Avatar billede whirlwind Nybegynder
26. januar 2008 - 15:44 Der er 7 kommentarer og
1 løsning

Hijackthis- root- og combofix.log

Hej, er der nogen der orker at kigge disse logs igennem for at se, om der er noget grimt der ikke bør være der ??

HJT-log:

Logfile of HijackThis v1.99.1
Scan saved at 03:28:28, on 26-01-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\hphmon04.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
C:\Documents and Settings\HP_Administrator\Desktop\clean\alternativ.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Norton-værktøjslinjen - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: PacificPoker4 - {94EDF7B4-4272-4af3-8F8B-4E2F68E225B7} - C:\PROGRA~1\PACIFI~1\pacificpoker.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Program Files\ladbrokesMPP\MPPoker.exe
O9 - Extra button: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://a1540.g.akamai.net/7/1540/52/20070711/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4445EA6A-9008-40D5-9160-035FDE5214C4} - http://www.123hjemmeside.dk/builder/pages/Mpu-dk-1-0-0-8.cab
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://www.king.com/ctl/kingcomie.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1152542244148
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.hp.com/ediags/dd/install/guidedsolutions.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {DC6FEBC5-0A2D-458A-A01B-5DB15EEC4305} (IlosoftImageUploadCtl Class) - http://webc.skarnsungerne.dk/controls/IlosoftImageUpload.dll
O16 - DPF: {EDAF796E-9210-4417-ADDC-2AB18E4F6C27} (Hjemmeside.KvikFoto) - http://www.123hjemmeside.dk/builder/pages/KvikFoto.CAB
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

----------
rootlog
----------
********************************* ROOTCHK-(28-12-07)-LOG, by ejvindh
26-01-2008  3:29:23,53

NOTICE!! Rootchk is not being updated anymore, and is thus gradually getting outdated.
Last update was made 28-12-07

The rootkits that are detected by this tool were not found.

********************************* ROOTCHK-LOG-end


catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-26 03:29:24
Windows 5.1.2600 Service Pack 2
scanning hidden processes ...
IPC error: 2 Den angivne fil blev ikke fundet.

scanning hidden services & system hive ...
IPC error: 2 Den angivne fil blev ikke fundet.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00125a5d3780]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s0"=dword:0592275a
"s1"=dword:81060f40
"s2"=dword:eec474b3
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:01,0f,17,d1,fa,31,68,61,5b,d4,3d,67,42,99,69,58,8e,8f,14,b6,2b,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\00125a5d3780]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:01,0f,17,d1,fa,31,68,61,5b,d4,3d,67,42,99,69,58,8e,8f,14,b6,2b,..

scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:00000281

scanning hidden files ...
IPC error: 2 Den angivne fil blev ikke fundet.

hidden processes: 0
hidden services: 0
hidden files: 0

------------
combofix.log
------------

ComboFix 08-01-23.1C - HP_Administrator 2008-01-26 13:58:34.2 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.500 [GMT 1:00]
Running from: C:\Documents and Settings\HP_Administrator\Desktop\clean\ComboFix.exe
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
.
---- Previous Run -------
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Program Files\MyWay
C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
C:\Program Files\MyWay\myBar\History\search
C:\Program Files\MyWay\myBar\Settings\prevcfg.htm
D:\Autorun.inf

----- BITS: Possible infected sites -----

hxxp://epg.tvdownload.microsoft.com

.
(((((((((((((((((((((((((  Files Created from 2007-12-26 to 2008-01-26  )))))))))))))))))))))))))))))))
.

2008-01-26 13:58 . 2008-01-26 13:58    6,736    --a------    C:\WINDOWS\system32\drivers\PROCEXP90.SYS
2008-01-26 03:32 . 2000-08-31 08:00    51,200    --a------    C:\WINDOWS\Nircmd.exe
2008-01-26 00:24 . 2008-01-26 00:36    <DIR>    d--------    C:\Program Files\SUPERAntiSpyware
2008-01-26 00:13 . 2008-01-26 00:13    <DIR>    d--------    C:\Program Files\CCleaner
2008-01-25 23:24 . 2008-01-26 13:01    1,697    --a------    C:\WINDOWS\bthservsdp.dat
2008-01-25 18:41 . 2004-08-03 22:58    100,992    --a------    C:\WINDOWS\system32\drivers\bthpan.sys
2008-01-25 18:41 . 2004-08-03 22:58    100,992    --a------    C:\WINDOWS\system32\dllcache\bthpan.sys
2008-01-25 18:30 . 2006-09-01 12:09    59,264    ---------    C:\WINDOWS\system32\dllcache\usbhub.sys
2008-01-25 18:30 . 2006-10-31 11:26    36,864    ---------    C:\WINDOWS\system32\dllcache\hidclass.sys
2008-01-25 18:16 . 2008-01-25 18:17    <DIR>    d--------    C:\Program Files\Microsoft IntelliPoint
2008-01-25 18:13 . 2008-01-25 18:14    <DIR>    d--------    C:\Program Files\Microsoft IntelliType Pro
2008-01-25 17:35 . 2008-01-25 17:35    <DIR>    d--------    C:\Program Files\MSBuild
2008-01-25 17:31 . 2008-01-25 17:31    <DIR>    d--------    C:\WINDOWS\system32\XPSViewer
2008-01-25 17:29 . 2008-01-25 17:29    <DIR>    d--------    C:\Program Files\Reference Assemblies
2008-01-25 17:27 . 2008-01-25 17:27    <DIR>    d--------    C:\Program Files\MSXML 6.0
2008-01-25 17:27 . 2006-06-29 13:07    14,048    ---------    C:\WINDOWS\system32\spmsg2.dll
2008-01-23 20:45 . 2008-01-23 20:45    <DIR>    d--------    C:\Program Files\Common Files\Apple
2008-01-16 21:57 . 2008-01-16 21:57    34    --a------    C:\WINDOWS\hpfsched.ini
2008-01-16 21:55 . 2008-01-16 21:55    <DIR>    d--------    C:\Program Files\HP Photosmart 11
2008-01-16 21:42 . 2008-01-16 22:18    <DIR>    d--------    C:\temp\photosmart
2008-01-03 23:34 . 2008-01-03 23:41    <DIR>    d--------    C:\Program Files\bet365poker

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-26 11:45    ---------    d-----w    C:\Program Files\Common Files\Symantec Shared
2008-01-25 23:23    ---------    d-----w    C:\Program Files\Common Files\Wise Installation Wizard
2008-01-25 23:06    ---------    d-----w    C:\Program Files\QuickTime
2008-01-25 23:03    ---------    d-----w    C:\Program Files\mIRC
2008-01-25 23:02    ---------    d-----w    C:\Program Files\eMule
2008-01-25 23:02    ---------    d-----w    C:\Program Files\BitTorrent
2008-01-25 22:41    ---------    d-----w    C:\Program Files\PKR
2008-01-25 22:11    ---------    d-----w    C:\Program Files\InterActual
2008-01-25 17:53    ---------    d-----w    C:\Program Files\PokerStars
2008-01-07 13:40    ---------    d-----w    C:\Program Files\bet365MPP
2008-01-03 22:46    ---------    d-----w    C:\Program Files\TexasCalculatem
2008-01-03 22:30    ---------    d-----w    C:\Program Files\PartyGaming
2008-01-03 22:26    ---------    d-----w    C:\Program Files\bwin
2008-01-03 22:23    ---------    d-----w    C:\Program Files\PokerRoom.com
2008-01-03 05:00    ---------    d-----w    C:\Program Files\DivX
2007-12-23 09:09    ---------    d-----w    C:\Program Files\Norton Internet Security
2007-12-20 21:16    ---------    d-----w    C:\Program Files\MySpace
2007-12-11 19:46    524,288    ----a-w    C:\WINDOWS\system32\DivXsm.exe
2007-12-11 19:46    3,596,288    ----a-w    C:\WINDOWS\system32\qt-dx331.dll
2007-12-11 19:45    200,704    ----a-w    C:\WINDOWS\system32\ssldivx.dll
2007-12-11 19:45    1,044,480    ----a-w    C:\WINDOWS\system32\libdivx.dll
2007-12-11 19:44    823,296    ----a-w    C:\WINDOWS\system32\divx_xx0c.dll
2007-12-11 19:44    823,296    ----a-w    C:\WINDOWS\system32\divx_xx07.dll
2007-12-11 19:44    81,920    ----a-w    C:\WINDOWS\system32\dpl100.dll
2007-12-11 19:44    802,816    ----a-w    C:\WINDOWS\system32\divx_xx11.dll
2007-12-11 19:44    682,496    ----a-w    C:\WINDOWS\system32\DivX.dll
2007-12-11 19:44    593,920    ----a-w    C:\WINDOWS\system32\dpuGUI11.dll
2007-12-11 19:44    57,344    ----a-w    C:\WINDOWS\system32\dpv11.dll
2007-12-11 19:44    53,248    ----a-w    C:\WINDOWS\system32\dpuGUI10.dll
2007-12-11 19:44    344,064    ----a-w    C:\WINDOWS\system32\dpus11.dll
2007-12-11 19:44    294,912    ----a-w    C:\WINDOWS\system32\dpu11.dll
2007-12-11 19:44    294,912    ----a-w    C:\WINDOWS\system32\dpu10.dll
2007-12-11 19:44    196,608    ----a-w    C:\WINDOWS\system32\dtu100.dll
2007-12-11 19:44    156,992    ----a-w    C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-12-11 19:43    12,288    ----a-w    C:\WINDOWS\system32\DivXWMPExtType.dll
2007-12-08 00:00    ---------    d-----w    C:\Program Files\SNGShark
2007-12-06 18:09    805    ----a-w    C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-12-06 18:09    60,800    ----a-w    C:\WINDOWS\system32\S32EVNT1.DLL
2007-12-06 18:09    123,952    ----a-w    C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-12-06 18:09    10,740    ----a-w    C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-12-06 18:09    ---------    d-----w    C:\Program Files\Symantec
2007-11-30 22:57    43,696    ----a-w    C:\WINDOWS\system32\drivers\srtspx.sys
2007-11-30 22:57    317,616    ----a-w    C:\WINDOWS\system32\drivers\srtspl.sys
2007-11-30 22:57    279,088    ----a-w    C:\WINDOWS\system32\drivers\srtsp.sys
2007-11-30 22:57    10,549    ----a-w    C:\WINDOWS\system32\drivers\srtspx.cat
2007-11-30 22:57    10,549    ----a-w    C:\WINDOWS\system32\drivers\srtspl.cat
2007-11-30 22:57    10,545    ----a-w    C:\WINDOWS\system32\drivers\srtsp.cat
2007-11-30 22:57    1,430    ----a-w    C:\WINDOWS\system32\drivers\srtspl.inf
2007-11-30 22:57    1,421    ----a-w    C:\WINDOWS\system32\drivers\srtspx.inf
2007-11-30 22:57    1,415    ----a-w    C:\WINDOWS\system32\drivers\srtsp.inf
2007-11-26 19:18    ---------    d-----w    C:\Program Files\Apple Software Update
2007-11-25 00:50    120    ----a-w    C:\drmHeader.bin
2007-11-07 09:26    721,920    ----a-w    C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26    721,920    ----a-w    C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 23:42    3,590,656    ----a-w    C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-30 17:20    360,064    ----a-w    C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-29 22:35    1,287,680    ----a-w    C:\WINDOWS\system32\quartz.dll
2007-10-29 22:35    1,287,680    ----a-w    C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 16:40    222,720    ----a-w    C:\WINDOWS\system32\wmasf.dll
2007-10-27 16:40    222,720    ----a-w    C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34    8,460,288    ----a-w    C:\WINDOWS\system32\dllcache\shell32.dll
2007-04-20 13:12    574    ----a-w    C:\Program Files\changeLog.txt
2007-04-20 12:31    875,778    ----a-w    C:\Program Files\Setup-SopCore-1.1.2-2007-04-20.exe
2006-10-22 12:08    251    ----a-w    C:\Program Files\wt3d.ini
2005-05-12 05:36    12,288    ----a-w    C:\WINDOWS\Fonts\RandFont.dll
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2007-08-24 20:51    316784    --a------    C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2007-09-16 16:49    116088    --a------    C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [2007-08-24 20:51 316784]

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 13:00 15360]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-04-23 15:46 1318128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-06 05:56 64512]
"ftutil2"="ftutil2.dll" [2004-06-08 06:05 106496 C:\WINDOWS\system32\ftutil2.dll]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 17:04 52736]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 08:19 77312 C:\WINDOWS\arpwrmsg.exe]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 07:35 49152]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 22:14 237568]
"Reminder"="C:\Windows\Creator\Remind_XP.exe" [2004-12-14 02:23 663552]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 06:12 49152]
"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 15:44 61440]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2006-01-06 20:07 188416]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50 155648]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2006-05-20 11:13 188416]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-01 16:22 7618560]
"nwiz"="nwiz.exe" [2006-06-01 16:22 1519616 C:\WINDOWS\system32\nwiz.exe]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 23:50 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 23:50 81920]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 16:22 86016 C:\WINDOWS\system32\nvmctray.dll]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-01-02 21:54 180269]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 10:09 63712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-10-23 16:18 51048]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2007-08-24 21:53 714608]
"HPHmon04"="C:\WINDOWS\system32\hphmon04.exe" [2006-01-06 20:07 348160]
"RTHDCPL"="RTHDCPL.EXE" [2007-10-25 03:57 16855552 C:\WINDOWS\RTHDCPL.EXE]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-11-22 02:08 813912]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-22 02:09 842584]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-10 13:00 110592 C:\WINDOWS\system32\bthprops.cpl]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [ ]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 06:23:26 282624]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

R0 dontgo;Promise Removable Disk Control Driver;C:\WINDOWS\system32\DRIVERS\DontGo.sys [2004-06-30 05:25]
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" [2007-10-23 16:18]
R3 3xHybrid;ASUSTek SAA713x PCI Card;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2007-01-26 10:42]
R3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 17:27]
R3 WN5301;LIteon Wireless PCI Network Adapter Service;C:\WINDOWS\system32\DRIVERS\wn5301.sys [2005-10-05 18:44]
S2 Automatisk LiveUpdate-planlægning;Automatisk LiveUpdate-planlægning;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-08-31 10:49]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2007-05-29 13:55]
S3 PciCon;PciCon;E:\PciCon.sys []
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 17:27]

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-01-23 10:50:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-25 17:33:03 C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job"
- C:\Program Files\Microsoft IntelliPoint\ipoint.exe
"2008-01-25 17:33:03 C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_IType_exe.job"
- C:\Program Files\Microsoft IntelliType Pro\itype.exe
"2008-01-09 02:07:24 C:\WINDOWS\Tasks\Norton Internet Security - Kør Fuld systemskanning - HP_Administrator.job"
26. januar 2008 - 19:05 #1
C:\Program Files\eMule !!!
C:\Program Files\BitTorrent !!!

http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=40284
01. februar 2008 - 21:07 #2
???
Avatar billede whirlwind Nybegynder
01. februar 2008 - 23:57 #3
Hej karise

Jeg beklager, at jeg ikke er vendt tílbage vedrørende ovennævnte og beklager, at jeg har spildt din tid ved ikke at læse grundigt nok på "lektien".

Jeg har i mellemtiden fundet ud af, at mit problem ikke ligger i de evt. snavs i mine logs.

Igen jeg beklager, at jeg har spildt din tid.

Du kan lægge et svar, så skal jeg give dig points :)
02. februar 2008 - 09:21 #4
... men ER det klaret ?
Avatar billede whirlwind Nybegynder
03. februar 2008 - 00:01 #5
Både ja og nej. Mit problem bestod i første omgang af, at en bluetooth-usb-stick åd al min processorkraft når jeg satte den til. Efter at have ledt højt og lavt efter en løsning og forsøgt alle mulige ting. Besluttede jeg mig for at prøve at rense ud i snavs på 'puteren vha. hijackthis osv.

Efter at have smidt loggen herinde, lykkedes det mig dog at finde en løsning, som intet havde med "snavs" at gøre. Der var bare nogle småting der skulles slås fra i enhedshåndteringen og så venter jeg på svar fra Microsoft-support, som er på sagen nu.
03. februar 2008 - 11:45 #6
ComboFix har dog smidt nogle Uønskede elementer ud for dig...

Generelt - pas på med nævnte
C:\Program Files\eMule !!!
C:\Program Files\BitTorrent !!!

Læg selv et [svar] og la' os alle dele...
Avatar billede whirlwind Nybegynder
05. februar 2008 - 08:09 #7
Jeg ved godt jeg generelt skal passe på vedr. P2P-software. Har også efterfølgende slettet de to programmer.

Snup du bare pointene karise ;)
05. februar 2008 - 08:46 #8
Takker...
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester