ComboFix 09-09-20.01 - Stefan Mammen 21-09-2009 8:07.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.45.1030.18.2039.1450 [GMT 2:00]
Kører fra: c:\documents and settings\Stefan Mammen\Dokumenter\Downloads\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
* Dannede nyt systemgendannelsespunkt
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\STEFAN~1\LOKALE~1\Temp\install_flash_player.exe
c:\documents and settings\Stefan Mammen\Application Data\ecuj.ban
c:\documents and settings\Stefan Mammen\Application Data\ycebyt.dll
c:\documents and settings\Stefan Mammen\Application Data\yzap.reg
c:\documents and settings\Stefan Mammen\Application Data\zohypym.dll
c:\documents and settings\Stefan Mammen\Cookies\feqyxyme.com
c:\documents and settings\Stefan Mammen\Cookies\tipuwy.bin
c:\documents and settings\Stefan Mammen\Lokale indstillinger\Application Data\walirysy.exe
c:\documents and settings\Stefan Mammen\Menuen Start\Programmer\Start\ChkDisk.lnk
c:\documents and settings\Stefan Mammen\protect.dll
c:\documents and settings\Stefan Mammen\rfyav.exe
c:\programmer\PC_Antispyware2010
c:\programmer\PC_Antispyware2010\AVEngn.dll
c:\programmer\PC_Antispyware2010\data\daily.cvd
c:\programmer\PC_Antispyware2010\htmlayout.dll
c:\programmer\PC_Antispyware2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
c:\programmer\PC_Antispyware2010\Microsoft.VC80.CRT\msvcm80.dll
c:\programmer\PC_Antispyware2010\Microsoft.VC80.CRT\msvcp80.dll
c:\programmer\PC_Antispyware2010\Microsoft.VC80.CRT\msvcr80.dll
c:\programmer\PC_Antispyware2010\PC_Antispyware2010.cfg
c:\programmer\PC_Antispyware2010\pthreadVC2.dll
c:\recycler\S-1-5-21-3375243515-3541712511-314844050-1003
c:\windows\duze.exe
c:\windows\kilaq.vbs
c:\windows\lyfowoxup.scr
c:\windows\puhufyd.dl
c:\windows\system32\1157492343.dat
c:\windows\system32\autochk.dll
c:\windows\system32\drivers\rotscxsppqbuxt.sys
c:\windows\system32\drivers\str.sys
c:\windows\system32\rotscxeylkiqko.dll
c:\windows\system32\rotscxibeeptta.dat
c:\windows\system32\rotscxpesmceth.dll
c:\windows\system32\rotscxxvmtnqwe.dat
c:\windows\system32\yxym.pif
.
((((((((((((((((((((((((((((((((((((((( Drivers/Tjenester )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_rotscxyrittfdt
-------\Legacy_THEMESCISVC
-------\Service_rotscxyrittfdt
-------\Service_ThemesCiSvc
((((((((((((((((((((((((((((( Filer skabt fra 2009-08-21 til 2009-09-21 )))))))))))))))))))))))))))))))))))
.
Ingen nye filer dannet i denne periode
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-04 04:01 . 2010-03-04 04:01 -------- d-----w- c:\programmer\microsoft frontpage
2010-03-04 03:59 . 2010-03-04 03:59 -------- d-----w- c:\programmer\Onlinetjenester
2010-03-04 03:59 . 2010-03-04 03:59 -------- d-----w- c:\programmer\Fælles filer\Tjenester
2010-03-04 03:59 . 2010-03-04 03:59 21644 ----a-w- c:\windows\system32\emptyregdb.dat
2009-09-21 06:02 . 2010-03-04 04:48 84030 ----a-w- c:\windows\system32\perfc006.dat
2009-09-21 06:02 . 2010-03-04 04:48 459900 ----a-w- c:\windows\system32\perfh006.dat
2009-09-18 07:48 . 2009-09-16 08:53 -------- d-----w- c:\programmer\Malwarebytes' Anti-Malware
2009-09-16 08:53 . 2009-09-16 08:53 -------- d-----w- c:\documents and settings\Stefan Mammen\Application Data\Malwarebytes
2009-09-16 08:53 . 2009-09-16 08:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-16 07:14 . 2009-09-16 07:14 -------- d-----w- c:\programmer\CCleaner
2009-09-15 10:33 . 2009-09-15 10:33 14635 ----a-w- c:\windows\lydopojan.dat
2009-09-15 10:33 . 2009-09-15 10:33 13879 ----a-w- c:\windows\system32\roby.dat
2009-09-12 07:11 . 2009-03-04 05:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-09-10 12:54 . 2009-09-16 08:53 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 12:53 . 2009-09-16 08:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-02 18:38 . 2009-08-24 22:36 70448 ----a-w- c:\documents and settings\Stefan Mammen\Lokale indstillinger\Application Data\GDIPFONTCACHEV1.DAT
2009-09-01 18:59 . 2009-03-04 04:51 -------- d-----w- c:\programmer\Microsoft Works
2009-09-01 18:58 . 2009-09-01 18:58 -------- d-----w- c:\programmer\Microsoft.NET
2009-09-01 18:46 . 2009-03-04 05:00 -------- d-----w- c:\programmer\Microsoft
2009-08-30 15:20 . 2009-08-30 15:20 -------- d-----w- c:\programmer\Graph
2009-08-29 07:16 . 2009-08-29 07:16 -------- d-----w- c:\programmer\MSBuild
2009-08-29 07:16 . 2009-08-29 07:16 -------- d-----w- c:\programmer\Reference Assemblies
2009-08-27 15:41 . 2009-08-27 15:41 48 ----a-w- c:\documents and settings\Stefan Mammen\Application Data\wklnhst.dat
2009-08-27 15:41 . 2009-08-27 15:41 -------- d-----w- c:\documents and settings\Stefan Mammen\Application Data\Template
2009-08-26 20:49 . 2009-03-04 04:50 -------- d-----w- c:\programmer\Fælles filer\Adobe
2009-08-26 20:19 . 2009-08-26 20:19 -------- d-----w- c:\documents and settings\Stefan Mammen\Application Data\RealWorld
2009-08-26 20:06 . 2009-08-26 19:56 -------- d-----w- c:\programmer\Paint.NET
2009-08-26 19:57 . 2009-03-04 05:00 -------- d-----w- c:\programmer\Windows Live
2009-08-26 19:16 . 2009-08-26 19:16 -------- d-----w- c:\programmer\Avira
2009-08-26 19:16 . 2009-08-26 19:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-08-26 18:56 . 2009-03-04 04:49 -------- d-----w- c:\programmer\ASUS
2009-08-05 09:00 . 2010-03-04 04:48 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-29 04:36 . 2010-03-04 04:48 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:36 . 2010-03-04 04:48 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-28 14:33 . 2009-08-26 19:16 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-07-21 06:52 . 2009-07-21 06:52 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-07-21 06:52 . 2009-07-21 06:52 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-07-17 19:03 . 2010-03-04 04:48 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 21:43 . 2010-03-04 04:48 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 15:58 . 2010-03-04 04:48 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 15:58 . 2010-03-04 04:48 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 15:58 . 2010-03-04 04:48 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-25 08:26 . 2010-03-04 04:48 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:26 . 2010-03-04 04:48 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:26 . 2010-03-04 04:48 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:26 . 2010-03-04 04:48 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:26 . 2010-03-04 04:48 731648 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:26 . 2010-03-04 04:48 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2010-03-04 04:48 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2008-05-07 08:34 . 2009-03-04 04:51 15523560 ----a-w- c:\programmer\U1 Setup.exe
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Stefan Mammen\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe" [2009-08-26 133104]
"msnmsgr"="c:\programmer\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-15 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"ETDWare"="c:\programmer\Elantech\ETDCtrl.exe" [2009-01-23 416768]
"AsusTray"="c:\programmer\EeePC\ACPI\AsTray.exe" [2008-12-04 114688]
"AsusACPIServer"="c:\programmer\EeePC\ACPI\AsAcpiSvr.exe" [2008-12-17 622592]
"AsusEPCMonitor"="c:\programmer\EeePC\ACPI\AsEPCMon.exe" [2008-05-21 94208]
"avgnt"="c:\programmer\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"fssui"="c:\programmer\Windows Live\Family Safety\fsui.exe" [2009-02-06 454000]
"Adobe Reader Speed Launcher"="c:\programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-02-13 17508864]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]
c:\documents and settings\All Users\Menuen Start\Programmer\Start\
BTTray.lnk - c:\programmer\WIDCOMM\Bluetooth Software\BTTray.exe [2008-9-2 604776]
SuperHybridEngine.lnk - c:\programmer\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2009-3-4 376832]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll schannel.dll digest.dll msnsspc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmer\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmer\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\programmer\Avira\AntiVir Desktop\sched.exe [26-08-2009 21:16 108289]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [04-03-2009 07:06 55136]
R2 fsssvc;Windows Live Family Safety;c:\programmer\Windows Live\Family Safety\fsssvc.exe [06-02-2009 18:08 533360]
R3 AsusACPI;ASUS ACPI Driver;c:\windows\system32\drivers\ASUSACPI.SYS [04-03-2009 06:47 10752]
R3 Ktp;Elantech Smart-Pad;c:\windows\system32\drivers\ETD.sys [01-08-2008 04:24 93696]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [04-11-2008 11:28 38400]
R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [14-04-2009 17:20 933504]
S2 jsjzvzqpvq;jsjzvzqpvq;\??\c:\windows\system32\drivers\rlvwnuwvqxclrf.sys --> c:\windows\system32\drivers\rlvwnuwvqxclrf.sys [?]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [04-03-2009 06:44 1684736]
.
Indhold af mappen 'Planlagte Opgaver'
2009-09-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1135438500-2191432629-2989547700-1006Core.job
- c:\documents and settings\Stefan Mammen\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe [2009-08-26 18:06]
2009-09-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1135438500-2191432629-2989547700-1006UA.job
- c:\documents and settings\Stefan Mammen\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe [2009-08-26 18:06]
.
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.commStart Page =
hxxp://www.google.comIE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send til &Bluetooth-enhed... - c:\programmer\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send til Bluetooth - c:\programmer\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
- - - - TOMME GENVEJE FJERNET - - - -
HKCU-Run-rfyav - c:\documents and settings\Stefan Mammen\rfyav.exe
HKLM-Run-PC Antispyware 2010 - c:\programmer\PC_Antispyware2010\PC_Antispyware2010.exe
HKU-Default-Run-autochk - c:\windows\system32\config\SYSTEM~1\protect.dll
AddRemove-HijackThis - e:\spywarefri\HijackThis.exe
AddRemove-PC_Antispyware2010 - c:\programmer\PC_Antispyware2010\Uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-21 08:13
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- DLLs startet under kørende Processer ---------------------
- - - - - - - > 'explorer.exe'(1804)
c:\windows\system32\btmmhook.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\programmer\Fælles filer\Adobe\Acrobat\ActiveX\PDFShell.DAN
.
------------------------ Andre kørende processer ------------------------
.
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\igfxext.exe
c:\programmer\Avira\AntiVir Desktop\avguard.exe
c:\programmer\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Gennemført tid: 2009-09-21 8:15 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2009-09-21 06:15
Pre-Kørsel: 67.481.997.312 byte ledig
Post-Kørsel: 67.440.971.776 byte ledig
WindowsXP-KB310994-SP2-Home-BootDisk-DAN.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
220 --- E O F --- 2009-09-12 07:14