LOG fra comboFix
ComboFix 09-09-08.01 - Administrator 08-09-2009 6:17.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1030.18.2047.1439 [GMT 2:00]
Kører fra: c:\documents and settings\Administrator\Dokumenter\Hentede filer\combo fic\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\Administrator\Dokumenter\Hentede filer\combo fic\CFScript.txt
AV: Kaspersky Internet Security *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.
((((((((((((((((((((((((((((( Filer skabt fra 2009-08-08 til 2009-09-08 )))))))))))))))))))))))))))))))))))
.
2009-09-08 04:04 . 2009-09-08 04:04 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-09-08 04:04 . 2009-08-03 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-08 04:04 . 2009-09-08 04:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-08 04:04 . 2009-09-08 04:04 -------- d-----w- c:\programmer\Malwarebytes' Anti-Malware
2009-09-08 04:04 . 2009-08-03 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-08 04:01 . 2009-09-08 04:02 -------- d-----w- c:\programmer\CCleaner
2009-09-08 03:10 . 2009-09-08 03:10 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-08 04:15 . 2004-01-01 00:09 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-24 13:05 . 2004-01-01 00:37 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-08-19 10:01 . 2004-01-01 00:37 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-08-14 05:58 . 2004-01-01 00:37 7396 ----a-w- c:\windows\system32\drivers\pctcore.cat
2009-07-03 14:48 . 2009-07-03 14:48 219664 ----a-w- c:\windows\system32\klogon.dll
2009-07-03 14:45 . 2009-07-03 14:45 27507 ----a-w- c:\windows\system32\drivers\klopp.dat
2009-06-15 13:01 . 2009-06-15 13:01 128016 ----a-w- c:\windows\system32\drivers\kl1.sys
.
------- Sigcheck -------
- 2009-02-17 . C75303C811202D68AA2DE5694374E449 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Administrator\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe" [2004-01-03 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-09 7561216]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-03-09 86016]
"avp"="c:\programmer\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-07-03 303376]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-03-09 1519616]
"C-Media Mixer"="Mixer.exe" - c:\windows\mixer.exe [2003-03-20 1855488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2008-04-15 101376]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [15-12-2008 21:41 33808]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [01-01-2004 02:37 206256]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [13-05-2009 18:46 31760]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [16-05-2009 21:59 19472]
S3 sdAuxService;PC Tools Auxiliary Service;c:\programmer\Spyware Doctor\pctsAuxs.exe [01-01-2004 02:36 348752]
--- Andre Services/Drivers i Hukommelsen ---
*NewlyCreated* - KLBG
.
Indhold af mappen 'Planlagte Opgaver'
2004-01-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-527237240-1958367476-1417001333-500Core.job
- c:\documents and settings\Administrator\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe [2004-01-03 02:27]
2009-09-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-527237240-1958367476-1417001333-500UA.job
- c:\documents and settings\Administrator\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe [2004-01-03 02:27]
.
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.com/uInternet Connection Wizard,ShellNext =
hxxp://www.google.com/FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\qlm8awy5.default\
FF - component: c:\programmer\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - plugin: c:\documents and settings\Administrator\Lokale indstillinger\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
---- FIREFOX POLITIKKER ----
c:\programmer\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-08 06:20
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Andre kørende processer ------------------------
.
c:\windows\system32\rundll32.exe
c:\documents and settings\Administrator\Lokale indstillinger\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\wmiadap.exe
.
**************************************************************************
.
Gennemført tid: 2009-09-08 6:21 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2009-09-08 04:21
Pre-Kørsel: 21.966.630.912 byte ledig
Post-Kørsel: 21.915.049.984 byte ledig
133