Log-fil for Combofix (fandt den endelig)
ComboFix 08-03-24.1 - Jørgen 2008-03-25 0:02:39.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1030.18.1019 [GMT 1:00]
Running from: D:\Basisprogrammer 04\Combofix\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
-- Script messages for sUBs --
MTEE /+ d-delA.dat
VFind -tf "C:\Documents and Settings\All Users.WINDOWS\Application Data.\microsoft\iehelper*"
CF28148.exe /c " VFind.exe -ltf -s-1000000 -d+2007-12-24 "C:\Programmer\*" >progfile.dat"
VFind.exe -ltf -s-1000000 -d+2007-12-24 "C:\Programmer\*"
CF28148.exe /c " dir /a/s/b C:\_desktop.ini C:\desktop_.ini C:\cnsmin* C:\_install.exe >DirRoot"
((((((((((((((((((((((((( Files Created from 2008-02-24 to 2008-03-24 )))))))))))))))))))))))))))))))
.
2008-03-24 23:16 . 2008-03-24 23:16 <DIR> d-------- C:\Programmer\SUPERAntiSpyware
2008-03-24 23:16 . 2008-03-24 23:16 <DIR> d-------- C:\Documents and Settings\Jørgen.CHIEFTEC\Application Data\SUPERAntiSpyware.com
2008-03-24 23:16 . 2008-03-24 23:16 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2008-03-24 21:57 . 2008-03-24 21:57 3 --a------ C:\WINDOWS\system\BR.dll
2008-03-24 19:32 . 2008-03-24 19:32 <DIR> d-------- C:\Programmer\IObit
2008-03-24 16:03 . 2008-02-29 17:14 19,712 --a------ C:\WINDOWS\system32\drivers\antispyware.sys
2008-03-24 15:31 . 2008-03-24 15:31 <DIR> d-------- C:\Programmer\PC Connectivity Solution
2008-03-24 15:31 . 2008-03-24 15:31 <DIR> d-------- C:\Programmer\Nokia
2008-03-24 15:31 . 2008-03-24 15:32 <DIR> d-------- C:\Programmer\Fælles filer\PCSuite
2008-03-24 15:31 . 2008-03-24 15:31 <DIR> d-------- C:\Programmer\Fælles filer\Nokia
2008-03-24 15:27 . 2008-03-24 15:27 <DIR> d-------- C:\Documents and Settings\Jørgen.CHIEFTEC\Bluetooth Software
2008-03-24 15:27 . 2008-03-24 15:27 <DIR> d-------- C:\Documents and Settings\Jørgen.CHIEFTEC\Bluetooth Software
2008-03-24 15:21 . 2008-03-24 15:21 <DIR> d-------- C:\Programmer\ASUS
2008-03-24 12:55 . 2008-03-24 12:55 <DIR> d-------- C:\Programmer\CCleaner
2008-03-22 16:46 . 2008-03-22 16:51 568 --a------ C:\WINDOWS\_delis32.ini
2008-03-22 13:15 . 2008-03-24 20:21 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-03-22 09:29 . 2008-03-22 09:29 <DIR> d-------- C:\Documents and Settings\Jørgen.CHIEFTEC\Application Data\Uniblue
2008-03-22 00:36 . 2008-03-24 23:41 5,394 --a------ C:\WINDOWS\system32\Config.MPF
2008-03-22 00:35 . 2008-03-24 12:46 <DIR> d-------- C:\Programmer\SiteAdvisor
2008-03-22 00:35 . 2008-03-22 00:35 <DIR> d-------- C:\Documents and Settings\LocalService.NT AUTHORITY\Skrivebord
2008-03-22 00:35 . 2008-03-22 10:14 <DIR> d-------- C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\SiteAdvisor
2008-03-22 00:35 . 2008-03-24 12:16 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\SiteAdvisor
2008-03-22 00:34 . 2008-02-06 09:51 171,400 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-03-22 00:34 . 2007-06-25 14:54 71,496 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-03-22 00:34 . 2007-06-25 10:57 37,480 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-03-22 00:34 . 2007-06-25 10:57 34,184 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-03-22 00:34 . 2007-06-25 10:57 32,008 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2008-03-22 00:33 . 2008-03-22 00:33 <DIR> d-------- C:\Programmer\McAfee.com
2008-03-22 00:33 . 2008-03-22 00:33 <DIR> d-------- C:\Programmer\Fælles filer\McAfee
2008-03-22 00:33 . 2007-03-02 14:16 109,608 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2008-03-22 00:32 . 2008-03-22 09:03 <DIR> d-------- C:\Programmer\McAfee
2008-03-21 23:38 . 2008-03-21 23:38 76,297 --a------ C:\WINDOWS\blue44.jpg
2008-03-14 16:26 . 2004-08-26 17:53 380,928 --------- C:\WINDOWS\system32\irprops.cpl
2008-03-14 16:26 . 2004-08-26 17:53 162,304 --------- C:\WINDOWS\system32\wuaucpl.cpl
2008-03-14 16:25 . 2004-08-26 17:53 7,680 --a--c--- C:\WINDOWS\system32\dllcache\migregdb.exe
2008-03-14 16:24 . 2008-03-14 16:24 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-03-14 16:19 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\
002719_.tmp
2008-03-14 15:39 . 2003-12-14 17:21 159,744 --a------ C:\WINDOWS\system32\igfxres.dll
2008-03-14 15:24 . 2001-10-09 13:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-03-14 15:23 . 2001-10-09 13:00 1,677,824 --a--c--- C:\WINDOWS\system32\dllcache\chsbrkr.dll
2008-03-14 15:11 . 2004-08-26 17:53 278,528 --a------ C:\WINDOWS\system32\inetcfg.dll
2008-03-14 15:10 . 2004-08-26 17:53 1,134,592 --a------ C:\WINDOWS\system32\wuaueng.dll
2008-03-14 15:08 . 2004-08-03 23:07 52,864 --a------ C:\WINDOWS\system32\drivers\dmusic.sys
2008-03-14 15:02 . 2004-08-26 17:48 57,856 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2008-03-14 15:02 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-03-14 15:02 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-03-14 14:38 . 2004-08-03 23:01 196,864 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys
2008-03-14 14:38 . 2004-08-26 17:54 40,840 --a------ C:\WINDOWS\system32\drivers\termdd.sys
2008-03-14 14:36 . 2008-03-14 14:36 <DIR> d-------- C:\Documents and Settings\Default User.WINDOWS\Skrivebord
2008-03-14 14:36 . 2008-03-14 15:10 <DIR> d--h----- C:\Documents and Settings\Default User.WINDOWS\Skabeloner
2008-03-14 14:36 . 2008-03-14 14:36 <DIR> d--h----- C:\Documents and Settings\Default User.WINDOWS\Printere
2008-03-14 14:36 . 2008-03-14 14:36 <DIR> dr------- C:\Documents and Settings\Default User.WINDOWS\Menuen Start
2008-03-14 14:36 . 2008-03-14 14:36 <DIR> dr-h----- C:\Documents and Settings\Default User.WINDOWS\Lokale indstillinger
2008-03-14 14:36 . 2008-03-14 14:36 <DIR> d-------- C:\Documents and Settings\Default User.WINDOWS\Foretrukne
2008-03-14 14:36 . 2008-03-14 14:36 <DIR> d-------- C:\Documents and Settings\Default User.WINDOWS\Dokumenter
2008-03-14 14:36 . 2008-03-14 14:36 <DIR> d--h----- C:\Documents and Settings\Default User.WINDOWS\Andre computere
2008-03-14 14:35 . 2001-10-09 13:00 1,085,938 -ra------ C:\WINDOWS\SET1A9.tmp
2008-03-13 18:47 . 2008-03-13 18:47 <DIR> d-------- C:\fsaua.data
2008-03-13 00:30 . 2008-03-13 00:30 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-03-12 22:02 . 2003-10-03 16:28 45,056 --a------ C:\WINDOWS\system32\vusetup.dll
2008-03-12 22:02 . 2005-06-06 17:51 11,264 --a------ C:\WINDOWS\system32\drivers\vulfntr.sys
2008-03-12 22:02 . 2005-01-05 18:02 6,912 --a------ C:\WINDOWS\system32\drivers\vulfnth.sys
2008-03-11 18:14 . 2008-03-24 23:42 <DIR> d-------- C:\Documents and Settings\Jørgen.CHIEFTEC\Application Data\Antispyware
2008-03-11 18:13 . 2008-03-24 23:42 <DIR> d-------- C:\Programmer\AntiSpywareApp
2008-03-11 15:27 . 2008-03-13 00:30 <DIR> d-------- C:\Programmer\ErrorSmart
2008-03-11 15:27 . 2008-03-13 00:30 <DIR> d-------- C:\Documents and Settings\Jørgen.CHIEFTEC\Application Data\ErrorSmart
2008-03-02 12:57 . 2008-03-02 19:34 35,363 --a------ C:\WINDOWS\system32\windrvNT.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-24 22:15 --------- d-----w C:\Programmer\Fælles filer\Wise Installation Wizard
2008-03-24 21:14 --------- d-----w C:\Programmer\Folder Lock
2008-03-24 15:54 --------- d-----w C:\Programmer\KopiKontrol
2008-03-24 15:11 --------- d-----w C:\Programmer\StreamCast
2008-03-24 12:05 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-03-24 11:25 --------- d-----w C:\Programmer\Windows Live Safety Center
2008-03-24 11:18 --------- d-----w C:\Programmer\LimeWire
2008-03-22 15:57 --------- d-----w C:\Programmer\Logitech
2008-03-22 15:56 --------- d-----w C:\Programmer\Fælles filer\Logitech
2008-03-21 23:42 --------- d-----w C:\Documents and Settings\Jørgen.CHIEFTEC\Application Data\SiteAdvisor
2008-03-21 23:36 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee
2008-03-21 23:26 --------- d-----w C:\Documents and Settings\Jørgen.CHIEFTEC\Application Data\U3
2008-03-18 23:12 95,672 ----a-w C:\Documents and Settings\Jørgen.CHIEFTEC\Application Data\GDIPFONTCACHEV1.DAT
2008-03-16 19:59 --------- d-----w C:\Documents and Settings\Jørgen.CHIEFTEC\Application Data\ZoomBrowser EX
2008-03-16 13:42 --------- d-----w C:\Programmer\Lotto3
2008-03-15 09:08 --------- d-----w C:\Documents and Settings\Jørgen.CHIEFTEC\Application Data\CoreFTP
2008-03-14 17:07 --------- d-----w C:\Programmer\Fælles filer\ANWSOFT
2008-03-14 17:07 --------- d-----w C:\Programmer\Fælles filer\A&W
2008-03-08 12:54 --------- d-----w C:\Documents and Settings\Jørgen.CHIEFTEC\Application Data\Canon
2008-02-26 17:45 --------- d-----w C:\Documents and Settings\Jørgen.CHIEFTEC\Application Data\OpenOffice.org2
2008-02-25 21:40 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\ZoomBrowser
2008-02-23 22:45 --------- d-----w C:\Programmer\Google
2008-02-23 18:42 --------- d-----w C:\Programmer\Fælles filer\Adobe
2008-02-23 09:52 --------- d-----w C:\Documents and Settings\Jørgen.CHIEFTEC\Application Data\LimeWire
2008-02-22 22:57 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
2008-02-17 00:52 --------- d-----w C:\Programmer\CodeStuff
2008-02-02 22:03 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2008-02-02 22:02 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-02-02 22:02 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2008-02-02 22:02 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-02-02 21:58 --------- d-----w C:\Programmer\Lavasoft
2008-02-02 21:53 --------- d-----w C:\Documents and Settings\Jørgen.CHIEFTEC\Application Data\Lavasoft
2008-01-29 21:46 --------- d-----w C:\Programmer\OpenOffice.org 2.0
2008-01-29 21:41 --------- d-----w C:\Programmer\OpenOffice.org 2.3
2008-01-28 20:30 --------- d-----w C:\Programmer\EXIF Date Changer
2008-01-25 13:57 --------- d--h--w C:\Programmer\InstallShield Installation Information
2008-01-09 14:01 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
2004-10-08 17:23 138,568 ----a-w C:\Documents and Settings\Jørgen\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-26 17:53 15360]
"AntiSpyware"="C:\Programmer\AntiSpywareApp\Antispyware.exe" [2008-03-10 20:04 19510520]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 15:58 1744896]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe" -osboot
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\wincmd\\WINCMD32.EXE"=
"C:\\Programmer\\Messenger\\msmsgs.exe"=
"C:\\Programmer\\ICUII5\\icuii5.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\system32\\rundll32.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Programmer\\MSN Messenger\\msnmsgr.exe"=
"C:\\Programmer\\Internet Explorer\\iexplore.exe"=
"C:\\WINDOWS\\explorer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmer\\Fælles filer\\McAfee\\MNA\\McNASvc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"86:TCP"= 86:TCP:BroadCam Web Server
R0 antispyware;antispyware;C:\WINDOWS\system32\DRIVERS\antispyware.sys [2008-02-29 17:14]
R1 SSHDRV65;SSHDRV65;C:\WINDOWS\system32\drivers\SSHDRV65.sys [2005-02-21 17:08]
R2 Fix-It Task Manager;Fix-It Task Manager;C:\PROGRA~1\Ontrack\Fix-It\mxtask.exe [2001-07-31 11:25]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ee49098b-2c5d-11db-a739-00112fe885b5}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
*Newly Created Service* - CATCHME
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9E4C88F5-F8EB-45C5-A0B3-08BC50AB9B1E}]
C:\WINDOWS\system32\msiexec.exe /fup {9E4C88F5-F8EB-45C5-A0B3-08BC50AB9B1E} /q
.
Contents of the 'Scheduled Tasks' folder
"2008-03-21 16:15:01 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Programmer\TuneUp Utilities 2006\SystemOptimizer.exe
"2008-03-24 23:00:11 C:\WINDOWS\Tasks\Antispyware Scheduled Scan.job"
- C:\Programmer\AntiSpywareApp\AntiSpyware.ex
- C:\Programmer\AntiSpywareApp.JørgenWRuns Antispyware to scan your computer for malicious and potenially unwanted programs.
"2008-03-11 21:17:18 C:\WINDOWS\Tasks\ErrorSmart Scheduled Scan.job"
- C:\Programmer\ErrorSmart\ErrorSmart.ex
- C:\Programmer\ErrorSmart.Jørgen+Runs ErrorSmart to optimize your registry.
"2008-03-21 23:33:32 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\programmer\mcafee\mqc\QcConsol.exe'
"2008-03-21 23:33:30 C:\WINDOWS\Tasks\McQcTask.job"
- c:\programmer\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-25 00:06:48
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
disk error: C:\WINDOWS\
**************************************************************************
.
Completion time: 2008-03-25 0:08:38
ComboFix-quarantined-files.txt 2008-03-24 23:07:44
.
2008-03-12 23:58:16 --- E O F ---