Hej det er ellers noget af en opgave, at lede en gammel amatør, som jeg ,igennem noget jeg slet ikke har forstand på
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1030.18.1595 [GMT 2:00]
Running from: F:\combofix\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Programmer\3
C:\Programmer\3\3Connect\_setup.dll
C:\Programmer\3\3Connect\AutoUpdateSrv.exe
C:\Programmer\3\3Connect\DataCard_Setup.exe
C:\Programmer\3\3Connect\Logger.dll
C:\Programmer\3\3Connect\Res.dll
C:\Programmer\3\3Connect\Setup.exe
C:\Programmer\3\3Connect\SmsApp2.dll
C:\Programmer\3\3Connect\WWanDevice.dll
C:\WINDOWS\system32\actskn43.ocx
.
((((((((((((((((((((((((( Files Created from 2008-08-15 to 2008-09-15 )))))))))))))))))))))))))))))))
.
2008-09-15 12:47 . 2008-09-15 12:47 <DIR> d-------- C:\Programmer\Huawei technologies
2008-09-15 12:46 . 2008-09-15 12:46 244 --ah----- C:\sqmnoopt14.sqm
2008-09-15 12:46 . 2008-09-15 12:46 232 --ah----- C:\sqmdata14.sqm
2008-09-15 11:20 . 2008-09-15 11:20 244 --ah----- C:\sqmnoopt13.sqm
2008-09-15 11:20 . 2008-09-15 11:20 232 --ah----- C:\sqmdata13.sqm
2008-09-14 22:47 . 2008-09-14 22:47 244 --ah----- C:\sqmnoopt12.sqm
2008-09-14 22:47 . 2008-09-14 22:47 232 --ah----- C:\sqmdata12.sqm
2008-09-14 19:33 . 2008-09-15 12:47 <DIR> d-------- C:\Programmer\Malwarebytes' Anti-Malware
2008-09-14 19:33 . 2008-09-14 19:33 <DIR> d-------- C:\Documents and Settings\per\Application Data\Malwarebytes
2008-09-14 19:33 . 2008-09-14 19:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-14 12:34 . 2008-09-14 12:34 244 --ah----- C:\sqmnoopt11.sqm
2008-09-14 12:34 . 2008-09-14 12:34 232 --ah----- C:\sqmdata11.sqm
2008-09-11 22:36 . 2008-09-11 22:36 244 --ah----- C:\sqmnoopt10.sqm
2008-09-11 22:36 . 2008-09-11 22:36 232 --ah----- C:\sqmdata10.sqm
2008-09-11 22:18 . 2008-09-11 22:18 244 --ah----- C:\sqmnoopt09.sqm
2008-09-11 22:18 . 2008-09-11 22:18 232 --ah----- C:\sqmdata09.sqm
2008-09-11 22:03 . 2008-09-11 22:03 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-09-11 20:43 . 2008-09-11 20:43 244 --ah----- C:\sqmnoopt08.sqm
2008-09-11 20:43 . 2008-09-11 20:43 232 --ah----- C:\sqmdata08.sqm
2008-09-11 19:32 . 2008-09-11 19:32 244 --ah----- C:\sqmnoopt07.sqm
2008-09-11 19:32 . 2008-09-11 19:32 232 --ah----- C:\sqmdata07.sqm
2008-09-11 17:11 . 2008-09-11 17:11 244 --ah----- C:\sqmnoopt06.sqm
2008-09-11 17:11 . 2008-09-11 17:11 232 --ah----- C:\sqmdata06.sqm
2008-09-11 16:10 . 2008-09-11 16:10 244 --ah----- C:\sqmnoopt05.sqm
2008-09-11 16:10 . 2008-09-11 16:10 232 --ah----- C:\sqmdata05.sqm
2008-09-11 15:47 . 2004-10-22 02:16 5,632 --a------ C:\DotNetInstaller.exe
2008-09-11 15:24 . 2008-09-11 15:24 <DIR> d-------- C:\Programmer\CCleaner
2008-09-11 15:14 . 2008-09-11 15:14 <DIR> d--h----- C:\WINDOWS\system32\CanonIJ Uninstaller Information
2008-09-11 15:14 . 2008-09-11 15:14 <DIR> d-------- C:\Programmer\Wisdom-soft
2008-09-11 15:14 . 2008-09-11 15:14 <DIR> d-------- C:\Programmer\Fælles filer\ScanSoft Shared
2008-09-11 15:14 . 2008-09-11 15:14 <DIR> d-------- C:\oces
2008-09-11 15:14 . 2008-09-11 15:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\InstallShield
2008-09-11 15:14 . 2008-09-11 15:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-09-11 15:14 . 2008-09-11 15:14 <DIR> d-------- C:\.oces
2008-09-11 14:40 . 2008-09-11 14:40 244 --ah----- C:\sqmnoopt04.sqm
2008-09-11 14:40 . 2008-09-11 14:40 232 --ah----- C:\sqmdata04.sqm
2008-09-11 12:33 . 2008-09-11 15:19 <DIR> d-------- C:\Documents and Settings\per\Application Data\Birdstep Technology(4)
2008-09-11 12:26 . 2008-09-11 12:26 244 --ah----- C:\sqmnoopt03.sqm
2008-09-11 12:26 . 2008-09-11 12:26 232 --ah----- C:\sqmdata03.sqm
2008-09-11 12:05 . 2008-09-11 19:07 <DIR> d-------- C:\Programmer\Yahoo!
2008-09-11 11:16 . 2008-09-11 11:16 244 --ah----- C:\sqmnoopt02.sqm
2008-09-11 11:16 . 2008-09-11 11:16 232 --ah----- C:\sqmdata02.sqm
2008-09-11 10:47 . 2008-09-11 10:47 244 --ah----- C:\sqmnoopt01.sqm
2008-09-11 10:47 . 2008-09-11 10:47 232 --ah----- C:\sqmdata01.sqm
2008-09-11 10:35 . 2008-09-11 15:20 <DIR> d-------- C:\Documents and Settings\per\Application Data\Birdstep Technology
2008-09-11 09:29 . 2008-09-11 15:20 <DIR> d-------- C:\Documents and Settings\per\Application Data\Birdstep Technology(2)
2008-09-10 22:11 . 2008-09-11 15:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-06 23:07 . 2008-09-06 23:07 <DIR> d-------- C:\Programmer\Driver-Soft
2008-09-06 22:54 . 2008-09-06 22:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-09-01 09:39 . 2008-09-01 09:39 <DIR> d-------- C:\WINDOWS\l2schemas
2008-09-01 09:37 . 2008-09-01 09:37 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-08-19 16:52 . 2004-07-17 11:35 67,866 --------- C:\WINDOWS\system32\drivers\netwlan5.img
2008-08-19 16:51 . 2004-07-17 11:36 64,352 --------- C:\WINDOWS\system32\drivers\ativmc20.cod
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-14 08:51 --------- d-----w C:\Programmer\Windows Media Connect 2
2008-09-12 07:44 --------- d-----w C:\Programmer\TeamViewer3
2008-09-11 15:28 --------- d--h--w C:\Programmer\InstallShield Installation Information
2008-09-11 13:20 --------- d-----w C:\Documents and Settings\per\Application Data\NCH Swift Sound
2008-09-11 13:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\NCH Software
2008-09-11 13:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Birdstep Technology
2008-09-11 13:18 --------- d-----w C:\Programmer\Microsoft Silverlight
2008-09-11 13:16 --------- d-----w C:\Documents and Settings\per\Application Data\NCH Software
2008-09-11 13:14 --------- d-----w C:\Programmer\Canon
2008-09-11 13:14 --------- d-----w C:\Programmer\Apple Software Update
2008-09-11 13:14 --------- d-----w C:\Documents and Settings\per\Application Data\ScanSoft
2008-09-11 13:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\ScanSoft
2008-09-11 13:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-09-11 13:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-29 10:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\CanonIJPLM
2008-08-06 17:44 --------- d-----w C:\Programmer\Nero
2008-08-06 15:11 --------- d-----w C:\Documents and Settings\per\Application Data\SolidDocuments
2008-08-06 15:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\SolidDocuments
2008-08-05 18:12 27,136 ----a-w C:\WINDOWS\system32\drivers\nchssvad.sys
2008-07-19 19:58 --------- d-----w C:\Documents and Settings\per\Application Data\Canon
2008-07-18 21:24 --------- d-----w C:\Documents and Settings\per\Application Data\CD-LabelPrint
2008-07-18 13:25 --------- d-----w C:\Programmer\Fælles filer\CANON
2008-07-18 13:22 --------- d--h--w C:\Documents and Settings\All Users\Application Data\CanonBJ
2008-07-18 13:21 --------- d--h--w C:\Programmer\CanonBJ
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es(5).dll
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es(4).dll
2008-06-24 16:24 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:24 74,240 ----a-w C:\WINDOWS\system32\mscms(4).dll
2008-06-24 16:24 74,240 ----a-w C:\WINDOWS\system32\mscms(3).dll
2008-06-24 16:12 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
2008-06-23 16:33 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:42 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:42 246,784 ----a-w C:\WINDOWS\system32\mswsock(3)(2).dll
2008-06-20 17:42 148,992 ----a-w C:\WINDOWS\system32\dnsapi(3)(2).dll
2008-03-30 17:55 22,938,616 ----a-w C:\Programmer\AdbeRdr812_da_DK.exe
2004-06-03 21:34 894,176 -c--a-w C:\Programmer\DVD_player.pdf
2004-06-03 21:22 323,070 -c--a-w C:\Programmer\DVDPlayer.chm
2004-05-20 09:22 335,872 ----a-w C:\Programmer\PlayerUI.dll
2004-04-20 14:07 946,176 ----a-w C:\Programmer\u32Prod.dll
2004-04-20 14:07 61,440 ----a-w C:\Programmer\u32Cfg.dll
2004-04-20 14:07 40,960 ----a-w C:\Programmer\UAboutbox.dll
2004-04-20 14:07 122,880 ----a-w C:\Programmer\u32Comm.dll
2004-04-20 14:07 1,273,856 ----a-w C:\Programmer\LangRes.dll
2004-04-20 14:06 860 ----a-w C:\Programmer\Dolby.gif
2004-04-20 14:06 57,344 ----a-w C:\Programmer\DvdPlayer.exe
2004-04-20 14:06 36,864 ----a-w C:\Programmer\VideoFrame.dll
2004-04-20 14:06 35,328 ----a-w C:\Programmer\DSETUP.dll
2004-04-20 14:06 24,878 ----a-w C:\Programmer\DvdPlayer.ico
2004-04-20 14:06 188,416 ----a-w C:\Programmer\CEVideo.ax
2004-04-20 14:06 172,032 ----a-w C:\Programmer\Player.dll
2004-04-20 14:06 147,456 ----a-w C:\Programmer\CEAudio.ax
2003-07-16 09:34 81,920 ----a-w C:\Programmer\CEParser.dll
2003-05-29 16:49 70,333 -c--a-r C:\Programmer\Readme.htm
2003-05-28 09:38 24,576 ----a-w C:\Programmer\u32sn.dll
2002-07-26 15:02 153,088 -c--a-w C:\Programmer\UNWISE.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 15360]
"MsnMsgr"="C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-31 68856]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programmer\Fælles filer\Ahead\lib\NMBgMonitor.exe" [2005-09-26 94208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.5.0\bin\jusched.exe" [2008-03-28 36972]
"USBToolTip"="C:\Programmer\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe" [2006-10-16 202312]
"ATIPTA"="C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-10-26 344064]
"PVR Agent"="D:\Programmer\TVR\Scheduled.exe" [2005-04-13 751104]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"LtMoh"="C:\Programmer\ltmoh\Ltmoh.exe" [2003-09-05 184320]
"SynTPLpr"="C:\Programmer\Synaptics\SynTP\SynTPLpr.exe" [2004-05-27 98304]
"SynTPEnh"="C:\Programmer\Synaptics\SynTP\SynTPEnh.exe" [2004-05-27 532480]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Adobe Photo Downloader"="C:\Programmer\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-09-14 61440]
"GUI"="C:\D-Link\AirPlusG+\AirPlus.exe" [2005-08-24 1474560]
"CanonSolutionMenu"="C:\Programmer\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="C:\Programmer\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"SSBkgdUpdate"="C:\Programmer\Fælles filer\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="D:\Programs\OpwareSE4.exe" [2007-02-04 79400]
"QuickTime Task"="D:\Programs\QTTask.exe" [2008-05-27 413696]
"avast!"="D:\Programs\ashDisp.exe" [2008-05-16 79224]
"SoundMan"="SOUNDMAN.EXE" [2004-07-27 C:\WINDOWS\SOUNDMAN.EXE]
"emMON"="emMON.exe" [2006-05-30 C:\WINDOWS\emMON.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2004-10-08 C:\WINDOWS\AGRSMMSG.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-27 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= Pvmjpg30.dll
"msacm.dvacm"= C:\PROGRA~1\FLLESF~1\ULEADS~1\Vio\Dvacm.acm
"msacm.divxa32"= msaud32_divx.acm
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmer\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programmer\\Pinnacle\\Studio 11\\programs\\RM.exe"=
"C:\\Programmer\\Pinnacle\\Studio 11\\programs\\Studio.exe"=
"C:\\Programmer\\Pinnacle\\Studio 11\\programs\\PMSRegisterFile.exe"=
"C:\\Programmer\\Pinnacle\\Studio 11\\programs\\umi.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"94:TCP"= 94:TCP:VRS Recording System Web Control Panel
"86:TCP"= 86:TCP:BroadCam Web Server
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 20560]
R2 IJPLMSVC;PIXMA Extended Survey Program;C:\Programmer\Canon\IJPLM\IJPLMSVC.EXE [2007-04-13 101528]
R2 mdvrmng;Mobile IP Route Manager;C:\WINDOWS\system32\drivers\mdvrmng.sys [2007-05-28 10240]
R2 TeamViewer;TeamViewer 3;C:\Programmer\TeamViewer3\TeamViewer_Host.exe [2008-03-12 181544]
R3 CONAN;CONAN;C:\WINDOWS\system32\drivers\o2mmb.sys [2004-10-04 191296]
R3 FUJ02E1;%FUJ02E1.DeviceDesc%;C:\WINDOWS\system32\Drivers\FUJ02E1.sys [2004-10-18 5632]
S2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;D:\PhotoshopElementsFileAgent.exe [ ]
S3 MbxStby;MbxStby;C:\WINDOWS\system32\drivers\MbxStby.sys [2004-03-10 5760]
S3 TNET1130;D-Link AirPlus G+ Wireless Adapter;C:\WINDOWS\system32\DRIVERS\GPLUS_XP.sys [2004-10-25 439296]
S3 TTUSB2TS;TTUSB2TS USB 2.0 Driver;C:\WINDOWS\system32\Drivers\ttusb2ts.sys [2006-04-04 92544]
S3 USB28xxBGA;USB 2820 Device;C:\WINDOWS\system32\DRIVERS\emBDA.sys [2006-09-12 292864]
S3 USB28xxOEM;USB 28xx OEM Filter;C:\WINDOWS\system32\DRIVERS\emOEM.sys [2006-08-22 7168]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{21487156-0018-11dd-abb5-000f3d58c8d1}]
\Shell\AutoRun\command - F:\setupSNK.exe
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-LaunchList - C:\Programmer\Pinnacle\Studio 10\LaunchList.exe
HKLM-Run-NWEReboot - (no file)
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page =
hxxp://www.ni.dk/O16 -: {07D09E9E-C667-45DD-B035-217BC2A61A3B} -
hxxps://www.portalbank.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.20.cabC:\WINDOWS\Downloaded Program Files\comp.inf
C:\WINDOWS\Downloaded Program Files\EBJSecurity_3.dll
C:\WINDOWS\Downloaded Program Files\ActiveXSikkerhedssoftware.ocx
O16 -: {D8575CE3-3432-4540-88A9-85A1325D3375} -
hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cabC:\WINDOWS\Downloaded Program Files\e-Safekey.inf
C:\WINDOWS\Downloaded Program Files\e-Safekey.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-15 19:17:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-15 19:18:44
ComboFix-quarantined-files.txt 2008-09-15 17:18:40
Pre-Run: 39,433,580,544 byte ledig
Post-Run: 39,416,135,680 byte ledig
237 --- E O F --- 2008-09-15 10:52:50
Jeg kan ikke se drev D nogen steder???????????????