Hermed log fra Combofix. den kom med nogle fejlmeddelelser i starten, men kom så igen (noget med forkert version af windows og restore-funktionen)
Ang. hijackthis-loggen ovenfor, hvad er så dette?
O4 - HKLM\..\Run: [68304122] C:\DOCUME~1\ALLUSE~1\APPLIC~1\68304122\68304122.exe
Har det noget at gøre med det samsonjens herover nævner?
ComboFix 10-10-08.01 - Katrine 09-10-2010 18:50:59.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.45.1033.18.1022.649 [GMT 2:00]
Running from: c:\documents and settings\Katrine\Desktop\Dender.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Katrine\Application Data\avdrn.dat
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\jestertb.dll
c:\windows\system32\drivers\fad.sys
Infected copy of c:\windows\system32\drivers\perc2hib.sys was found and disinfected
Restored copy from - Kitty had a snack :p
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_USNJSVC
-------\Service_usnjsvc
((((((((((((((((((((((((( Files Created from 2010-09-09 to 2010-10-09 )))))))))))))))))))))))))))))))
.
2010-10-09 16:32 . 2010-10-09 16:32 -------- d-----w- C:\Dender30934D
2010-10-09 14:54 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-09 14:54 . 2010-10-09 14:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-10-09 14:54 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-09 14:54 . 2010-10-09 14:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-08 19:18 . 2010-10-08 19:18 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2010-10-08 18:54 . 2010-10-09 15:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-10-08 18:54 . 2010-10-08 18:54 -------- d-----w- c:\program files\Alwil Software
2010-10-07 19:11 . 2010-10-07 19:11 -------- d-----w- c:\documents and settings\Katrine\Application Data\AVG9
2010-10-06 18:20 . 2010-10-06 18:20 -------- d-----w- c:\documents and settings\Katrine\DoctorWeb
2010-10-06 17:46 . 2010-10-06 17:46 -------- d-----w- c:\program files\Trend Micro
2010-09-30 18:47 . 2010-09-30 18:47 -------- d-----w- c:\documents and settings\Katrine\.oces2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-09 14:47 . 2009-02-07 19:14 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-10-08 19:00 . 2005-05-08 18:45 -------- d-----w- c:\program files\Pixeline
2010-10-08 19:00 . 2004-10-19 23:21 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-10-06 16:28 . 2009-12-29 17:40 -------- d-----w- c:\program files\CCleaner
2010-10-03 12:01 . 2008-01-18 17:02 54 -c-h--w- c:\windows\popcreg.dat
2010-10-03 12:01 . 2008-01-18 17:02 16 -c--a-w- c:\windows\popcinfot.dat
2010-09-30 05:26 . 2010-08-15 19:44 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-29 15:49 . 2010-01-04 19:17 0 ----a-w- c:\documents and settings\Katrine\Local Settings\Application Data\prvlcl.dat
2010-09-29 15:49 . 2010-01-23 17:49 0 ----a-w- c:\documents and settings\Astrid\Local Settings\Application Data\prvlcl.dat
2010-09-15 16:33 . 2009-07-07 10:55 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-09-14 13:43 . 2007-03-27 12:10 -------- d-----w- c:\program files\Steam
2010-09-04 21:24 . 2005-10-22 13:40 -------- d-----w- c:\documents and settings\Katrine\Application Data\Skype
2010-09-03 19:13 . 2010-09-03 19:05 -------- d-----w- c:\documents and settings\Katrine\Application Data\gtk-2.0
2010-09-03 19:02 . 2010-09-03 19:02 -------- d-----w- c:\program files\Gimp-2.0
2010-08-28 22:58 . 2007-01-03 17:25 -------- d-----w- c:\documents and settings\Katrine\Application Data\Apple Computer
2010-08-17 13:17 . 2004-08-12 14:06 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-07-22 15:49 . 2004-08-12 14:04 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 05:57 . 2009-04-17 05:32 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-07-15 17:37 . 2009-12-30 00:18 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-15 17:37 . 2010-07-15 17:37 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-15 17:36 . 2009-12-30 00:17 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Free Internet Window Washer"="c:\progra~1\FREEIN~1\Clearpch.exe" [2009-03-17 1541120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 19968]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-21 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976]
"EEventManager"="c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2008-05-07 591696]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-08-23 57344]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-03-15 122933]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-10-05 2067808]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-15 17:37 12536 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Steam\\steamapps\\frello\\condition zero\\hl.exe"=
"c:\\Program Files\\Steam\\steamapps\\frello\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Microsoft Games\\Halo Trial\\halo.exe"=
"c:\\Program Files\\Disciples II - Rise of the Elves\\Discipl2.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\WINDOWS\\SYSTEM32\\DPLAYSVR.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020
"3724:TCP"= 3724:TCP:Blizzard downloader
"6112:TCP"= 6112:TCP:Blizzard downloader
"6881:TCP"= 6881:TCP:Blizzard downloader
"6999:TCP"= 6999:TCP:Blizzard downloader
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [30-12-2009 02:17 216400]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [30-12-2009 02:18 243024]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [15-07-2010 19:37 308136]
S0 drusbnt;drusbnt; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [04-02-2010 20:45 135664]
S3 75c8fc3c-78bd-4a6e-aa5a-26c22763c162;75c8fc3c-78bd-4a6e-aa5a-26c22763c162;\??\d:\player\cds300.dll --> d:\player\cds300.dll [?]
S3 USBAAPL;Apple Mobile USB Driver;c:\windows\SYSTEM32\DRIVERS\usbaapl.sys [23-09-2007 12:45 30336]
.
Contents of the 'Scheduled Tasks' folder
2010-10-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 18:44]
2010-10-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 18:44]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.dk/uInternet Connection Wizard,ShellNext =
hxxp://www.euro.dell.com/uSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} -
hxxps://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exeFF - ProfilePath - c:\documents and settings\Katrine\Application Data\Mozilla\Firefox\Profiles\9z12l9qi.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.dk/FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2740)
c:\program files\Logitech\MouseWare\System\LgWndHk.dll
c:\program files\Common Files\Logitech\Scrolling\LgMsgHk.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\wscntfy.exe
c:\program files\Logitech\MouseWare\system\em_exec.exe
.
**************************************************************************
.
Completion time: 2010-10-09 19:21:41 - machine was rebooted
ComboFix-quarantined-files.txt 2010-10-09 17:21
Pre-Run: 112.309.846.016 bytes free
Post-Run: 112.970.113.024 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 3E9F4095173D5A49439D2288B559D7CB