Jeg fik combo til at køre ved at køre den direkte fra downloadningskilden. Så nu har jeg alle logs'ne. Computeren føles rigtig god nu. Her kommer logs'ne.
ComboFix 07-12-21.4 - André 2007-12-29 17:15:08.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1030.18.186 [GMT 1:00]
Running from: D:\Documents and Settings\André\Lokale indstillinger\Temporary Internet Files\Content.IE5\5GKZXL05\ComboFix[1].exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\_install.exe
D:\Documents and Settings\Andr‚\Application Data\Install.dat
D:\Documents and Settings\André\Application Data\install.dat
D:\Documents and Settings\André\Dokumenter\FNTS~1
D:\Documents and Settings\André\Dokumenter\FNTS~1\F?nts\
D:\Programmer\Fælles filer\PagingSYS.dll
D:\Programmer\inetget2
D:\Programmer\Microsoft Security Adviser
D:\Programmer\Temporary
D:\Programmer\WinAble
D:\WINDOWS\system32\3_exception.nls
D:\WINDOWS\system32\954125041.dll
D:\WINDOWS\system32\config\49897778.Evt
D:\WINDOWS\system32\drivers\secdrv.sys
D:\WINDOWS\system32\drivers\smtpdrv.sys
D:\WINDOWS\system32\drivers\STWB56.sys
D:\WINDOWS\system32\drivers\symavc32.sys
D:\WINDOWS\system32\kernelw.sys
D:\WINDOWS\system32\kernelwind32.exe
D:\WINDOWS\system32\kr_done1
D:\WINDOWS\system32\PagingSYS.sys
D:\WINDOWS\system32\shift.exe.exe
D:\WINDOWS\system32\vx.tll
D:\WINDOWS\system32\wsnpoem
D:\WINDOWS\system32\xpdx.sys
.
---- Previous Run -------
.
D:\Documents and Settings\Andr‚\Application Data\Microsoft\25319.dat
D:\Documents and Settings\Andr‚\temp.tpk
D:\Programmer\Microsoft Security Adviser
D:\Programmer\s2f.exe
D:\WINDOWS\avp.exe
D:\WINDOWS\bayxxx.ini
D:\WINDOWS\bck7.dat
D:\WINDOWS\Casino.ico
D:\WINDOWS\Downloaded Program Files\UDC6K_0001_D19M0509NetInstaller.exe
D:\WINDOWS\Free Online Dating.ico
D:\WINDOWS\kklopo.ini
D:\WINDOWS\msavsc.dll
D:\WINDOWS\msctrl.dll
D:\WINDOWS\msfw.dll
D:\WINDOWS\msiemon.dll
D:\WINDOWS\mssadv.dll
D:\WINDOWS\msscan.dll
D:\WINDOWS\nwan.dat
D:\WINDOWS\opolkk.dll
D:\WINDOWS\spoolzv.exe
D:\WINDOWS\Spyware Remover.ico
D:\WINDOWS\system32\3_exception.nls
D:\WINDOWS\system32\7295978141.dll
D:\WINDOWS\system32\away.exe.exe
D:\WINDOWS\system32\config\49883500.Evt
D:\WINDOWS\system32\dllh8jkd1q1.exe
D:\WINDOWS\system32\dllh8jkd1q2.exe
D:\WINDOWS\system32\dllh8jkd1q5.exe
D:\WINDOWS\system32\dllh8jkd1q6.exe
D:\WINDOWS\system32\dllh8jkd1q7.exe
D:\WINDOWS\system32\dllh8jkd1q8.exe
D:\WINDOWS\system32\drivers\Jwc47.sys
D:\WINDOWS\system32\drivers\symavc32.sys
D:\WINDOWS\system32\KB_963493.exe~
D:\WINDOWS\system32\KB18561603.exe
D:\WINDOWS\system32\KB21542167.exe
D:\WINDOWS\system32\KB66507128.exe
D:\WINDOWS\system32\KB93427757.exe
D:\WINDOWS\system32\KB93736873.exe
D:\WINDOWS\system32\kernelwind32.exe
D:\WINDOWS\system32\kr_done1
D:\WINDOWS\system32\ldpackage.dll
D:\WINDOWS\system32\m1ax1d1213216143v.exe
D:\WINDOWS\system32\max1d11643v.exe
D:\WINDOWS\system32\model.dat
D:\WINDOWS\system32\mstaskmgr.exe
D:\WINDOWS\system32\newmaxxsv234.exe
D:\WINDOWS\system32\noskrnl.sys
D:\WINDOWS\system32\RunOnce2.t__
D:\WINDOWS\system32\silc_dll.dll
D:\WINDOWS\system32\spoolsvv.exe
D:\WINDOWS\system32\spoolzv.sys
D:\WINDOWS\system32\spywarewarning.mht
D:\WINDOWS\system32\svcp.csv
D:\WINDOWS\system32\vedxg3am1et3.exe
D:\WINDOWS\system32\vedxg4am1et2.exe
D:\WINDOWS\system32\vedxg6ame4.exe
D:\WINDOWS\system32\vedxga1me4t1.exe
D:\WINDOWS\system32\vedxga3me2.exe
D:\WINDOWS\system32\vedxga4m1et4.exe
D:\WINDOWS\system32\vedxga4me1.exe
D:\WINDOWS\system32\vedxga5me3.exe
D:\WINDOWS\system32\vedxga8me6.exe
D:\WINDOWS\system32\vx.tll
D:\WINDOWS\system32\windbg___
D:\WINDOWS\system32\winsub.xml
D:\WINDOWS\system32\wmvds32.dll
D:\WINDOWS\system32\wsnpoem
D:\WINDOWS\system32\wsnpoem\audio.dll
D:\WINDOWS\system32\wsnpoem\video.dll
D:\WINDOWS\system32\xpdx.sys
D:\WINDOWS\system32runonce2.t__
D:\WINDOWS\system32runonce2.tm_
D:\WINDOWS\temp\107683925.exe
D:\WINDOWS\temp\1274712429.exe
D:\WINDOWS\temp\1357678677.exe
D:\WINDOWS\temp\1402909559.exe
D:\WINDOWS\temp\1419038757.exe
D:\WINDOWS\temp\1545735495.exe
D:\WINDOWS\temp\1593674485.exe
D:\WINDOWS\temp\1613416791.exe
D:\WINDOWS\temp\1614348887.exe
D:\WINDOWS\temp\1913324498.exe
D:\WINDOWS\temp\1997087655.exe
D:\WINDOWS\temp\203284647.exe
D:\WINDOWS\temp\2106097431.exe
D:\WINDOWS\temp\2209975931.exe
D:\WINDOWS\temp\2343220533.exe
D:\WINDOWS\temp\2472797357.exe
D:\WINDOWS\temp\2544509815.exe
D:\WINDOWS\temp\2592363159.exe
D:\WINDOWS\temp\2991035003.exe
D:\WINDOWS\temp\3255036051.exe
D:\WINDOWS\temp\330652653.exe
D:\WINDOWS\temp\3432585955.exe
D:\WINDOWS\temp\3472906107.exe
D:\WINDOWS\temp\3481073573.exe
D:\WINDOWS\temp\3860734021.exe
D:\WINDOWS\temp\4146485563.exe
D:\WINDOWS\temp\447634647.exe
D:\WINDOWS\temp\465744461.exe
D:\WINDOWS\temp\520205651.exe
D:\WINDOWS\temp\888171909.exe
D:\WINDOWS\temp\909547453.exe
D:\WINDOWS\temp\90995666.exe
D:\WINDOWS\xxxyab.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_ASC3550P
-------\LEGACY_DRIVER
-------\LEGACY_FCI
-------\LEGACY_KDI33
-------\LEGACY_NTIO256
-------\LEGACY_POOF
-------\LEGACY_RUNTIME
-------\Driver
-------\FCI
-------\kprof
-------\ntio256
-------\poof
-------\SysLibrary
-------\LEGACY_ASC3550F
-------\LEGACY_ASC3550P
-------\asc3550f
-------\asc3550p
-------\Kdi33
-------\SysLibrary
-------\LEGACY_PAGINGSYS
-------\asc3550f
-------\LEGACY_ASC3550P
-------\LEGACY_DRIVER
-------\LEGACY_NDISWON
-------\LEGACY_PAGINGSYS
-------\LEGACY_RUNTIME
-------\LEGACY_SMTPDRV
-------\LEGACY_STWB56
-------\asc3550f
-------\asc3550p
-------\NdisWon
-------\smtpdrv
((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-29 )))))))))))))))))))))))))))))))
.
2007-12-29 17:22 . 2007-12-29 17:22 0 --a------ D:\WINDOWS\system32\
0_exception.nls
2007-12-27 20:01 . 2007-12-27 20:01 142,848 --a------ D:\WINDOWS\system32\drivers\Amlk65.sys
2007-12-27 20:01 . 2007-12-27 20:01 16,384 --a------ D:\WINDOWS\system32\users32.dat
2007-12-27 11:20 . 2007-12-27 11:20 142,848 --a------ D:\WINDOWS\system32\drivers\Dwq67.sys
2007-12-27 11:19 . 2007-12-28 21:22 9,216 --a------ D:\WINDOWS\medichi2.exe
2007-12-27 11:19 . 2007-12-29 17:20 6,144 --a------ D:\WINDOWS\murka.dat
2007-12-27 11:19 . 2007-12-28 21:22 4,608 --a------ D:\WINDOWS\medichi.exe
2007-12-27 11:16 . 2007-12-27 11:16 142,848 --a------ D:\WINDOWS\system32\drivers\Snub48.sys
2007-12-26 18:16 . 2007-12-26 18:16 142,848 --a------ D:\WINDOWS\system32\drivers\Ojc29.sys
2007-12-26 18:12 . 2007-12-29 09:05 21,760 --a------ D:\WINDOWS\Lor03.sys
2007-12-26 14:58 . 2007-12-26 14:58 <DIR> d-------- D:\Programmer\CCleaner
2007-12-26 14:33 . 2007-12-26 14:33 142,848 --a------ D:\WINDOWS\system32\drivers\Njes50.sys
2007-12-26 14:26 . 2007-12-26 14:26 142,848 --a------ D:\WINDOWS\system32\drivers\Fifw62.sys
2007-12-26 11:17 . 2007-12-27 15:27 16 --a------ D:\WINDOWS\system32\dllgh8jkd1q8.exe
2007-12-26 11:16 . 2007-12-26 11:16 142,848 --a------ D:\WINDOWS\system32\drivers\Hbk36.sys
2007-12-26 10:07 . 2007-12-26 10:07 142,848 --a------ D:\WINDOWS\system32\drivers\Blyh73.sys
2007-12-26 10:04 . 2007-12-28 21:01 13,760 --a------ D:\WINDOWS\system32\taskmon.sys
2007-12-26 09:58 . 2007-12-26 09:58 21,760 --a------ D:\WINDOWS\system32\drivers\Lor03.sys
2007-12-26 09:57 . 2007-12-26 09:57 142,848 --a------ D:\WINDOWS\system32\drivers\Qvn50.sys
2007-12-26 09:57 . 2007-12-26 09:57 129,664 --a------ D:\WINDOWS\system32\init_7a0e-6aff.sys
2007-12-26 09:57 . 2007-12-27 11:21 23,806 --a------ D:\WINDOWS\system32\init_sys.config
2007-12-25 19:17 . 2007-12-27 20:02 177 --a------ D:\WINDOWS\system32\winupdate.dat
2007-12-25 18:34 . 2007-12-26 17:32 517,120 --a--c--- D:\WINDOWS\system32\dllcache\winlogon.exe
2007-12-25 18:32 . 2007-12-25 18:32 53,248 --a------ D:\WINDOWS\system32\mstscex.dll
2007-12-25 18:32 . 2007-12-26 10:07 39,936 --a------ D:\WINDOWS\mrofinu27.exe.tmp
2007-12-25 18:32 . 2007-12-25 18:32 35,702 --a------ D:\WINDOWS\system32\dllgh8jkd1q2.exe
2007-12-25 18:32 . 2007-12-25 18:32 18,294 --a------ D:\WINDOWS\system32\dllgh8jkd1q7.exe
2007-12-25 18:32 . 2007-12-25 18:32 17,782 --a------ D:\WINDOWS\system32\dllgh8jkd1q6.exe
2007-12-25 18:32 . 2007-12-25 18:32 16,758 --a------ D:\WINDOWS\system32\dllgh8jkd1q5.exe
2007-12-25 18:32 . 2007-12-25 18:32 11,638 --a------ D:\WINDOWS\system32\dllgh8jkd1q1.exe
2007-12-25 17:49 . 2007-12-27 15:28 54,156 --ah----- D:\WINDOWS\QTFont.qfn
2007-12-25 17:49 . 2007-12-25 17:49 1,409 --a------ D:\WINDOWS\QTFont.for
2007-12-25 10:15 . 2007-12-25 10:20 29,184 --a------ D:\WINDOWS\system32\slx.exe???????????????????5
2007-12-25 10:15 . 2007-12-25 10:20 29,184 --a------ D:\WINDOWS\system32\slx.exe???????????????????4
2007-12-25 10:11 . 2007-12-25 10:20 29,184 --a------ D:\WINDOWS\system32\slx.exe???????????????????3
2007-12-25 10:11 . 2007-12-25 10:20 29,184 --a------ D:\WINDOWS\system32\slx.exe???????????????????2
2007-12-08 14:56 . 2002-12-12 00:14 1,798,144 --a------ D:\WINDOWS\system32\qedit.dll
2007-12-08 14:56 . 2002-12-12 00:14 1,798,144 --a--c--- D:\WINDOWS\system32\dllcache\qedit.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-28 09:50 --------- d-----w D:\Programmer\SUPERAntiSpyware
2007-12-27 19:02 37,888 ----a-w D:\WINDOWS\system32\drivers\beep.sys
2007-12-27 11:17 --------- d-----w D:\Programmer\BearShare
2007-12-27 10:19 --------- d-----w D:\Programmer\QuickTime
2007-12-27 10:19 --------- d-----w D:\Programmer\MSN Messenger
2007-12-27 10:19 --------- d-----w D:\Programmer\iTunes
2007-12-08 14:02 --------- d-----w D:\Programmer\EA SPORTS
2007-11-01 21:27 --------- d-----w D:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-11-01 21:25 --------- d-----w D:\Programmer\Fælles filer\Wise Installation Wizard
2007-10-28 13:05 355,072 ----a-w D:\WINDOWS\system32\drivers\tcpip.sys
2007-10-28 07:28 12,800 ----a-w D:\WINDOWS\system32\svchost.exe
2007-10-27 16:12 109,231 ----a-w D:\WINDOWS\system32\_install.exe
2007-10-27 16:12 109,231 ----a-w D:\WINDOWS\PCHEALTH\UploadLB\Binaries\_install.exe
2007-10-27 16:12 109,231 ----a-w D:\WINDOWS\PCHEALTH\HELPCTR\Binaries\_install.exe
2007-10-27 16:12 109,231 ----a-w D:\WINDOWS\inf\_install.exe
2007-10-27 16:12 109,231 ----a-w D:\WINDOWS\Help\Tours\mmTour\_install.exe
2007-10-27 16:12 109,231 ----a-w D:\WINDOWS\_install.exe
2007-10-27 16:12 109,231 ----a-w D:\Programmer\_install.exe
2004-07-29 20:38 93,386 -c--a-w D:\Programmer\filelist.txt
2003-10-08 01:00 614,456 -c--a-w D:\Programmer\
00000001.016
2003-10-08 01:00 614,456 -c--a-w D:\Programmer\
00000000.016
2003-10-08 01:00 41,472 -c--a-w D:\Programmer\DrvMgt.dll
2003-10-08 01:00 12,528 -c--a-w D:\Programmer\SECDRV.SYS
2003-10-08 01:00 1,228,856 -c--a-w D:\Programmer\
00000001.256
2003-10-08 01:00 1,228,856 -c--a-w D:\Programmer\
00000000.256
2003-10-07 19:03 14,775 -c--a-w D:\Programmer\config.dat
2003-10-03 02:59 23,558 -c--a-w D:\Programmer\fifapc.ico
2001-11-23 04:08 712,704 -c--a-w D:\WINDOWS\inf\OTHER\AUDIO3D.DLL
2007-05-15 11:35 31,552 --sh--r D:\WINDOWS\system32\1037d.exe
2007-07-03 21:16 56 --sh--r D:\WINDOWS\system32\F4AE630A3B.sys
2007-06-21 16:43 37 --sha-w D:\WINDOWS\system32\index.dat
2007-07-03 21:16 3,350 --sha-w D:\WINDOWS\system32\KGyGaAvL.sys
.
D:\WINDOWS\system32\drivers\tcpip.sys ... is infected !! (additional data below) 327,168 2001-10-09 12:00:00 D:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
332,928 2002-08-28 23:58:12 D:\WINDOWS\ServicePackFiles\i386\tcpip.sys
355,072 2007-10-28 13:05:36 D:\WINDOWS\system32\drivers\tcpip.sys
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 503,808 2003-09-07 18:41:26 D:\Programmer\Creative\Mouse Optical\bak\mouse_2k.exe
----a-w 0 2003-06-05 15:18:26 D:\Programmer\Creative\Mouse Optical\mouse_2k.exe
----a-w 109,231 2007-10-27 16:12:21 D:\Programmer\Creative\Mouse Optical\bak\_install.exe
----a-w 109,231 2007-10-27 16:12:21 D:\Programmer\Creative\Mouse Optical\_install.exe
------w 0 1601-01-01 00:00:00 D:\Programmer\Fµlles filer\Ahead\Lib\bak\
----a-w 256,576 2006-10-30 08:36:36 D:\Programmer\iTunes\bak\iTunesHelper.exe
----a-w 256,576 2007-12-27 10:16:32 D:\Programmer\iTunes\ituneshelper.exe
----a-w 109,231 2007-10-27 16:12:21 D:\Programmer\iTunes\bak\_install.exe
----a-w 109,231 2007-10-27 16:12:21 D:\Programmer\iTunes\_install.exe
----a-w 49,263 2006-11-09 14:07:30 D:\Programmer\Java\jre1.5.0_10\bin\bak\jusched.exe
----a-w 109,231 2007-10-27 16:12:21 D:\Programmer\Java\jre1.5.0_10\bin\bak\_install.exe
----a-w 109,231 2007-10-27 16:12:21 D:\Programmer\Java\jre1.5.0_10\bin\_install.exe
----a-w 401,491 2004-02-24 13:07:58 D:\Programmer\Microsoft ActiveSync\bak\WCESCOMM.EXE
----a-w 0 2003-06-05 15:18:29 D:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE
----a-w 282,624 2006-10-25 17:58:18 D:\Programmer\QuickTime\bak\qttask.exe
----a-w 282,624 2007-12-27 10:16:32 D:\Programmer\QuickTime\qttask.exe
----a-w 109,231 2007-10-27 16:12:21 D:\Programmer\QuickTime\bak\_install.exe
----a-w 109,231 2007-10-27 16:12:21 D:\Programmer\QuickTime\_install.exe
----a-w 327,680 2002-07-18 15:12:50 D:\Programmer\Trend Micro\PC-cillin 2002\bak\PCCClient.exe
----a-w 258,048 2002-07-18 15:18:42 D:\Programmer\Trend Micro\PC-cillin 2002\bak\pccguide.exe
----a-w 307,266 2002-07-18 15:15:32 D:\Programmer\Trend Micro\PC-cillin 2002\bak\Pop3trap.exe
----a-w 109,231 2007-10-27 16:12:21 D:\Programmer\Trend Micro\PC-cillin 2002\bak\_install.exe
----a-w 109,231 2007-10-27 16:12:21 D:\Programmer\Trend Micro\PC-cillin 2002\_install.exe
----a-w 106,496 2002-07-12 10:15:12 D:\WINDOWS\bak\SiSUSBrg.exe
----a-w 109,231 2007-10-27 16:12:21 D:\WINDOWS\bak\_install.exe
----a-w 109,231 2007-10-27 16:12:21 D:\WINDOWS\_install.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="D:\Programmer\MSN Messenger\msnmsgr.exe" [2007-12-27 11:16]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2001-10-09 13:00 D:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2005-08-02 15:35 D:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="RUNDLL32.exe" [2001-10-09 13:00 D:\WINDOWS\system32\rundll32.exe]
"iTunesHelper"="D:\Programmer\iTunes\iTunesHelper.exe" [2007-12-27 11:16]
"QuickTime Task"="D:\Programmer\QuickTime\qttask.exe" [2007-12-27 11:16]
"kcbtaxcf"="D:\mgbdrlta.bat" []
"ysvcvcji"="D:\yvyalyqf.bat" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\System32\CTFMON.EXE" [2002-09-09 13:13]
"Ordbogen.com"="D:\Programmer\CoolSystems\ordbogen.com\ordbogen.exe" [2007-08-17 13:19]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 1 (0x1)
"DisableTaskMgr"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 1 (0x1)
"DisableTaskMgr"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoControlPanel"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoControlPanel"= 1 (0x1)
"NoWindowsUpdate"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= D:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
D:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 D:\Programmer\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lor03.sys]
@="Driver"
R0 Lor03;Lor03;D:\WINDOWS\System32\Drivers\Lor03.sys [2007-12-26 09:58]
R2 PCC_PFW;PC-Cillin Personal Firewall;D:\WINDOWS\System32\Drivers\PCC_PFW.sys [2002-07-18 16:11]
S2 init_7a0e-6aff;init_7a0e-6aff;D:\WINDOWS\System32\init_7a0e-6aff.sys [2007-12-26 09:57]
S3 AntiyFirewall;AntiyFirewall;D:\WINDOWS\System32\drivers\AntiyFW.sys [2005-10-12 17:27]
S3 taskmon.sys;taskmon.sys;D:\WINDOWS\System32\taskmon.sys [2007-12-28 21:01]
.
Contents of the 'Scheduled Tasks' folder
"2007-12-19 13:13:07 D:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- D:\Programmer\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-12-29 17:23:04
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
D:\WINDOWS\medichi.exe [2420] 0x81CFEBC8
D:\WINDOWS\medichi2.exe [2456] 0x81DBF9E8
scanning hidden autostart entries ...
scanning hidden files ...
D:\WINDOWS\system32\bldy.config 56390 bytes
D:\WINDOWS\system32\bldy332e-15e.sys 129664 bytes executable
scan completed successfully
hidden files: 2
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\bldy332e-15e]
"ImagePath"="\??\D:\WINDOWS\System32\bldy332e-15e.sys"
.
Completion time: 2007-12-29 17:28:00 - machine was rebooted [Andr‚]
----------------------------------------------------
SmitFraudFix v2.274
Scan done at 17:50:20.42, 29-12-2007
Run from C:\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix
S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
IEDFix.exe by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» DNS
HKLM\SYSTEM\CCS\Services\Tcpip\..\{9721E5A9-F71E-4EC0-9716-2D6E45DB2400}: DhcpNameServer=193.162.153.164 194.239.134.83
HKLM\SYSTEM\CS1\Services\Tcpip\..\{9721E5A9-F71E-4EC0-9716-2D6E45DB2400}: DhcpNameServer=193.162.153.164 194.239.134.83
HKLM\SYSTEM\CS2\Services\Tcpip\..\{9721E5A9-F71E-4EC0-9716-2D6E45DB2400}: DhcpNameServer=193.162.153.164 194.239.134.83
HKLM\SYSTEM\CS3\Services\Tcpip\..\{9721E5A9-F71E-4EC0-9716-2D6E45DB2400}: DhcpNameServer=193.162.153.164 194.239.134.83
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=193.162.153.164 194.239.134.83
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=193.162.153.164 194.239.134.83
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=193.162.153.164 194.239.134.83
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=193.162.153.164 194.239.134.83
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
-----------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 18:06:47, on 29-12-2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Programmer\Antiy Labs\Alive\ALiveCenter.exe
D:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Programmer\Trend Micro\PC-cillin 2002\Tmntsrv.exe
D:\WINDOWS\System32\MsPMSPSv.exe
D:\Programmer\Trend Micro\PC-cillin 2002\PCCPFW.exe
D:\Programmer\Canon\CAL\CALMAIN.exe
D:\Programmer\Internet Explorer\IEXPLORE.EXE
D:\WINDOWS\Explorer.EXE
D:\Programmer\iTunes\iTunesHelper.exe
D:\Programmer\QuickTime\qttask.exe
D:\Programmer\MSN Messenger\msnmsgr.exe
D:\Programmer\iPod\bin\iPodService.exe
D:\Programmer\MSN Messenger\usnsvc.exe
D:\Programmer\Internet Explorer\IEXPLORE.EXE
D:\WINDOWS\system32\NOTEPAD.EXE
D:\André\André\Musik\alternativ.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dr.dk/sportenR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\programmer\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\programmer\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "D:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [kcbtaxcf] D:\mgbdrlta.bat
O4 - HKLM\..\Run: [ysvcvcji] D:\yvyalyqf.bat
O4 - HKCU\..\Run: [msnmsgr] "D:\Programmer\MSN Messenger\msnmsgr.exe" /background
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: Add to AMV Convert Tool... - D:\Programmer\MP3 Player Utilities 3.79\AMVConverter\grab.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel -
res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: MediaManager tool grab multimedia file - D:\Programmer\MP3 Player Utilities 3.79\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Opret Foretrukken på mobil enhed - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Opret Foretrukken på mobil enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmer\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: D:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) -
http://downol.dr.dk/download/netradio/Rawflow.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cabO16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) -
https://netbank.bgbank.dk/html/activex/BG/Menu.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1133301966077O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cabO16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cabO16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) -
https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exeO16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) -
https://netbank.bgbank.dk/html/activex/e-Safekey/BG/e-Safekey.cabO16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cabO18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: murka.dat
O20 - Winlogon Notify: !SASWinLogon - D:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Gatewaytjeneste til programlaget (ALG) - Unknown owner - cmd.exe (file missing)
O23 - Service: Antiy live update (Alive Auto-Update Service) - Unknown owner - D:\Programmer\Antiy Labs\Alive\ALiveCenter.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - D:\Programmer\Canon\CAL\CALMAIN.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - D:\Programmer\iPod\bin\iPodService.exe
O23 - Service: NetMeeting - Deling af fjernskrivebord mnmsrvcUMWdf (mnmsrvcUMWdf) - Unknown owner - D:\WINDOWS\System32\1037d.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - D:\Programmer\Trend Micro\PC-cillin 2002\PCCPFW.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - D:\Programmer\Trend Micro\PC-cillin 2002\Tmntsrv.exe