Tak!
her er logfilen:
ComboFix 09-06-04.09 - sejr 05-06-2009 17:30.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1030.18.503.294 [GMT 2:00]
Kører fra: c:\documents and settings\sejr\Dokumenter\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Forrige Kørsel -------
.
C:\autorun.inf
S:\Autorun.inf
.
((((((((((((((((((((((((((((( Filer skabt fra 2009-05-05 til 2009-06-05 )))))))))))))))))))))))))))))))))))
.
2009-06-03 20:11 . 2009-06-03 20:11 -------- d--h--w- C:\$AVG8.VAULT$
2009-06-03 18:06 . 2009-06-03 18:06 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-03 18:06 . 2009-06-03 18:06 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-06-03 18:06 . 2009-06-03 18:06 325896 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-03 18:06 . 2009-06-03 18:06 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-03 18:06 . 2009-06-05 12:39 -------- d-----w- c:\windows\system32\drivers\Avg
2009-06-03 18:05 . 2009-06-03 18:05 -------- d-----w- c:\programmer\AVG
2009-06-03 18:05 . 2009-06-05 14:40 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-03 17:47 . 2008-11-20 19:19 9200 ------w- c:\windows\system32\drivers\cdralw2k.sys
2009-06-03 17:47 . 2008-11-20 19:19 9072 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2009-06-03 17:46 . 2009-06-03 17:46 -------- d-----w- c:\windows\system32\IOSUBSYS
2009-06-03 17:11 . 2009-06-03 17:11 0 ----a-w- c:\windows\nsreg.dat
2009-06-03 17:11 . 2009-06-03 17:11 -------- d-----w- c:\documents and settings\sejr\Lokale indstillinger\Application Data\Mozilla
2009-06-03 17:10 . 2009-06-05 14:53 -------- d-----w- c:\programmer\Mozilla Firefox 3.5 Beta 4
2009-06-03 15:18 . 2008-04-14 15:05 152064 ----a-w- c:\windows\system32\irftp.exe
2009-06-03 15:18 . 2008-04-14 15:05 152064 ----a-w- c:\windows\system32\dllcache\irftp.exe
2009-06-03 15:18 . 2008-04-14 15:05 8192 ----a-w- c:\windows\system32\wshirda.dll
2009-06-03 15:18 . 2008-04-14 15:05 8192 ----a-w- c:\windows\system32\dllcache\wshirda.dll
2009-06-03 15:18 . 2008-04-14 15:05 28160 ----a-w- c:\windows\system32\irmon.dll
2009-06-03 15:18 . 2008-04-14 15:05 28160 ----a-w- c:\windows\system32\dllcache\irmon.dll
2009-06-03 09:46 . 2009-06-03 09:46 -------- d-----w- c:\documents and settings\sejr\Application Data\Malwarebytes
2009-06-03 09:46 . 2009-05-26 11:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-03 09:46 . 2009-06-03 09:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-03 09:46 . 2009-06-03 09:46 -------- d-----w- c:\programmer\Malwarebytes' Anti-Malware
2009-06-03 09:46 . 2009-05-26 11:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-03 09:05 . 2009-06-03 09:05 -------- d-----w- c:\programmer\CCleaner
2009-06-03 05:38 . 2007-08-24 17:45 101120 ----a-r- c:\windows\system32\drivers\ewusbmdm.sys
2009-06-03 05:38 . 2007-08-24 17:45 24448 ----a-r- c:\windows\system32\drivers\ewdcsc.sys
2009-06-03 05:38 . 2009-06-03 05:39 -------- d-----w- c:\programmer\Mobile Partner
2009-05-31 14:51 . 2003-03-18 19:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2009-05-31 14:51 . 2009-05-31 14:51 -------- d-----w- c:\programmer\Alwil Software
2009-05-29 10:20 . 2007-10-23 07:27 110592 ----a-w- c:\documents and settings\sejr\Application Data\U3\temp\cleanup.exe
2009-05-29 10:15 . 2008-02-25 11:47 3489792 ---ha-w- c:\documents and settings\sejr\Application Data\U3\temp\Launchpad Removal.exe
2009-05-29 10:14 . 2009-05-29 10:20 -------- d-----w- c:\documents and settings\sejr\Application Data\U3
2009-05-27 20:53 . 2009-02-06 10:10 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe
2009-05-27 20:53 . 2009-02-09 11:25 110592 ------w- c:\windows\system32\dllcache\services.exe
2009-05-27 20:53 . 2009-02-09 10:53 401408 ------w- c:\windows\system32\dllcache\rpcss.dll
2009-05-27 20:53 . 2009-02-09 10:53 473600 ------w- c:\windows\system32\dllcache\fastprox.dll
2009-05-27 20:53 . 2009-02-06 10:39 35328 ------w- c:\windows\system32\dllcache\sc.exe
2009-05-27 20:53 . 2009-02-09 10:53 730624 ------w- c:\windows\system32\dllcache\lsasrv.dll
2009-05-27 20:53 . 2009-02-09 10:53 719360 ------w- c:\windows\system32\dllcache\ntdll.dll
2009-05-27 20:53 . 2009-02-09 10:53 682496 ------w- c:\windows\system32\dllcache\advapi32.dll
2009-05-27 20:53 . 2009-02-09 10:53 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-03 17:46 . 2005-10-23 11:08 -------- d-----w- c:\programmer\Google
2009-06-03 15:19 . 2004-09-16 15:38 76978 ----a-w- c:\windows\system32\perfc006.dat
2009-06-03 15:19 . 2004-09-16 15:38 425946 ----a-w- c:\windows\system32\perfh006.dat
2009-05-31 21:47 . 2007-12-10 12:22 -------- d-----w- c:\programmer\Brother
2009-05-31 21:46 . 2005-06-29 07:40 -------- d--h--w- c:\programmer\InstallShield Installation Information
2009-05-31 21:37 . 2007-01-31 21:00 -------- d-----w- c:\documents and settings\sejr\Application Data\SoftMaker
2009-05-31 14:07 . 2005-06-29 07:44 -------- d-----w- c:\programmer\Sonic
2009-05-31 14:05 . 2006-01-23 23:03 -------- d-----w- c:\documents and settings\sejr\Application Data\Lavasoft
2009-05-29 14:19 . 2005-08-16 07:56 71496 -c--a-w- c:\documents and settings\sejr\Lokale indstillinger\Application Data\GDIPFONTCACHEV1.DAT
2009-05-01 18:30 . 2009-05-01 18:30 3366912 ----a-w- c:\windows\system32\GPhotos.scr
2009-03-18 09:07 . 2008-11-28 09:52 0 ----a-w- c:\documents and settings\sejr\temp.dat
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\programmer\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"H/PC Connection Agent"="c:\programmer\Microsoft ActiveSync\WCESCOMM.EXE" [2003-04-22 413775]
"WMPNSCFG"="c:\programmer\Windows Media Player\WMPNSCFG.exe" [2006-11-15 204288]
"ccleaner"="c:\programmer\CCleaner\CCleaner.exe" [2009-05-27 1573104]
"swg"="c:\programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-31 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\programmer\Apoint\Apoint.exe" [2004-09-13 155648]
"Dell QuickSet"="c:\programmer\Dell\QuickSet\quickset.exe" [2005-03-04 606208]
"DVDLauncher"="c:\programmer\r\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-26 53248]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"BigDogPath"="c:\windows\VM_STI.EXE" [2004-06-09 40960]
"SunJavaUpdateSched"="c:\programmer\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"IntelZeroConfig"="c:\programmer\Intel\Wireless\bin\ZCfgSvc.exe" [2006-07-02 802816]
"IntelWireless"="c:\programmer\Intel\Wireless\Bin\ifrmewrk.exe" [2006-07-02 700416]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"LogitechCommunicationsManager"="c:\programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"LogitechQuickCamRibbon"="c:\programmer\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-03 1947928]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\sejr\Menuen Start\Programmer\Start\
Genvej til Printkey2000.lnk - c:\windows\Printkey2000.exe [2005-8-12 869376]
Genvej til SISUBST.lnk - c:\windows\SISUBST.CMD [2005-8-12 47]
c:\documents and settings\All Users\Menuen Start\Programmer\Start\
Digital Line Detect.lnk - c:\programmer\Digital Line Detect\DLG.exe [2005-6-29 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-03 18:06 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0aswBoot.exe /M:ec3690cc6
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\Microsoft Office\\OFFICE11\\OUTLOOK.EXE"=
"c:\\Programmer\\Messenger\\msmsgs.exe"=
"c:\\Programmer\\Microsoft ActiveSync\\WCESMGR.EXE"=
"c:\\Programmer\\Microsoft ActiveSync\\WCESCOMM.EXE"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmer\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Programmer\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programmer\\AVG\\AVG8\\avgnsx.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [03-06-2009 20:06 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [03-06-2009 20:06 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [03-06-2009 20:05 298776]
R2 netmaps1;NetMaps;c:\windows\netmaps.exe [08-03-2006 09:39 452096]
.
Indhold af mappen 'Planlagte Opgaver'
2009-06-05 c:\windows\Tasks\Søg efter opdateringer til Windows Live Toolbar.job
- c:\programmer\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 10:20]
.
- - - - TOMME GENVEJE FJERNET - - - -
SafeBoot-procexp90.Sys
.
------- Yderligere scanning -------
.
uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8uSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: &Windows Live Search - c:\programmer\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\programmer\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: {4445EA6A-9008-40D5-9160-035FDE5214C4} -
hxxp://www.123hjemmeside.dk/builder/pages/Mpu-dk-1-0-0-8.cabDPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} -
hxxps://udstedelse.certifikat.tdc.dk/csp/authenticode/digitalsignatur-csp.exeFF - ProfilePath - c:\documents and settings\sejr\Application Data\Mozilla\Firefox\Profiles\eqc43a46.default\
FF - prefs.js: browser.startup.homepage -
hxxp://login.live.com/login.srf?wa=wsignin1.0&rpsnv=10&ct=1244049408&rver=5.5.4177.0&wp=MBI&wreply=http:%2F%2Fmail.live.com%2Fdefault.aspx&lc=1030&id=64855&mkt=da-DKFF - plugin: c:\programmer\Google\Picasa3\npPicasa3.dll
---- FIREFOX POLITIKKER ----
c:\programmer\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\programmer\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("media.cache_size", 51200);
c:\programmer\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("media.ogg.enabled", true);
c:\programmer\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("media.wave.enabled", true);
c:\programmer\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\programmer\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\programmer\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\programmer\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\programmer\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\programmer\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\programmer\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\programmer\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\programmer\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\programmer\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\programmer\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\programmer\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\programmer\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\programmer\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\programmer\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("geo.wifi.uri", "
https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-05 17:37
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- DLLs startet under kørende Processer ---------------------
- - - - - - - > 'winlogon.exe'(980)
c:\windows\system32\igfxdev.dll
.
Gennemført tid: 2009-06-05 17:40
Pre-Kørsel: 23.969.247.232 byte ledig
Post-Kørsel: 24.027.443.200 byte ledig
191 --- E O F --- 2009-05-27 22:31