Jeg har nu kørt Combofix. Her er logfilen
ComboFix 09-09-02.02 - jmch 03-09-2009 11:28.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1030.18.1526.1080 [GMT 2:00]
Kører fra: c:\documents and settings\jmch\Skrivebord\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\\ZbThumbnail.info
C:\desktop.ini
c:\documents and settings\All Users\Application Data\17587654
c:\documents and settings\All Users\Application Data\17587654\17587654
c:\documents and settings\All Users\Application Data\17587654\17587654.exe
c:\documents and settings\All Users\Application Data\17587654\pc17587654ins
c:\documents and settings\jmch\Menuen Start\Programmer\Total Security
c:\documents and settings\jmch\Menuen Start\Programmer\Total Security\Total Security 2009.lnk
c:\programmer\DDnsFilter
c:\programmer\DDnsFilter\DDnsFilter.dll
c:\windows\010112010146101105.te
c:\windows\0101120101464950.xe
c:\windows\0101120101464954.xe
c:\windows\0101120101465249.xe
c:\windows\Fonts\AcadEref.ttf
c:\windows\freddy61.exe
c:\windows\ld14.exe
c:\windows\mstre21.exe
c:\windows\pp11.exe
c:\windows\system32\drivers\ss.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Tjenester )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SfX
-------\Legacy_ddnsfilter
-------\Service_ddnsfilter
-------\Service_StreamSurge
((((((((((((((((((((((((((((( Filer skabt fra 2009-08-03 til 2009-09-03 )))))))))))))))))))))))))))))))))))
.
2009-09-02 06:19 . 2009-09-03 06:29 -------- d-----w- c:\programmer\Enigma Software Group
2009-09-01 07:53 . 2009-09-01 07:53 1 ---h--w- c:\windows\ex23567.dat
2009-09-01 07:53 . 2009-09-01 07:53 37760 ----a-w- c:\windows\system32\drivers\Filter.sys
2009-09-01 07:53 . 2009-09-01 07:53 1 ---h--w- c:\windows\mmsmark2.dat
2009-08-30 10:44 . 2009-08-30 10:44 -------- d-----w- c:\programmer\Polar
2009-08-13 04:51 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-11 06:39 . 2009-08-11 06:39 -------- d-----w- C:\Aktivitetstur til Hovborg
2009-08-06 19:14 . 2009-08-06 21:38 -------- d-----w- c:\documents and settings\jmch\Application Data\FileZilla
2009-08-05 11:53 . 2009-08-05 11:54 -------- d-----w- c:\documents and settings\jmch\Application Data\Ventrilo
2009-08-05 11:53 . 2009-08-05 11:53 -------- d-----w- c:\programmer\Ventrilo
2009-08-05 09:00 . 2009-08-05 09:00 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-03 06:54 . 2004-08-27 12:00 83484 ----a-w- c:\windows\system32\perfc006.dat
2009-09-03 06:54 . 2004-08-27 12:00 459330 ----a-w- c:\windows\system32\perfh006.dat
2009-09-03 06:52 . 2008-05-22 19:08 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-09-03 06:48 . 2006-06-21 10:52 119120 ----a-w- c:\documents and settings\jmch\Lokale indstillinger\Application Data\GDIPFONTCACHEV1.DAT
2009-09-01 10:28 . 2009-02-19 08:37 107912 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-09-01 10:28 . 2008-05-22 19:08 325640 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-09-01 10:28 . 2008-02-03 16:37 27656 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-09-01 10:28 . 2009-01-30 06:07 10520 ----a-w- c:\windows\system32\avgrsstx.dll
2009-09-01 09:16 . 2008-12-20 10:06 -------- d-----w- c:\programmer\Yahoo!
2009-09-01 09:14 . 2006-11-19 16:53 -------- d-----w- c:\programmer\PrisKalk
2009-09-01 09:10 . 2006-10-26 12:54 -------- d-----w- c:\programmer\BuildDesk DK 3.2
2009-09-01 09:10 . 2006-06-21 09:28 -------- d--h--w- c:\programmer\InstallShield Installation Information
2009-08-13 05:06 . 2007-08-02 17:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-11 06:54 . 2006-09-19 20:07 -------- d-----w- c:\documents and settings\jmch\Application Data\U3
2009-08-05 11:52 . 2007-06-28 08:17 -------- d-----w- c:\programmer\Fælles filer\Wise Installation Wizard
2009-08-05 09:00 . 2004-08-27 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:03 . 2004-08-27 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 21:43 . 2004-08-27 12:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-13 10:48 . 2006-10-02 19:21 -------- d-----w- c:\programmer\IrfanView
2009-07-03 16:59 . 2004-08-27 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 20:18 . 2009-06-29 20:18 20747 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-06-16 14:39 . 2004-08-27 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:39 . 2004-08-27 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-15 10:44 . 2004-08-27 12:00 77824 ----a-w- c:\windows\system32\telnet.exe
2009-06-15 10:44 . 2004-08-27 12:00 81920 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-10 14:15 . 2004-08-27 12:00 85504 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 07:21 . 2006-03-09 11:25 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:16 . 2004-08-27 12:00 132096 ----a-w- c:\windows\system32\wkssvc.dll
2007-04-25 08:49 . 2008-07-18 20:05 328 ------w- c:\programmer\GuideMenuSetup.iss
2007-04-06 03:28 . 2008-07-18 20:08 1237 ------w- c:\programmer\WinDVDSetup.iss
2008-07-18 20:47 . 2008-07-18 20:47 8 --sh--r- c:\windows\system32\AF3D73CD53.sys
2008-07-25 11:30 . 2007-01-02 18:28 3350 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\programmer\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1062144]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 07:56 1062144 ----a-w- c:\programmer\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\programmer\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1062144]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\programmer\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1062144]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-24 68856]
"MSMSGS"="c:\programmer\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Creative Live! Cam Manager"="c:\programmer\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe" [2006-09-06 143360]
"TomTomHOME.exe"="c:\programmer\TomTom HOME 2\HOMERunner.exe" [2008-05-06 202088]
"WMPNSCFG"="c:\programmer\Windows Media Player\WMPNSCFG.exe" [2006-11-15 204288]
"Google Update"="c:\documents and settings\jmch\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-04 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-08-24 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-08-24 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-08-24 114688]
"SunJavaUpdateSched"="c:\programmer\Java\jre6\bin\jusched.exe" [2008-10-26 136600]
"Sony Ericsson PC Suite"="c:\programmer\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 159744]
"Adobe Photo Downloader"="c:\programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"GrooveMonitor"="c:\programmer\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"AVFX Engine"="c:\programmer\Creative\Creative Live! Cam\VideoFX\StartFX.exe" [2006-08-16 24576]
"V0230Mon.exe"="c:\windows\V0230Mon.exe" [2006-09-06 32768]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-09-01 1932568]
"GuideMenu"="c:\programmer\Corel\Corel GuideMenu\GuideMenu.exe" [2007-08-07 1282048]
"QuickTime Task"="c:\programmer\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\programmer\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"F5D9050"="c:\programmer\Belkin\F5D9050\Belkinwcui.exe" [2006-07-20 1617920]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" - c:\windows\system32\HdAShCut.exe [2005-01-07 61952]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Ordbogen.com"="c:\programmer\CoolSystems\ordbogen.com\ordbogen.exe" [2007-10-19 274432]
c:\documents and settings\jmch\Menuen Start\Programmer\Start\
Screen Clipper and Launcher til OneNote 2007.lnk - c:\programmer\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
c:\documents and settings\All Users\Menuen Start\Programmer\Start\
Adobe Reader Hurtigstart.lnk - c:\programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
AutoCAD Startup Accelerator.lnk - c:\programmer\F‘lles filer\Autodesk Shared\acstart17.exe [2006-3-5 11000]
Device Detector 3.lnk - c:\programmer\Olympus\DeviceDetector\DevDtct2.exe [2007-6-25 114688]
RICOH Gate La.lnk - c:\programmer\Caplio Software\RGateLXP.exe [2008-5-7 360448]
VPN Client.lnk - c:\windows\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico [2007-9-18 6144]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-09-03 09:50 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^VersionTrackerPro.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\VersionTrackerPro.lnk
backup=c:\windows\pss\VersionTrackerPro.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Programmer\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmer\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmer\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmer\\Caplio Software\\RGateLXP.exe"=
"c:\\Programmer\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programmer\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmer\\MSN Messenger\\livecall.exe"=
"c:\\Programmer\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmer\\iTunes\\iTunes.exe"=
"c:\\Programmer\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Programmer\\Skype\\Phone\\Skype.exe"=
"c:\\Programmer\\Ventrilo\\Ventrilo.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8085:TCP"= 8085:TCP:ddnsfilter
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [22-05-2008 21:08 325640]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [19-02-2009 10:37 107912]
R1 Filter;Filter;c:\windows\system32\drivers\Filter.sys [1-09-2009 09:53 37760]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [30-01-2009 08:07 298264]
S3 V0230Vfx;V0230Vfx;c:\windows\system32\drivers\V0230Vfx.sys [27-12-2007 19:30 6272]
S3 V0230VID;Live! Cam Video IM Pro;c:\windows\system32\drivers\V0230VID.sys [27-12-2007 19:30 500480]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
ddnsfilter REG_MULTI_SZ ddnsfilter
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Indhold af mappen 'Planlagte Opgaver'
2009-08-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmer\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2009-08-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-436374069-682003330-1005Core.job
- c:\documents and settings\jmch\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 20:10]
2009-09-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-436374069-682003330-1005UA.job
- c:\documents and settings\jmch\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 20:10]
2009-08-30 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 16:04]
2009-09-03 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 16:04]
2009-09-03 c:\windows\Tasks\RegCure Program Check.job
- c:\programmer\RegCure\RegCure.exe [2008-12-29 17:58]
2009-02-12 c:\windows\Tasks\RegCure.job
- c:\programmer\RegCure\RegCure.exe [2008-12-29 17:58]
2009-09-03 c:\windows\Tasks\User_Feed_Synchronization-{877EF6A2-E603-44D7-A1CC-8CE8F7B6F1A4}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
- - - - TOMME GENVEJE FJERNET - - - -
HKCU-Run-VoipStunt - c:\programmer\voipstunt.com\voipstunt\voipstunt.exe
HKLM-Run-sysfbtray - c:\windows\freddy61.exe
HKLM-Run-17587654 - c:\documents and settings\All Users\Application Data\17587654\17587654.exe
.
------- Yderligere scanning -------
.
uStart Page =
uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {0018A71D-26DA-4707-AF52-E0B9D39796F2} -
hxxp://lafarge.kampanj.nu/LafargeOnline.cabDPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} -
hxxps://bestilling.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exeFF - ProfilePath - c:\documents and settings\jmch\Application Data\Mozilla\Firefox\Profiles\ibee3lyv.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.comFF - plugin: c:\documents and settings\jmch\Lokale indstillinger\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\programmer\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\programmer\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\programmer\Virtual Earth 3D\npVE3D.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLITIKKER ----
c:\programmer\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-03 11:42
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
GuideMenu = c:\programmer\Corel\Corel GuideMenu\GuideMenu.exe -hide???????????>?????????????CTRLMGR_3_CTRL_21?????????????????+x????????????????????z???????????????H???@???@?????????????????>???>?????????8472072? ?????????>???>?????????CTRL_SUBTYPE??????????????>????????
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\
.
--------------------- DLLs startet under kørende Processer ---------------------
- - - - - - - > 'explorer.exe'(3924)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\programmer\Bonjour\mDNSResponder.exe
c:\programmer\Sektornet VPN\cvpnd.exe
c:\programmer\Fælles filer\InterVideo\RegMgr\iviRegMgr.exe
c:\programmer\Java\jre6\bin\jqs.exe
c:\programmer\Fælles filer\Protexis\License Service\PSIService.exe
c:\programmer\Fælles filer\Ulead Systems\DVD\ULCDRSvr.exe
c:\programmer\Windows Media Player\wmpnetwk.exe
c:\programmer\AVG\AVG8\avgrsx.exe.oldS
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\programmer\Fælles filer\Teleca Shared\CapabilityManager.exe
c:\programmer\iPod\bin\iPodService.exe
c:\programmer\Fælles filer\Teleca Shared\Generic.exe
c:\programmer\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
.
**************************************************************************
.
Gennemført tid: 2009-09-03 11:54 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2009-09-03 09:54
Pre-Kørsel: 35.108.483.072 byte ledig
Post-Kørsel: 37.119.430.656 byte ledig
260 --- E O F --- 2009-09-01 14:37