uha den komplette scanning med sas tog lang tid på denne gamle maskine.
Her log fra Compofix. Spændt på hvor meget skidt der er på den ?
ComboFix 10-03-02.02 - Randi Juul 03-03-2010 0:52.4.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.45.1030.18.190.92 [GMT 1:00]
Kører fra: c:\documents and settings\Randi Juul\Skrivebord\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: Norton AntiVirus *On-access scanning disabled* (Outdated) {B5510F6F-87E1-47F7-A411-360BC453007C}
.
((((((((((((((((((((((((((((( Filer skabt fra 2010-02-02 til 2010-03-02 )))))))))))))))))))))))))))))))))))
.
2010-03-02 22:16 . 2010-03-02 22:16 -------- d-----w- c:\programmer\Trend Micro
2010-03-02 22:00 . 2010-03-02 22:00 52224 ----a-w- c:\documents and settings\Randi Juul\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-03-02 22:00 . 2010-03-02 22:00 117760 ----a-w- c:\documents and settings\Randi Juul\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-03-02 21:59 . 2010-03-02 21:59 -------- d-----w- c:\programmer\SUPERAntiSpyware
2010-02-27 20:38 . 2010-02-27 20:38 -------- d-----w- c:\documents and settings\Randi Juul\Tracing
2010-02-27 14:07 . 2010-02-27 14:07 -------- d-----w- c:\programmer\Microsoft
2010-02-27 14:05 . 2010-02-27 14:05 -------- d-----w- c:\programmer\Windows Live SkyDrive
2010-02-27 14:04 . 2010-02-27 14:04 -------- d-----w- c:\programmer\Windows Live
2010-02-27 13:54 . 2010-02-27 13:54 -------- d-----w- c:\programmer\Fælles filer\Windows Live
2010-02-12 12:48 . 2010-02-12 12:48 -------- d-----w- c:\documents and settings\Randi Juul\Application Data\Auslogics
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-02 21:32 . 2004-10-28 20:14 43520 ----a-w- c:\documents and settings\Randi Juul\Lokale indstillinger\Application Data\GDIPFONTCACHEV1.DAT
2010-01-11 16:40 . 2010-01-11 16:40 -------- d-----w- c:\documents and settings\Randi Juul\Application Data\Symantec
2010-01-11 16:40 . 2010-01-11 16:40 -------- d-----w- c:\documents and settings\Randi Juul\Application Data\SUPERAntiSpyware.com
2010-01-11 16:40 . 2010-01-11 16:40 -------- d-----w- c:\documents and settings\Randi Juul\Application Data\Malwarebytes
2010-01-07 17:52 . 2010-01-07 16:18 20 ----a-w- c:\windows\popcinfot.dat
2010-01-07 16:17 . 2010-01-07 16:17 -------- d-----w- c:\documents and settings\All Users\Application Data\PopCap Games
2009-12-25 15:37 . 2009-12-25 15:37 0 ----a-w- c:\windows\nsreg.dat
2006-08-25 13:36 . 2006-08-25 13:36 32 --sha-w- c:\windows\{A1FF46D2-5D6E-4A55-B17C-F70F47B0C989}.dat
2006-08-25 13:36 . 2006-08-25 13:36 32 --sha-w- c:\windows\{2BC60108-5EFC-4078-B56B-095CD595BF7B}.dat
2004-07-13 20:40 . 2004-07-13 20:40 32 --sha-w- c:\windows\{EC76C762-F5AD-4B24-8B98-D41242189205}.dat
2006-08-25 13:36 . 2006-08-25 13:36 32 --sha-w- c:\windows\{619F0380-A42E-4E72-8866-0471B608CFF5}.dat
2006-08-26 21:28 . 2006-08-26 21:28 32 --sha-w- c:\windows\{6CB9D832-B9E1-4EA3-A832-76BE44B0BAC7}.dat
2006-08-26 21:29 . 2006-08-26 21:29 32 --sha-w- c:\windows\{9ECBD495-98BB-4678-8B14-764E0680245F}.dat
2006-08-26 21:30 . 2006-08-26 21:30 32 --sha-w- c:\windows\{42D4DC8C-00F4-42E9-9801-33DE05B2E747}.dat
2009-07-13 08:35 . 2009-07-13 08:35 23 --sha-w- c:\windows\system32\edacded0.dat
2006-08-25 13:36 . 2006-08-25 13:36 32 --sha-w- c:\windows\system32\{6874A427-2DAD-45C5-925C-D6E6EFB9D37A}.dat
2006-08-25 13:36 . 2006-08-25 13:36 32 --sha-w- c:\windows\system32\{9A7B3AB4-752C-4532-A7E9-4CF680030449}.dat
2006-08-25 13:36 . 2006-08-25 13:36 32 --sha-w- c:\windows\system32\{6DB52566-BCAC-4E43-9C61-8D23923612CB}.dat
2006-08-26 21:28 . 2006-08-26 21:28 32 --sha-w- c:\windows\system32\{D838C278-5970-4FAF-8C8C-8484B2A7EAC2}.dat
2006-08-26 21:29 . 2006-08-26 21:29 32 --sha-w- c:\windows\system32\{64007669-C962-44C3-9945-774000B14BFA}.dat
2006-08-26 21:30 . 2006-08-26 21:30 32 --sha-w- c:\windows\system32\{CF020891-DD76-4A18-B77C-2E550B345C17}.dat
2007-05-17 20:02 . 2007-05-17 20:02 5 --sha-w- c:\windows\system32\acedfd4_g.dll
2004-07-13 20:40 . 2004-07-13 20:40 32 --sha-w- c:\windows\system32\{2CE3002D-F3C7-425A-89FD-F05C62FC7C97}.dat
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TrueImageMonitor.exe"="c:\programmer\Acronis\TrueImageHome\TrueImageMonitor.exe" [2006-06-30 1106386]
"AcronisTimounterMonitor"="c:\programmer\Acronis\TrueImageHome\TimounterMonitor.exe" [2006-06-29 1848150]
"Acronis Scheduler2 Service"="c:\programmer\Fælles filer\Acronis\Schedule2\schedhlp.exe" [2006-06-29 126976]
"ISUSScheduler"="c:\programmer\Fælles filer\InstallShield\UpdateService\issch.exe" [2004-08-09 81920]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-27 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
[BU]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0stera
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LaunchApp]
Alaunch [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
2003-04-01 03:54 88267 ----a-w- c:\windows\AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
VTTimer.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
S3 rtl8180;Realtek RTL8180 Wireless LAN (Mini-)PCI NIC NT Driver;c:\windows\system32\drivers\RTL8180.sys [02-09-2003 17:19 173184]
S3 RTLWUSB;11g Wireless USB Adapter;c:\windows\system32\DRIVERS\RTL8187.sys --> c:\windows\system32\DRIVERS\RTL8187.sys [?]
S3 SjyPkt;SjyPkt;\??\c:\windows\System32\Drivers\SjyPkt.sys --> c:\windows\System32\Drivers\SjyPkt.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{42C5E519-D47F-4105-9CEC-29CC51DD953F}]
2005-03-21 14:00 78848 ----a-w- c:\windows\system32\msiexec.exe
.
.
------- Yderligere scanning -------
.
uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8uStart Page =
hxxp://www.google.dk/ig?hl=da&source=iglkuInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-03-03 00:56
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
[HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\MessengerService]
@DACL=(02 0000)
[HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows]
@DACL=(02 0000)
[HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs]
@DACL=(02 0000)
[HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU]
@DACL=(02 0000)
[HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Run]
@DACL=(02 0000)
[HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows NT]
@DACL=(02 0000)
[HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows NT\CurrentVersion\Network\Persistent Connections]
@DACL=(02 0000)
DUMPHIVE0.003 (REGF)
.
--------------------- DLLs startet under kørende Processer ---------------------
- - - - - - - > 'lsass.exe'(768)
c:\windows\system32\relog_ap.dll
- - - - - - - > 'explorer.exe'(2508)
c:\windows\system32\msi.dll
.
Gennemført tid: 2010-03-03 00:57:40
ComboFix-quarantined-files.txt 2010-03-02 23:57
Pre-Kørsel: 6.286.467.072 byte ledig
Post-Kørsel: 6.256.197.632 byte ledig
- - End Of File - - C0A97E97D55E93C3C7630B852F565156