Hej
Jeg har snydt og kørt combofix. Her er log-filen
ComboFix 09-03-06.02 - Leif 2009-03-10 21:40:06.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1030.18.502.291 [GMT 1:00]
Kører fra: E:\mike.exe
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Protect\svhost.exe
c:\documents and settings\All Users\Application Data\Microsoft\Protect\track.sys
c:\documents and settings\All Users\Application Data\svhost.exe
c:\documents and settings\Birgitte\Application Data\urlredir.cfg
c:\documents and settings\Elisabeth\Application Data\Microsoft\Internet Explorer\Quick Launch\PCPrivacyCleaner.lnk
c:\documents and settings\Elisabeth\Application Data\urlredir.cfg
c:\documents and settings\Elisabeth\Skrivebord\PCPrivacyCleaner.lnk
c:\documents and settings\Leif\Application Data\Microsoft\Internet Explorer\Quick Launch\PCPrivacyCleaner.lnk
c:\documents and settings\Leif\Application Data\urlredir.cfg
c:\documents and settings\Leif\ResErrors.log
c:\documents and settings\Xenia\Application Data\urlredir.cfg
c:\programmer\Mozilla Firefox\components\hewiinbdsjnr.dll
c:\programmer\PCPrivacyCleaner
c:\programmer\Spyware Guard 2009
c:\programmer\Spyware Guard 2009\queue.vdb
c:\programmer\Spyware Guard 2009\spywareguard.exe
c:\programmer\Spyware Guard 2009\uninstall.exe
c:\windows\reged.exe
c:\windows\spoolsystem.exe
c:\windows\sys.com
c:\windows\syscert.exe
c:\windows\sysexplorer.exe
c:\windows\system32\adssite-remove.exe
c:\windows\system32\drivers\TDSSpqlt.sys
c:\windows\system32\hewiinbdsjnr.dll
c:\windows\system32\mysidesearch_sidebar_uninstall.exe
c:\windows\system32\myss_sb_uninstall.exe
c:\windows\system32\TDSSbrsr.dll
c:\windows\system32\TDSSlxwp.dll
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSoiqh.dll
c:\windows\system32\TDSSosvd.dat
c:\windows\system32\TDSSrhym.log
c:\windows\system32\TDSSriqp.dll
c:\windows\system32\TDSSsihc.dll
c:\windows\system32\TDSStkdu.log
c:\windows\system32\TDSSxfum.dll
c:\windows\system32\winscenter.exe
c:\windows\vmreg.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Tjenester )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_TDSSserv.sys
-------\Legacy_TDSSserv.sys
-------\Legacy_DHLP
((((((((((((((((((((((((((((( Filer skabt fra 2009-02-10 til 2009-03-10 )))))))))))))))))))))))))))))))))))
.
2009-03-10 12:39 . 2009-03-10 12:39 1,374 --a------ c:\windows\imsins.BAK
2009-03-07 17:54 . 2009-03-07 17:54 <DIR> d-------- c:\programmer\Ubisoft
2009-02-23 17:19 . 2004-09-17 15:24 <DIR> d-------- c:\documents and settings\Administrator\Skrivebord
2009-02-23 17:19 . 2004-09-17 15:24 <DIR> d--h----- c:\documents and settings\Administrator\Skabeloner
2009-02-23 17:19 . 2004-09-17 15:24 <DIR> d--h----- c:\documents and settings\Administrator\Printere
2009-02-23 17:19 . 2004-09-17 15:24 <DIR> dr------- c:\documents and settings\Administrator\Menuen Start
2009-02-23 17:19 . 2004-09-17 15:24 <DIR> d--h----- c:\documents and settings\Administrator\Lokale indstillinger
2009-02-23 17:19 . 2004-09-17 15:36 <DIR> dr------- c:\documents and settings\Administrator\Foretrukne
2009-02-23 17:19 . 2006-04-19 03:43 <DIR> dr------- c:\documents and settings\Administrator\Dokumenter
2009-02-23 17:19 . 2006-04-19 03:38 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Intel
2009-02-23 17:19 . 2006-04-19 03:44 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Corel
2009-02-23 17:19 . 2004-09-17 15:24 <DIR> d--h----- c:\documents and settings\Administrator\Andre computere
2009-02-23 17:19 . 2009-03-10 17:26 <DIR> d-------- c:\documents and settings\Administrator
2009-02-23 16:19 . 2009-02-23 16:19 <DIR> d-------- c:\documents and settings\Elisabeth\Tracing
2009-02-19 18:51 . 2009-02-19 18:51 <DIR> d-------- c:\programmer\EA GAMES
2009-02-19 18:51 . 2005-02-26 06:34 442,368 -ra------ c:\windows\system32\vp6vfw.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-10 18:44 --------- d-----w c:\programmer\Fælles filer\PC Tools
2009-03-10 18:42 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-10 16:27 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-03-10 11:06 --------- d-----w c:\programmer\Microsoft ActiveSync
2009-03-10 10:29 --------- d-----w c:\documents and settings\Birgitte\Application Data\OpenOffice.org2
2009-03-07 16:54 --------- d--h--w c:\programmer\InstallShield Installation Information
2009-02-19 17:44 --------- d-----w c:\programmer\Lx_cats
2009-01-22 09:54 --------- d-----w c:\programmer\AVG
2009-01-18 18:44 --------- d-----w c:\programmer\Fighters
2009-01-13 08:30 --------- d-----w c:\programmer\CCleaner
2009-01-11 18:17 --------- d-----w c:\documents and settings\Birgitte\Application Data\Sonic
2009-01-11 18:16 --------- d-----w c:\documents and settings\Birgitte\Application Data\Leadertech
2009-01-11 15:56 36,624 ------w c:\windows\system32\drivers\pxhelp20.sys
2009-01-11 15:01 --------- d-----w c:\programmer\Mixware
2009-01-11 15:01 --------- d-----w c:\documents and settings\Birgitte\Application Data\Mixware
2006-10-11 08:04 61,036 ----a-w c:\programmer\mozilla firefox\components\jar50.dll
2006-10-11 08:04 48,742 ----a-w c:\programmer\mozilla firefox\components\jsd3250.dll
2006-10-11 08:05 29,313 ----a-w c:\programmer\mozilla firefox\components\myspell.dll
2006-10-11 08:05 41,082 ----a-w c:\programmer\mozilla firefox\components\spellchk.dll
2006-10-11 08:04 166,510 ----a-w c:\programmer\mozilla firefox\components\xpinstal.dll
2007-03-17 09:16 56 --sh--r c:\windows\system32\26D8A9D931.sys
2007-03-10 11:35 88 --sh--r c:\windows\system32\31D9A9D826.sys
2007-03-17 09:16 6,580 --sha-w c:\windows\system32\KGyGaAvL.sys
2008-10-01 15:33 32,768 --sha-w c:\windows\system32\config\systemprofile\Lokale indstillinger\Oversigt\History.IE5\MSHist012008100120081002\index.dat
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"ModemOnHold"="c:\programmer\NetWaiting\netwaiting.exe" [2003-09-10 20480]
"swg"="c:\programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-18 68856]
"H/PC Connection Agent"="c:\programmer\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"msnmsgr"="c:\programmer\Windows Live\Messenger\msnmsgr.exe" [2008-12-02 3882312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShowLOMControl"="1 (0x1)" [X]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"SunJavaUpdateSched"="c:\programmer\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Dell QuickSet"="c:\programmer\Dell\QuickSet\quickset.exe" [2005-12-06 839680]
"IntelZeroConfig"="c:\programmer\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
"IntelWireless"="c:\programmer\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
"DVDLauncher"="c:\programmer\r\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 49152]
"DMXLauncher"="c:\programmer\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 86016]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\programmer\Fælles filer\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\programmer\Fælles filer\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"LXCGCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-07-20 73728]
"lxcgmon.exe"="c:\programmer\Lexmark 2300 Series\lxcgmon.exe" [2005-07-21 200704]
"EzPrint"="c:\programmer\Lexmark 2300 Series\ezprint.exe" [2005-08-01 94208]
"FaxCenterServer"="c:\programmer\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 299008]
"MSKDetectorExe"="c:\programmer\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 1121792]
"QuickTime Task"="c:\programmer\QuickTime\qttask.exe" [2007-04-27 282624]
"HP Software Update"="c:\programmer\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"TkBellExe"="c:\programmer\Fælles filer\Real\Update_OB\realsched.exe" [2008-04-27 185896]
"hpqSRMon"="c:\programmer\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"SigmatelSysTrayApp"="stsystra.exe" [2005-11-16 c:\windows\stsystra.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 c:\windows\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Picasa Media Detector"="c:\programmer\Picasa2\PicasaMediaDetector.exe" [2007-10-23 443968]
c:\documents and settings\Birgitte\Menuen Start\Programmer\Start\
OpenOffice.org 2.4.lnk - c:\programmer\OpenOffice.org 2.4\program\quickstart.exe [2008-05-30 393216]
c:\documents and settings\All Users\Menuen Start\Programmer\Start\
Adobe Reader Speed Launch.lnk - c:\programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
Bluetooth Manager.lnk - c:\programmer\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2004-12-24 479232]
Digital Line Detect.lnk - c:\programmer\Digital Line Detect\DLG.exe [2006-04-19 24576]
HP Digital Imaging Monitor.lnk - c:\programmer\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\lxcgcoms.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxcgpswx.exe"=
"c:\programmer\Microsoft ActiveSync\rapimgr.exe"= c:\programmer\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\programmer\Microsoft ActiveSync\wcescomm.exe"= c:\programmer\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\programmer\Microsoft ActiveSync\WCESMgr.exe"= c:\programmer\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Programmer\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
S3 getPlus(R) Helper;getPlus(R) Helper;c:\programmer\NOS\bin\getPlus_HelperSvc.exe [2008-11-15 33752]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Indhold af mappen 'Planlagte Opgaver'
2009-03-06 c:\windows\Tasks\McAfee.com Scan for virus - Denne computer (blærbar-Birgitte).job
- c:\programmer\mcafee.com\vso\mcmnhdlr.exe []
.
- - - - TOMME GENVEJE FJERNET - - - -
BHO-{1648E328-3E5A-4EA5-A9C6-E5F09EE272DA} - (no file)
BHO-{1D8282E6-BC4F-469B-AAED-7E4FF077AD93} - (no file)
BHO-{3A89AF00-0D68-4B83-B37D-2A41C340F3BB} - (no file)
BHO-{9C8A568E-4201-478a-8536-526CF371D2E2} - (no file)
BHO-{BF5E7C05-4CAE-061B-E473-684405D0D041} - c:\windows\system32\hewiinbdsjnr.dll
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.dk/uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8uInternet Connection Wizard,ShellNext =
hxxp://www1.euro.dell.com/content/default.aspx?c=dk&l=da&s=genuSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
DPF: {9C196458-4145-46AF-8A77-1506878DFECA} -
ftp://ftp.sektornet.dk/sektornet/skolekom/fcplugin.cabDPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} -
hxxps://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exeDPF: {D8575CE3-3432-4540-88A9-85A1325D3375} -
hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cabFF - ProfilePath -
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-10 21:47:16
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCGCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
------------------------ Andre kørende processer ------------------------
.
c:\programmer\Intel\Wireless\Bin\EvtEng.exe
c:\programmer\Intel\Wireless\Bin\S24EvMon.exe
c:\programmer\Intel\Wireless\Bin\WLKEEPER.exe
c:\programmer\Dell\NicConfigSvc\NicConfigSvc.exe
c:\programmer\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\lxcgcoms.exe
c:\progra~1\MICROS~4\rapimgr.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\programmer\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\programmer\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
.
**************************************************************************
.
Gennemført tid: 2009-03-10 21:51:27 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2009-03-10 20:51:23
Pre-Kørsel: 24,492,531,712 byte ledig
Post-Kørsel: 24,466,968,576 byte ledig
WindowsXP-KB310994-SP2-Home-BootDisk-DAN.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
249 --- E O F --- 2009-03-10 11:45:13