ComboFix 10-12-19.03 - ove 20-12-2010 18:31:16.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.45.1030.18.702.483 [GMT 1:00]
Kører fra: c:\documents and settings\ove\Skrivebord\Ny mappe\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\ove\Skrivebord\Ny mappe\CFScript.txt
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\8dce9c
c:\documents and settings\All Users\Application Data\8dce9c\567.mof
c:\documents and settings\All Users\Application Data\8dce9c\MSS.ico
c:\documents and settings\All Users\Application Data\8dce9c\MSSSys\vd952342.bd
.
((((((((((((((((((((((((((((( Filer skabt fra 2010-11-20 til 2010-12-20 )))))))))))))))))))))))))))))))))))
.
2010-12-20 15:54 . 2010-12-20 15:54 -------- d-----w- c:\documents and settings\ove\Application Data\AVG10
2010-12-20 15:39 . 2010-12-20 15:39 -------- d--h--w- c:\documents and settings\All Users\Application Data\Common Files
2010-12-20 15:36 . 2010-12-20 17:22 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG10
2010-12-20 15:33 . 2010-12-20 15:35 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
2010-12-20 12:19 . 2010-12-20 12:19 -------- d-----w- c:\documents and settings\pia\Application Data\SUPERAntiSpyware.com
2010-12-20 11:44 . 2010-12-20 11:44 -------- d-----w- c:\windows\system32\NtmsData
2010-12-20 08:23 . 2009-08-06 18:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-12-17 11:42 . 2010-11-02 15:17 40960 ------w- c:\windows\system32\dllcache\ndproxy.sys
2010-12-17 11:42 . 2010-10-11 14:59 45568 ------w- c:\windows\system32\dllcache\wab.exe
2010-12-17 10:53 . 2008-04-14 17:05 21504 ----a-w- c:\windows\system32\hidserv.dll
2010-12-17 10:53 . 2008-04-14 17:05 21504 ----a-w- c:\windows\system32\dllcache\hidserv.dll
2010-12-17 10:53 . 2008-04-14 16:42 14720 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2010-12-17 10:53 . 2008-04-14 16:42 14720 ----a-w- c:\windows\system32\dllcache\kbdhid.sys
2010-12-09 08:46 . 2010-12-09 08:46 -------- d-----w- c:\documents and settings\pia\Application Data\Malwarebytes
2010-12-02 14:34 . 2010-12-02 14:34 -------- d-----w- c:\documents and settings\ove\Lokale indstillinger\Application Data\HP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-29 16:42 . 2010-09-22 12:11 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-29 16:42 . 2010-09-22 12:11 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-18 18:15 . 2006-06-22 17:58 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-12 17:53 . 2010-06-02 19:20 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-12 15:34 . 2007-04-18 16:58 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-11-06 00:23 . 2005-12-07 08:01 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:23 . 2006-06-22 17:58 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:23 . 2006-06-22 17:58 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-11-05 22:44 . 2009-10-26 12:09 520192 ----a-w- c:\windows\system32\jule_saver_2009.scr
2010-11-03 12:25 . 2006-06-22 17:58 385024 ----a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2006-06-22 17:58 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:08 . 2006-06-22 17:55 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:58 . 2005-12-07 08:01 1853312 ----a-w- c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-30 68856]
"SUPERAntiSpyware"="c:\programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-12-17 2424560]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmer\SUPERAntiSpyware\SASSEH.DLL" [2008-05-21 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-05 09:27 548352 ----a-w- c:\programmer\SUPERAntiSpyware\SASWINLO.DLL
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Adobe Reader Hurtigstart.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\Adobe Reader Hurtigstart.lnk
backup=c:\windows\pss\Adobe Reader Hurtigstart.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 21:07 932288 ----a-r- c:\programmer\Fælles filer\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 02:47 35760 ----a-w- c:\programmer\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2009-11-18 14:13 54576 ----a-w- c:\programmer\Hewlett-Packard\HP Software Update\hpwuschd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 16:05 1695232 ----a-w- c:\programmer\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power2GoExpress]
2010-09-20 21:07 932288 ----a-r- c:\programmer\Fælles filer\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
2002-09-13 13:42 212992 ----a-w- c:\windows\SMINST\Recguard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2005-01-12 01:01 32768 ----a-w- c:\programmer\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2005-08-17 10:39 90112 ----a-r- c:\windows\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 09:44 248552 ----a-w- c:\programmer\Fælles filer\Java\Java Update\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-06-30 13:30 68856 ----a-w- c:\programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2010-06-24 14:41 247144 ----a-w- c:\programmer\TomTom HOME 2\TomTomHOMERunner.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
2005-03-07 19:33 53248 ----a-r- c:\windows\system32\VTTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTrayp]
2005-10-31 20:15 163840 ----a-r- c:\windows\system32\VTTrayp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WheelMouse]
2007-07-28 04:59 204800 ----a-w- c:\programmer\Mouse\Amoumain.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmer\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmer\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmer\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmer\\Hewlett-Packard\\Digital Imaging\\bin\\hpqcopy2.exe"=
"c:\\Programmer\\Hewlett-Packard\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Programmer\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Programmer\\Hewlett-Packard\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Programmer\\Hewlett-Packard\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Programmer\\Hewlett-Packard\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Programmer\\Hewlett-Packard\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Programmer\\Hewlett-Packard\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Programmer\\Hewlett-Packard\\HP Software Update\\hpwucli.exe"=
"c:\\Programmer\\Hewlett-Packard\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
R1 SASDIFSV;SASDIFSV;c:\programmer\SUPERAntiSpyware\SASDIFSV.SYS [10-10-2006 12:53 12872]
R1 SASKUTIL;SASKUTIL;c:\programmer\SUPERAntiSpyware\SASKUTIL.SYS [27-02-2007 11:39 67656]
R2 TomTomHOMEService;TomTomHOMEService;c:\programmer\TomTom HOME 2\TomTomHOMEService.exe [24-06-2010 15:41 92008]
S2 gupdate;Tjenesten Google Update (gupdate);c:\programmer\Google\Update\GoogleUpdate.exe [04-02-2010 10:33 135664]
S3 FXDRV;FXDRV;\??\d:\fxdrv.sys --> d:\Fxdrv.sys [?]
S3 SASENUM;SASENUM;c:\programmer\SUPERAntiSpyware\SASENUM.SYS [16-02-2006 16:51 12872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Indhold af mappen 'Planlagte Opgaver'
2010-12-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2010-02-04 09:33]
2010-12-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2010-02-04 09:33]
2010-12-20 c:\windows\Tasks\User_Feed_Synchronization-{1D083DFF-4251-44D4-A350-E2576F0D7EF7}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
2010-12-20 c:\windows\Tasks\User_Feed_Synchronization-{B023E0B2-875A-457E-8252-D916A36F4483}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.dk/uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8uSearchAssistant =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://www.google.com/search?q=%s.
- - - - TOMME GENVEJE FJERNET - - - -
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
Toolbar-Locked - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKCU-Run-AV8 - c:\programmer\AV8\av8.exe
MSConfigStartUp-AdobeUpdater - c:\programmer\Fælles filer\Adobe\Updater5\AdobeUpdater.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-12-20 18:42
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs startet under kørende Processer ---------------------
- - - - - - - > 'winlogon.exe'(504)
c:\programmer\SUPERAntiSpyware\SASWINLO.DLL
- - - - - - - > 'explorer.exe'(3004)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\windows\System32\SCardSvr.exe
c:\programmer\Java\jre6\bin\jqs.exe
c:\programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Gennemført tid: 2010-12-20 18:48:48 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2010-12-20 17:48
Pre-Kørsel: 53.283.663.872 byte ledig
Post-Kørsel: 55.692.038.144 byte ledig
- - End Of File - - 1D792A2F6169D48948B387664FEF433A