sådan det var vist et skrapt program
her er logen...:
ComboFix 09-07-12.03 - Jesper 13-07-2009 19:57.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.45.1030.18.1534.996 [GMT 2:00]
Kører fra: c:\documents and settings\Jesper\Skrivebord\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090712-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\137721b.msp
c:\windows\Installer\137721c.msp
c:\windows\Installer\137721d.msp
c:\windows\Installer\137721e.msp
c:\windows\Installer\137721f.msp
c:\windows\Installer\1377220.msp
c:\windows\Installer\1377221.msp
c:\windows\Installer\1377222.msp
c:\windows\Installer\1377223.msp
c:\windows\Installer\1377224.msp
D:\Autorun.inf
.
((((((((((((((((((((((((((((( Filer skabt fra 2009-06-13 til 2009-07-13 )))))))))))))))))))))))))))))))))))
.
2009-07-13 03:39 . 2009-07-13 03:39 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-07-12 19:44 . 2009-07-12 19:44 -------- d-----w- c:\documents and settings\Jesper\Application Data\Malwarebytes
2009-07-12 19:44 . 2009-06-17 09:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-12 19:44 . 2009-07-12 19:44 -------- d-----w- c:\programmer\Malwarebytes' Anti-Malware
2009-07-12 19:44 . 2009-07-12 19:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-12 19:44 . 2009-06-17 09:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-12 19:39 . 2009-07-12 19:39 -------- d-----w- c:\programmer\CCleaner
2009-07-09 15:40 . 2009-07-09 15:40 -------- d-----w- C:\Microgaming
2009-07-09 15:40 . 2009-07-09 15:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Microgaming
2009-07-09 15:40 . 2009-07-09 15:40 -------- d-----w- c:\documents and settings\All Users\Application Data\MGS
2009-07-09 10:36 . 2009-07-09 10:36 -------- d-----w- c:\programmer\ESET
2009-06-30 21:03 . 2009-07-03 23:08 226936 ----a-w- c:\documents and settings\LocalService\Lokale indstillinger\Application Data\FontCache3.0.0.0.dat
2009-06-30 13:13 . 2009-06-30 13:13 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-06-28 15:48 . 2009-06-28 15:48 -------- d-----w- c:\programmer\Fælles filer\Macrovision Shared
2009-06-28 15:09 . 2009-06-28 15:11 -------- d-----w- c:\programmer\DWG TrueView 2010
2009-06-25 14:43 . 2009-06-28 14:56 -------- d-----w- c:\programmer\Panda Security
2009-06-22 12:40 . 2009-06-22 12:40 -------- d-----w- c:\documents and settings\Jesper\Application Data\IObit
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-13 03:41 . 2008-10-07 18:55 12 ----a-w- c:\windows\bthservsdp.dat
2009-07-11 13:25 . 2009-03-30 18:51 -------- d-----w- c:\documents and settings\Jesper\Application Data\uTorrent
2009-07-09 11:55 . 2008-11-16 08:01 -------- d-----w- c:\programmer\Windows Live Safety Center
2009-07-06 12:25 . 2009-06-20 12:24 25440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\savapibridge.dll
2009-07-06 12:25 . 2009-06-20 12:24 1630560 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Resources.dll
2009-07-06 12:24 . 2009-06-20 12:24 2353480 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Ad-Aware.exe
2009-07-05 06:44 . 2009-04-26 17:05 -------- d-----w- c:\programmer\Farm Frenzy Pizza Party
2009-07-04 12:25 . 2009-06-20 12:24 314712 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\threatwork.exe
2009-07-04 12:25 . 2009-06-20 12:24 169312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lavamessage.dll
2009-07-04 12:25 . 2009-06-20 12:24 348496 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lavalicense.dll
2009-07-04 12:25 . 2009-06-20 12:24 298336 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\UpdateManager.dll
2009-07-04 12:25 . 2009-06-06 12:24 84832 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\ShellExt.dll
2009-07-04 12:25 . 2009-06-06 12:24 246128 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\RPAPI.dll
2009-07-04 12:25 . 2009-06-20 12:24 85352 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Drivers\32\AAWDriverTool.exe
2009-07-04 12:25 . 2009-06-06 12:24 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\PrivacyClean.dll
2009-07-04 12:25 . 2009-06-20 12:24 664424 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\CEAPI.dll
2009-07-04 12:25 . 2009-06-20 12:24 563064 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Ad-AwareCommand.exe
2009-07-04 12:24 . 2009-06-20 12:24 566632 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Ad-AwareAdmin.exe
2009-07-04 12:24 . 2009-06-20 12:24 629072 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\AAWWSC.exe
2009-07-04 12:24 . 2009-06-20 12:24 520024 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\AAWTray.exe
2009-07-04 12:24 . 2009-06-20 12:24 1029456 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\AAWService.exe
2009-07-03 08:01 . 2008-09-27 07:55 132520 ----a-w- c:\documents and settings\HP_Ejer\Lokale indstillinger\Application Data\GDIPFONTCACHEV1.DAT
2009-07-02 18:22 . 2009-04-14 18:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Autodesk
2009-07-02 18:22 . 2009-04-14 18:51 -------- d-----w- c:\documents and settings\Jesper\Application Data\Autodesk
2009-07-01 17:36 . 2004-12-03 19:32 531890 ----a-w- c:\windows\system32\perfh006.dat
2009-07-01 17:36 . 2004-12-03 19:32 112080 ----a-w- c:\windows\system32\perfc006.dat
2009-06-28 16:33 . 2009-05-04 16:54 132520 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-06-28 16:11 . 2009-04-14 18:51 -------- d-----w- c:\programmer\Fælles filer\Autodesk Shared
2009-06-28 15:59 . 2009-04-14 18:51 -------- d-----w- c:\programmer\Autodesk
2009-06-28 08:42 . 2009-04-14 18:55 -------- d-----w- c:\programmer\AOEMView 2009
2009-06-21 17:47 . 2008-09-29 16:22 -------- d-----w- c:\documents and settings\Jesper\Application Data\Ahead
2009-06-21 08:48 . 2008-09-25 16:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-10 20:35 . 2008-09-26 13:16 -------- d-----w- c:\programmer\Windows Desktop Search
2009-06-06 12:24 . 2009-06-06 12:24 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lsdelete.exe
2009-06-06 12:24 . 2009-04-18 12:46 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-05-24 22:24 . 2008-05-26 20:18 350208 ------w- c:\windows\system32\mssph.dll
2009-05-13 05:05 . 2004-08-27 11:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-12 16:21 . 2009-03-28 10:01 19 ----a-w- c:\windows\popcinfo.dat
2009-05-12 13:12 . 2008-09-25 14:29 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2009-05-07 20:21 . 2009-05-07 20:21 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2009-05-07 15:33 . 2008-09-25 04:58 346624 ----a-w- c:\windows\system32\localspl.dll
2009-04-25 12:24 . 2009-04-25 12:24 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Drivers\32\lbd.sys
2009-04-25 12:24 . 2009-04-18 12:24 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-04-19 19:50 . 2008-09-25 05:02 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:53 . 2008-09-25 05:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-14 19:31 . 2008-09-26 14:34 132520 ----a-w- c:\documents and settings\Jesper\Lokale indstillinger\Application Data\GDIPFONTCACHEV1.DAT
2009-04-14 18:55 . 2009-04-14 18:55 10134 ----a-r- c:\documents and settings\Jesper\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2007-02-15 15:55 . 2008-09-25 05:37 32 --sha-w- c:\windows\SMINST\HPCD.SYS
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\programmer\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmer\Fælles filer\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"swg"="c:\programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-19 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-07 655360]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"PS2"="c:\windows\system32\ps2.exe" [2004-10-25 90112]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"NeroFilterCheck"="c:\programmer\Fælles filer\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"QuickTime Task"="c:\programmer\QuickTime\qttask.exe" [2005-01-02 98304]
"Adobe Reader Speed Launcher"="c:\programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Windows Defender"="c:\programmer\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"SunJavaUpdateSched"="c:\programmer\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"Ad-Watch"="c:\programmer\Lavasoft\Ad-Aware\AAWTray.exe" [2009-07-04 520024]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 86016]
"GrooveMonitor"="c:\programmer\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-03-27 1657376]
"AlcxMonitor"="ALCXMNTR.EXE" - c:\windows\ALCXMNTR.EXE [2004-09-07 57344]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2007-04-16 577536]
c:\documents and settings\HP_Ejer\Menuen Start\Programmer\Start\
Screen Clipper and Launcher til OneNote 2007.lnk - c:\programmer\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
c:\documents and settings\All Users\Menuen Start\Programmer\Start\
HotKey.lnk - c:\programmer\TEXTware\HotKey\TWALINK.EXE [2008-12-20 19968]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programmer\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmer\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmer\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmer\\Messenger\\msmsgs.exe"=
"c:\\Programmer\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmer\\uTorrent\\uTorrent.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [18-04-2009 14:24 64160]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [28-09-2008 11:45 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [28-09-2008 11:45 20560]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\programmer\Lavasoft\Ad-Aware\AAWService.exe [09-03-2009 21:06 1029456]
R2 WinDefend;Windows Defender;c:\programmer\Windows Defender\MsMpEng.exe [03-11-2006 19:19 13592]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\programmer\Fælles filer\Microsoft Shared\Windows Live\WLIDSVC.EXE [30-03-2009 16:28 1533808]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\programmer\NOS\bin\getPlus_HelperSvc.exe [12-11-2008 15:45 33752]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B2C3BB6B-E005-4246-B8E5-DF0A4D073CDC}]
c:\programmer\PixiePack Codec Pack\InstallerHelper.exe
.
Indhold af mappen 'Planlagte Opgaver'
2009-07-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\programmer\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 12:24]
2009-07-13 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmer\Windows Defender\MpCmdRun.exe [2006-11-03 17:20]
2009-07-13 c:\windows\Tasks\User_Feed_Synchronization-{D126B16D-E0EA-4C3D-ACA7-D3159DAF1FEE}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
- - - - TOMME GENVEJE FJERNET - - - -
HKCU-Run-Tunebite - c:\programmer\RapidSolution\Tunebite\Tunebite.exe
HKCU-RunOnce-Shockwave Updater - c:\windows\system32\Adobe\Shockwave 11\SwHelper_1150596.exe -Update -1150596 -Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB6; InfoPath.2; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://s5.travian.dk/dorf1.phpmSearch Bar =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=Q305&bd=pavilion&pf=desktopuInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} -
hxxps://www.sparhobro.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.30.cabDPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} -
hxxp://download.eset.com/special/eos/OnlineScanner.cabDPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} -
hxxps://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-07-13 20:03
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
Gennemført tid: 2009-07-13 20:05
ComboFix-quarantined-files.txt 2009-07-13 18:05
Pre-Kørsel: 382.253.322.240 byte ledig
Post-Kørsel: 383.078.506.496 byte ledig
189 --- E O F --- 2009-07-09 15:06