4,026 --sha-w c:\windows\system32\KGyGaAvL.sys
2008-08-25 01:05 32,768 --sha-w c:\windows\system32\config\systemprofile\Lokale indstillinger\Application Data\Microsoft\Feeds Cache\index.dat
2008-10-29 18:27 32,768 --sha-w c:\windows\system32\config\systemprofile\Lokale indstillinger\Oversigt\History.IE5\MSHist012008102920081030\index.dat
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-15 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"SynTPEnh"="c:\programmer\Synaptics\SynTP\SynTPEnh.exe" [2008-01-11 1028096]
"MGSysCtrl"="c:\programmer\System Control Manager\MGSysCtrl.exe" [2008-06-10 782336]
"Google Desktop Search"="c:\programmer\Google\Google Desktop Search\GoogleDesktop.exe" [2008-11-15 29744]
"toolbar_eula_launcher"="c:\program files\GoogleEULA\EULALauncher.exe" [2007-02-09 16896]
"Adobe Reader Speed Launcher"="c:\programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"F-Secure Manager"="c:\programmer\F-Secure\Common\FSM32.EXE" [2005-10-26 122929]
"F-Secure TNB"="c:\programmer\F-Secure\TNB\TNBUtil.exe" [2004-05-27 684032]
"SunJavaUpdateSched"="c:\programmer\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\F-Secure\\BackWeb\\7681197\\program\\F-Secure Automatic Update.exe"=
"c:\\Programmer\\Bonjour\\mDNSResponder.exe"=
R0 iaStor;Intel AHCI Controller;c:\windows\system32\drivers\iaStor.sys [2007-09-29 308248]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-01 64160]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI;c:\windows\system32\drivers\wmiacpi.sys [2008-05-26 8832]
R2 F-Secure Filter;F-Secure File System Filter;c:\programmer\F-Secure\Anti-Virus\win2k\FSfilter.sys [2008-12-28 48816]
R2 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\programmer\F-Secure\Anti-Virus\win2k\fsgk.sys [2008-12-28 48256]
R2 F-Secure Recognizer;F-Secure File System Recognizer;c:\programmer\F-Secure\Anti-Virus\win2k\FSrec.sys [2008-12-28 16720]
R2 FSMA;F-Secure Management Agent;c:\programmer\F-Secure\common\FSMA32.EXE [2008-12-28 61490]
R2 JavaQuickStarterService;Java Quick Starter;c:\programmer\Java\jre6\bin\jqs.exe [2008-12-02 152984]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\programmer\McAfee\SiteAdvisor\McSACore.exe [2009-02-02 206096]
R2 Micro Star SCM;Micro Star SCM;c:\programmer\System Control Manager\MSIService.exe [2008-08-23 159744]
R2 ProtexisLicensing;ProtexisLicensing;c:\windows\system32\PSIService.exe [2006-11-02 174656]
R2 PTK License-FIGHTERS-37333603;PTK License-FIGHTERS-37333603;c:\programmer\Fighters\LicenseService.exe [2008-11-18 283272]
R2 PTK Live Update-FIGHTERS-37333603;PTK Live Update-FIGHTERS-37333603;c:\programmer\Fighters\UpdateService.exe [2008-11-18 307848]
R2 PTK Scanner-FIGHTERS-37333603;PTK Scanner-FIGHTERS-37333603;c:\programmer\Fighters\ScannerService.exe [2008-11-18 311944]
R2 PTK SharedAccess-FIGHTERS-37333603;PTK SharedAccess-FIGHTERS-37333603;c:\programmer\Fighters\ConfigService.exe [2008-11-18 139912]
R2 RichVideo;Cyberlink RichVideo Service(CRVS);c:\programmer\Cyberlink\Shared files\RichVideo.exe [2008-05-28 171040]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service;c:\programmer\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2007-02-02 118784]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [2008-08-23 156160]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver;c:\windows\system32\drivers\Rtenicxp.sys [2008-05-26 106368]
R3 SynTP;Synaptics TouchPad Driver;c:\windows\system32\drivers\SynTP.sys [2008-05-26 220128]
R3 Vfscan;Vfscan;c:\windows\system32\drivers\vffilter.sys [2008-11-18 15496]
S2 BackWeb Plug-in - 7681197;F-Secure Automatic Update;c:\progra~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE [2008-12-28 32807]
S2 fsbwsys;fsbwsys;c:\programmer\F-Secure\BackWeb\7681197\program\fsbwsys.exe [2008-12-28 270428]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\programmer\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
S3 BGRaSvc;BGRaSvc;"c:\programmer\BullGuard Software\BullGuard\support\bgrasvc.exe" --> c:\programmer\BullGuard Software\BullGuard\support\bgrasvc.exe [?]
S3 dot4;MS IEEE-1284.4-driver;c:\windows\system32\drivers\Dot4.sys [2009-01-10 206976]
S3 Dot4Print;Printerklassedriver til IEEE-1284.4;c:\windows\system32\drivers\Dot4Prt.sys [2009-01-10 12928]
S3 Dot4Scan;Scannerklassedriver til IEEE-1284.4;c:\windows\system32\drivers\Dot4scan.sys [2009-01-10 8704]
S3 dot4usb;Dot4USB-filter Dot4USB Filter;c:\windows\system32\drivers\Dot4usb.sys [2009-01-10 23936]
S3 GoogleDesktopManager-061008-081103;Google Desktop-administrator 5.7.806.10245;c:\programmer\Google\Google Desktop Search\GoogleDesktop.exe [2008-08-25 29744]
S3 NdisIP;Microsoft TV/Video-forbindelse;c:\windows\system32\drivers\NdisIP.sys [2008-05-26 10880]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2008-12-10 7808]
S3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [2008-05-24 572416]
S3 SLIP;BDA Slip De-Framer;c:\windows\system32\drivers\SLIP.sys [2008-05-26 11136]
S3 Tosrfcom;Tosrfcom; [x]
S3 usbvideo;USB-videoenhed (WDM);c:\windows\system32\drivers\usbvideo.sys [2008-05-26 121984]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{816e40ce-2b3d-11dd-96c7-806d6172696f}]
\Shell\AutoRun\command - F:\setup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9E4C88F5-F8EB-45C5-A0B3-08BC50AB9B1E}]
c:\windows\system32\msiexec.exe /fup {9E4C88F5-F8EB-45C5-A0B3-08BC50AB9B1E} /q
.
Indhold af mappen 'Planlagte Opgaver'
2009-02-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\programmer\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-01 21:22]
.
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.aldi.dk/mStart Page =
hxxp://www.aldi.dk/uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) =
hxxp://search.yahoo.com/search?fr=mcafee&p=%sIE: &Block this popup - c:\programmer\F-Secure\Anti-Spyware\blockpopups.htm
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Open with WordPerfect - c:\programmer\WordPerfect Office X3\Programs\WPLauncher.hta
FF - ProfilePath - c:\documents and settings\Torben Haslund\Application Data\Mozilla\Firefox\Profiles\7en90tnw.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.dmi.dk/dmi/index/danmark.htmFF - component: c:\documents and settings\Torben Haslund\Application Data\Mozilla\Firefox\Profiles\7en90tnw.default\extensions\{7E7165E2-0767-448c-852F-5FA8714F2C37}\components\PlainOldFavorites.dll
FF - component: c:\programmer\Mozilla Firefox\components\GoogleDesktopMozilla.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-02-06 23:27:18
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- DLLs startet under kørende Processer ---------------------
- - - - - - - > 'explorer.exe'(3776)
c:\programmer\McAfee\SiteAdvisor\saHook.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\programmer\Bonjour\mDNSResponder.exe
c:\programmer\F-Secure\Anti-Virus\fsgk32st.exe
c:\programmer\F-Secure\Anti-Virus\fsgk32.exe
c:\programmer\F-Secure\Anti-Virus\fssm32.exe
c:\programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\wbem\unsecapp.exe
c:\programmer\F-Secure\common\FSLAUNCH.EXE
.
**************************************************************************
.
Gennemført tid: 2009-02-06 23:29:59 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2009-02-06 22:29:44
Pre-Kørsel: 134.654.676.992 byte ledig
Post-Kørsel: 134,809,882,624 byte ledig
215 --- E O F --- 2009-01-13 21:26:27