Undskyld forsinkelsen, har ikke været hjemme siden fredag. Men her kommer den !
ComboFix 09-06-07.01 - Administrator 07-06-2009 23:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1030.18.767.450 [GMT 2:00]
Kører fra: c:\documents and settings\Administrator\Skrivebord\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090607-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.
((((((((((((((((((((((((((((( Filer skabt fra 2009-05-07 til 2009-06-07 )))))))))))))))))))))))))))))))))))
.
2009-06-07 21:06 . 2009-06-07 21:06 -------- d-----w- c:\programmer\Fælles filer\Application
2009-06-07 21:06 . 2009-06-07 21:12 -------- d-----w- c:\programmer\SPAMfighter
2009-06-07 20:53 . 2009-02-05 20:06 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-06-07 20:53 . 2009-02-05 20:06 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-06-07 20:53 . 2009-02-05 20:05 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-06-07 20:53 . 2009-02-05 20:08 93296 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-06-07 20:53 . 2009-02-05 20:08 94032 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-06-07 20:53 . 2009-02-05 20:07 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-06-07 20:53 . 2009-02-05 20:07 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-06-07 20:53 . 2009-02-05 20:04 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-06-07 20:53 . 2009-02-05 20:11 1256296 ----a-w- c:\windows\system32\aswBoot.exe
2009-06-05 10:58 . 2009-06-07 15:43 -------- d-----w- c:\documents and settings\Administrator\Application Data\F-Secure
2009-06-05 10:53 . 2009-06-05 10:53 -------- d-----w- c:\documents and settings\NetworkService\Lokale indstillinger\Application Data\F-Secure
2009-06-05 10:52 . 2009-06-07 20:51 -------- d-----w- c:\programmer\TDCSikkerhedspakke
2009-06-05 10:51 . 2009-06-05 10:51 -------- d-----w- c:\documents and settings\All Users\Application Data\fssg
2009-06-05 10:49 . 2009-06-07 20:48 -------- d-----w- c:\documents and settings\All Users\Application Data\f-secure
2009-06-02 00:12 . 2009-06-02 00:12 3371383 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-02 00:12 . 2009-06-02 00:12 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-06-02 00:12 . 2009-05-26 11:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-02 00:12 . 2009-05-26 11:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-02 00:12 . 2009-06-05 08:11 -------- d-----w- c:\programmer\Malwarebytes' Anti-Malware
2009-06-02 00:12 . 2009-06-02 00:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-01 23:11 . 2009-06-01 23:11 -------- d-----w- c:\programmer\Recuva
2009-06-01 11:45 . 2009-06-01 11:45 -------- d-----r- C:\Foretrukne
2009-06-01 11:45 . 2009-03-29 20:22 38674984 ----a-w- C:\175.19_geforce_winxp_32bit_english_whql.exe
2009-05-31 22:14 . 2009-05-31 22:53 -------- d-----w- c:\windows\system32\Adobe
2009-05-31 06:31 . 2009-05-31 07:13 -------- d-----w- c:\documents and settings\Administrator\Application Data\Download Manager
2009-05-30 15:45 . 2009-06-01 07:13 34 ----a-w- c:\documents and settings\Administrator\jagex_runescape_preferences.dat
2009-05-30 15:45 . 2009-05-31 16:18 -------- d-----w- c:\windows\.jagex_cache_32
2009-05-28 17:45 . 2009-05-28 17:45 -------- d-----w- c:\programmer\Alwil Software
2009-05-27 10:36 . 2009-05-27 10:36 -------- d-----w- c:\programmer\MSConfig CleanUp
2009-05-19 13:03 . 2009-05-19 13:03 -------- d-sh--w- c:\documents and settings\Administrator\IECompatCache
2009-05-19 13:01 . 2009-05-19 13:01 -------- d-----w- c:\programmer\CCleaner
2009-05-19 05:35 . 2009-05-19 05:35 -------- d-----w- c:\programmer\IObit
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-07 21:07 . 2009-03-23 17:36 -------- d-----w- c:\programmer\Mozilla Thunderbird
2009-06-07 20:48 . 2002-12-31 12:00 48300 ----a-w- c:\windows\system32\perfc006.dat
2009-06-07 20:48 . 2002-12-31 12:00 327272 ----a-w- c:\windows\system32\perfh006.dat
2009-06-07 15:39 . 2009-03-29 21:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-06-02 21:20 . 2009-03-20 21:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-01 08:49 . 2009-03-20 22:05 -------- d-----w- c:\programmer\Google
2009-05-19 05:44 . 2009-03-29 19:12 -------- d-----w- c:\documents and settings\Administrator\Application Data\IObit
2009-05-04 23:05 . 2009-05-04 23:05 152576 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-04 21:46 . 2009-04-15 19:39 -------- d-----w- c:\programmer\Mobile Partner
2009-04-30 16:20 . 2009-04-30 16:20 -------- d-----w- c:\programmer\QuickTime
2009-04-20 10:25 . 2009-04-20 10:25 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-04-20 10:25 . 2009-04-20 10:25 -------- d-----w- c:\programmer\NOS
2009-04-20 10:24 . 2009-04-20 10:24 -------- d-----w- c:\documents and settings\Administrator\Application Data\AdobeUM
2009-03-23 17:36 . 2009-03-23 17:36 0 ----a-w- c:\windows\nsreg.dat
2009-03-20 22:01 . 2009-03-20 22:01 69232 ----a-w- c:\documents and settings\Administrator\Lokale indstillinger\Application Data\GDIPFONTCACHEV1.DAT
2009-03-20 21:17 . 2009-03-20 18:08 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-20 18:48 . 2009-03-20 18:48 21035 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-03-20 18:06 . 2009-03-20 18:06 21644 ----a-w- c:\windows\system32\emptyregdb.dat
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\programmer\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"Adobe Reader Speed Launcher"="c:\programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\programmer\QuickTime\qttask.exe" [2009-04-30 413696]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"SPAMfighter Agent"="c:\programmer\SPAMfighter\SFAgent.exe" [2009-03-12 326792]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2003-12-19 65024]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Administrator\Menuen Start\Programmer\Start\
Screen Clipper and Launcher til OneNote 2007.lnk - c:\programmer\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\documents and settings\All Users\Menuen Start\Programmer\Start\
Adobe Gamma Loader.lnk - c:\programmer\F‘lles filer\Adobe\Calibration\Adobe Gamma Loader.exe [2009-3-21 113664]
Wireless LAN Utility.lnk - c:\programmer\LevelOne WNC-0301\WlanCU.exe [2007-11-28 626688]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmer\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmer\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmer\\SiSoftware\\SiSoftware Sandra Lite 2005.SR3\\sandra.exe"=
"c:\\Programmer\\SiSoftware\\SiSoftware Sandra Lite 2005.SR3\\RpcSandraSrv.exe"=
"c:\\Programmer\\SiSoftware\\SiSoftware Sandra Lite 2005.SR3\\RpcDataSrv.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\iexist.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\ifilflyt.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\ikundenr.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\initexp.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\ikortval.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\iprint.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\totalxml.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\itransak.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\iudpak.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\ichckkod.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\igembo.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\iudskriv.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\ivaluta.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\ixmlinsr.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\totalexp.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\ibettype.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\ibackup.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\Wkvit.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\dkt1.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\iartopsl.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\FormView.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\Drawer.exe"=
"c:\\Programmer\\EDB Gruppen\\MO-BIL-LET B410\\pgm\\icruvagt.exe"=
"c:\\Programmer\\EA GAMES\\MOHAA\\MOHAA.EXE"=
"c:\\Programmer\\GlobalSCAPE\\CuteFTP\\cutftp32.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"53:TCP"= 53:TCP:websrvx
"1120:UDP"= 1120:UDP:Windows Media Format SDK (IEXPLORE.EXE)
"1121:UDP"= 1121:UDP:Windows Media Format SDK (IEXPLORE.EXE)
"1122:UDP"= 1122:UDP:Windows Media Format SDK (IEXPLORE.EXE)
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [07-06-2009 22:53 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [07-06-2009 22:53 20560]
R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\programmer\SPAMfighter\sfus.exe [12-03-2009 10:44 184968]
S2 gupdate1c9b0b423c076ac;Tjenesten Google Update (gupdate1c9b0b423c076ac);c:\programmer\Google\Update\GoogleUpdate.exe [29-03-2009 23:20 133104]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\programmer\NOS\bin\getPlus_HelperSvc.exe [20-04-2009 12:25 33176]
--- Andre Services/Drivers i Hukommelsen ---
*NewlyCreated* - ASWUPDSV
*NewlyCreated* - AVAST!_ANTIVIRUS
*NewlyCreated* - AVAST!_MAIL_SCANNER
*NewlyCreated* - AVAST!_WEB_SCANNER
*NewlyCreated* - SPAMFIGHTER_UPDATE_SERVICE
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Indhold af mappen 'Planlagte Opgaver'
2009-06-07 c:\windows\Tasks\Google Software Updater.job
- c:\programmer\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-29 21:19]
2009-06-07 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2009-03-29 21:20]
2009-06-07 c:\windows\Tasks\User_Feed_Synchronization-{358F4E54-2413-4DC8-BF45-E82B6460881E}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
- - - - TOMME GENVEJE FJERNET - - - -
SafeBoot-procexp90.Sys
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.dk/IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} -
hxxps://www.sparekassen-vendsyssel.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.30.cabFF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\zq21dc77.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.dk/FF - plugin: c:\programmer\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\programmer\Google\Update\1.2.145.5\npGoogleOneClick8.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-07 23:13
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
[HKEY_USERS\S-1-5-21-1123561945-926492609-1801674531-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c3,00,52,af,8b,a1,06,45,93,0f,a1,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c3,00,52,af,8b,a1,06,45,93,0f,a1,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c3,00,52,af,8b,a1,06,45,93,0f,a1,\
.
--------------------- DLLs startet under kørende Processer ---------------------
- - - - - - - > 'winlogon.exe'(652)
c:\windows\SYSTEM32\Wireless\WirelessGina.DLL
- - - - - - - > 'explorer.exe'(1028)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Gennemført tid: 2009-06-07 23:14
ComboFix-quarantined-files.txt 2009-06-07 21:14
Pre-Kørsel: 140.665.434.112 byte ledig
Post-Kørsel: 140.920.111.104 byte ledig
195 --- E O F --- 2009-05-12 21:05