Gå til innhold

Noen som kan se på loggene mine?


Anbefalte innlegg

Min bærbare pc har for tiden "oppført" seg tregt, særlig etter å ha vært påslått en stund. Hadde derfor vert fint om noen kunne se over mbam, HJT- og combofix loggene.

 

Malwarebytes' Anti-Malware 1.30

Database versjon: 1441

Windows 5.1.2600 Service Pack 3

 

2008-12-01 20:52:55

mbam-log-2008-12-01 (20-52-55).txt

 

Skanntype: Rask Skann

Objekter skannet: 54367

Tid tilbakelagt: 12 minute(s), 16 second(s)

 

Minneprosesser infisert: 0

Minnemoduler infisert: 0

Registernøkler infisert: 0

Registerverdier infisert: 0

Registerfiler infisert: 0

Mapper infisert: 0

Filer infisert: 0

 

Minneprosesser infisert:

(Ingen mistenkelige filer funnet)

 

Minnemoduler infisert:

(Ingen mistenkelige filer funnet)

 

Registernøkler infisert:

(Ingen mistenkelige filer funnet)

 

Registerverdier infisert:

(Ingen mistenkelige filer funnet)

 

Registerfiler infisert:

(Ingen mistenkelige filer funnet)

 

Mapper infisert:

(Ingen mistenkelige filer funnet)

 

Filer infisert:

(Ingen mistenkelige filer funnet)

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 21:34, on 2008-12-01

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.20815)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Progs\Norman\Npm\bin\ELOGSVC.EXE

C:\Progs\Norman\Npm\Bin\Zanda.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\System32\SCardSvr.exe

C:\WINDOWS\system32\svchost.exe

C:\Progs\Java\jre6\bin\jqs.exe

C:\SYS.000\Evl.exe

C:\Progs\Common\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Progs\Dell\QuickSet\NICCONFIGSVC.exe

C:\Progs\Norman\Npm\bin\NJEEVES.EXE

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\Progs\Norman\Nvc\bin\nvcoas.exe

C:\Progs\Norman\Nvc\BIN\NVCSCHED.EXE

C:\WINDOWS\system32\igfxsrvc.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

C:\Progs\Norman\Npm\bin\ZLH.EXE

C:\Progs\SigmaTel\C-Major Audio\WDM\stsystra.exe

C:\Progs\Java\jre6\bin\jusched.exe

C:\WINDOWS\System32\DLA\DLACTRLW.EXE

C:\Progs\Norman\Nvc\BIN\NIP.EXE

C:\Progs\Common\InstallShield\UpdateService\issch.exe

C:\SYS.000\SW.exe

C:\SYS.000\hostsw.exe

C:\Progs\Microsoft IntelliType Pro\itype.exe

C:\Progs\Norman\Nvc\bin\cclaw.exe

C:\Progs\Microsoft IntelliPoint\ipoint.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Progs\Windows Live\Messenger\MsnMsgr.Exe

C:\Progs\Messenger\msmsgs.exe

C:\SYS.000\svpr.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\notepad.exe

C:\Progs\Mozilla Firefox\firefox.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Progs\Malwarebytes' Anti-Malware\mbam.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Progs\Trend Micro\HijackThis\HijackThis.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://itsl.ntvgs.no/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

O2 - BHO: Koblingshjelpeprogram for Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Progs\Common\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Progs\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Progs\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Progs\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [Norman ZANDA] "C:\Progs\Norman\Npm\bin\ZLH.EXE" /LOAD /SPLASH

O4 - HKLM\..\Run: [sigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Progs\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Progs\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE

O4 - HKLM\..\Run: [iSUSPM Startup] C:\Progs\Common\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Progs\Common\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [sSConfig] C:\SYS.000\SW.exe

O4 - HKLM\..\Run: [ProcMon] C:\SYS.000\hostsw.exe

O4 - HKLM\..\Run: [itype] "C:\Progs\Microsoft IntelliType Pro\itype.exe"

O4 - HKLM\..\Run: [intelliPoint] "C:\Progs\Microsoft IntelliPoint\ipoint.exe"

O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Progs\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [MSMSGS] "C:\Progs\Messenger\msmsgs.exe" /background

O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')

O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\Progs\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Progs\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Progs\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Progs\Messenger\msmsgs.exe

O16 - DPF: DirectEdit - https://www.itslearning.com//file/DirectEdit.CAB

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ntvgs.no

O17 - HKLM\Software\..\Telephony: DomainName = ntvgs.no

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ntvgs.no

O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:\Progs\Norman\Npm\bin\ELOGSVC.EXE

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Progs\Java\jre6\bin\jqs.exe

O23 - Service: Event Log Audit (MASEL) - CISL - C:\SYS.000\Evl.exe

O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Progs\Dell\QuickSet\NICCONFIGSVC.exe

O23 - Service: Norman NJeeves - Norman ASA - C:\Progs\Norman\Npm\bin\NJEEVES.EXE

O23 - Service: Norman ZANDA - Norman ASA - C:\Progs\Norman\Npm\Bin\Zanda.exe

O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Progs\Norman\Nvc\bin\nvcoas.exe

O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman ASA - C:\Progs\Norman\Nvc\BIN\NVCSCHED.EXE

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Progs\WinPcap\rpcapd.exe

 

--

End of file - 7044 bytes

 

ComboFix 08-11-30.02 - ?????????????? 2008-12-01 21:01:31.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1044.18.382 [GMT 1:00]

Kjører fra: c:\users\??????????????\Skrivebord\ComboFix.exe

* Resident AV is active

 

.

 

((((((((((((((((((((((((((((((((((((((( Andre slettinger )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\windows\system32\x64

 

.

((((((((((((((((((((((((((((((((((((((( Drivere/Tjenester )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Legacy_NSESVC

-------\Service_nsesvc

 

 

((((((((((((((((((((((((((( Filer Opprettet Fra 2008-11-01 til 2008-12-01 )))))))))))))))))))))))))))))))))

.

 

2008-12-01 20:57 . 2008-12-01 20:57 <DIR> d-------- c:\progs\Trend Micro

2008-12-01 20:37 . 2008-12-01 20:37 <DIR> d-------- c:\users\??????????????\Programdata\Malwarebytes

2008-12-01 20:37 . 2008-12-01 20:37 <DIR> d-------- c:\users\All Users\Programdata\Malwarebytes

2008-12-01 20:37 . 2008-12-01 20:37 <DIR> d-------- c:\progs\Malwarebytes' Anti-Malware

2008-12-01 20:37 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

2008-12-01 20:37 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys

2008-11-28 20:26 . 2005-01-22 20:12 679,936 --a------ c:\windows\system32\D3DX81ab.dll

2008-11-17 16:44 . 2008-11-17 16:44 <DIR> d-------- c:\progs\WinPcap

2008-11-17 16:44 . 2008-11-28 21:41 <DIR> d-------- c:\progs\WC3Banlist

2008-11-17 16:27 . 2008-11-17 16:38 139,264 --a------ c:\windows\War3Unin.exe

2008-11-17 16:27 . 2008-11-17 16:53 68,142 --a------ c:\windows\War3Unin.dat

2008-11-17 16:27 . 2008-11-17 16:38 2,829 --a------ c:\windows\War3Unin.pif

2008-11-17 16:23 . 2008-11-29 00:23 <DIR> d-------- c:\progs\Warcraft III

2008-11-16 03:01 . 2008-11-16 03:01 <DIR> d-------- c:\users\??????????????\Programdata\vlc

2008-11-16 03:00 . 2008-11-16 03:00 <DIR> d-------- c:\progs\VideoLAN

2008-11-15 21:54 . 2008-12-01 21:03 <DIR> dr-h----- c:\users\??????????????\Siste

2008-11-15 20:17 . 2008-11-15 20:17 <DIR> d-------- c:\progs\DAEMON Tools Lite

2008-11-15 20:11 . 2008-11-15 20:11 <DIR> d-------- c:\users\??????????????\Programdata\DAEMON Tools

2008-11-15 20:11 . 2008-11-15 20:11 717,296 --a------ c:\windows\system32\drivers\sptd.sys

2008-11-15 18:41 . 2008-11-15 18:41 <DIR> d-------- c:\progs\DVD Decrypter

2008-11-15 17:01 . 2008-12-01 21:04 12 --a------ c:\windows\bthservsdp.dat

2008-11-15 17:00 . 2008-04-14 09:22 21,504 --a------ c:\windows\system32\hidserv.dll

2008-11-15 17:00 . 2008-04-14 09:22 21,504 --a--c--- c:\windows\system32\dllcache\hidserv.dll

2008-11-15 17:00 . 2008-04-14 08:50 14,592 --a------ c:\windows\system32\drivers\kbdhid.sys

2008-11-15 17:00 . 2008-04-14 08:50 14,592 --a--c--- c:\windows\system32\dllcache\kbdhid.sys

2008-11-15 16:54 . 2008-11-15 16:54 <DIR> d-------- c:\progs\Microsoft IntelliType Pro

2008-11-15 16:54 . 2008-11-15 16:54 <DIR> d-------- c:\progs\Microsoft IntelliPoint

2008-11-15 16:48 . 2008-11-15 16:48 410,976 --a------ c:\windows\system32\deploytk.dll

2008-11-15 01:05 . 2008-11-15 01:05 <DIR> d-------- c:\users\??????????????\Programdata\teamspeak2

2008-11-15 01:05 . 2008-11-15 01:05 <DIR> d-------- c:\progs\Teamspeak2_RC2

2008-11-15 01:05 . 2008-11-15 01:05 34,064 --a------ c:\windows\system32\lhacm.acm

2008-11-14 14:38 . 2008-12-01 21:03 <DIR> d-------- c:\users\??????????????\Programdata\uTorrent

2008-11-14 14:38 . 2008-11-14 14:38 <DIR> d-------- c:\progs\uTorrent

2008-11-14 14:18 . 2008-12-01 11:29 <DIR> d-------- c:\users\??????????????\Programdata\foobar2000

2008-11-14 14:15 . 2008-11-14 14:18 <DIR> d-------- c:\progs\foobar2000

2008-11-14 14:09 . 2008-11-24 19:07 <DIR> d-------- c:\windows\.jagex_cache_32

2008-11-14 14:09 . 2008-11-30 14:16 31 --a------ c:\users\??????????????\jagex_runescape_preferences.dat

2008-11-13 16:20 . 2001-10-06 11:36 12,160 --a------ c:\windows\system32\drivers\mouhid.sys

2008-11-13 16:20 . 2001-10-06 11:36 12,160 --a--c--- c:\windows\system32\dllcache\mouhid.sys

2008-11-13 16:20 . 2008-04-13 11:45 10,368 --a------ c:\windows\system32\drivers\hidusb.sys

2008-11-13 16:20 . 2008-04-13 11:45 10,368 --a--c--- c:\windows\system32\dllcache\hidusb.sys

2008-11-13 11:54 . 2008-11-30 14:46 <DIR> d-------- c:\users\??????????????\Programdata\NoNameScript

2008-11-13 11:53 . 2008-11-29 21:08 <DIR> d-------- c:\progs\mIRC

2008-11-13 11:45 . 2008-11-13 11:45 <DIR> d-------- c:\users\??????????????\Programdata\mIRC

2008-11-13 11:27 . 2008-11-13 11:27 <DIR> d-------- c:\progs\CCleaner

2008-11-13 11:25 . 2008-11-14 23:52 <DIR> d-------- c:\users\??????????????\Contacts

2008-11-13 11:17 . 2008-11-13 11:23 <DIR> d--hsc--- c:\progs\Common\WindowsLiveInstaller

2008-11-13 11:16 . 2008-11-13 11:16 <DIR> d-------- c:\users\All Users\Programdata\WLInstaller

2008-11-13 11:16 . 2008-11-13 11:23 <DIR> d-------- c:\progs\Windows Live

2008-11-13 11:13 . 2008-11-13 11:13 <DIR> d-------- c:\progs\TeaTimer (Spybot - Search & Destroy)

2008-11-13 11:13 . 2008-11-13 11:13 <DIR> d-------- c:\progs\SDHelper (Spybot - Search & Destroy)

2008-11-13 11:13 . 2008-11-13 11:13 <DIR> d-------- c:\progs\Misc. Support Library (Spybot - Search & Destroy)

2008-11-13 11:13 . 2008-11-13 11:13 <DIR> d-------- c:\progs\File Scanner Library (Spybot - Search & Destroy)

2008-11-13 11:12 . 2008-11-13 11:12 0 --a------ c:\windows\nsreg.dat

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-12-01 20:05 --------- d-----w c:\progs\Norman

2008-11-15 15:48 --------- d-----w c:\progs\Java

2008-11-14 07:17 --------- d-----w c:\progs\Spybot - Search & Destroy

2008-11-13 10:20 --------- d-----w c:\users\All Users\Programdata\Spybot - Search & Destroy

2008-10-22 10:32 268,435,456 --sha-w C:\WinPEpge.sys

2008-07-14 10:18 32,768 --sha-w c:\windows\system32\config\systemprofile\Cookies\index.dat

2008-07-11 12:01 32,768 --sha-w c:\windows\system32\config\systemprofile\Lokale innstillinger\Logg\History.IE5\index.dat

2008-07-11 12:01 32,768 --sha-w c:\windows\system32\config\systemprofile\Lokale innstillinger\Logg\History.IE5\MSHist012008071120080712\index.dat

2008-07-11 12:01 32,768 --sha-w c:\windows\system32\config\systemprofile\Lokale innstillinger\Temporary Internet Files\Content.IE5\index.dat

2008-07-14 10:37 32,768 --sha-w c:\windows\system32\config\systemprofile\Programdata\Microsoft\Internet Explorer\UserData\index.dat

.

 

(((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret )))))))))))))))))))))))))))))))))))))))))))))

.

.

*Merk* tomme oppføringer & gyldige standardoppføringer vises ikke

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

"MsnMsgr"="c:\progs\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

"MSMSGS"="c:\progs\Messenger\msmsgs.exe" [2008-04-14 1695232]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-05-09 131072]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-05-09 163840]

"Persistence"="c:\windows\system32\igfxpers.exe" [2008-05-09 135168]

"Norman ZANDA"="c:\progs\Norman\Npm\bin\ZLH.EXE" [2008-06-02 273520]

"SigmatelSysTrayApp"="c:\progs\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]

"SunJavaUpdateSched"="c:\progs\Java\jre6\bin\jusched.exe" [2008-11-15 136600]

"Adobe Reader Speed Launcher"="c:\progs\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]

"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]

"ISUSPM Startup"="c:\progs\Common\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]

"ISUSScheduler"="c:\progs\Common\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]

"SSConfig"="c:\sys.000\SW.exe" [2008-10-01 10489856]

"ProcMon"="c:\sys.000\hostsw.exe" [2008-06-23 217088]

"itype"="c:\progs\Microsoft IntelliType Pro\itype.exe" [2006-11-22 813912]

"IntelliPoint"="c:\progs\Microsoft IntelliPoint\ipoint.exe" [2006-11-22 842584]

"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 c:\windows\system32\bthprops.cpl]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"nltide_2"="shell32" [X]

"nltide_3"="advpack.dll" [2008-04-23 c:\windows\system32\advpack.dll]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]

"DisableChangePassword"= 1 (0x1)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-790525478-1644491937-682003330-62552\Scripts\Logon\0\0]

"Script"=%logonserver%\netlogon\pwdcheck.bat

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Progs\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Progs\\Windows Live\\Messenger\\livecall.exe"=

"c:\\Progs\\mIRC\\mirc.exe"=

"c:\\Progs\\uTorrent\\uTorrent.exe"=

"c:\\Users\\??????????????\\Skrivebord\\Listchecker\\pickup.listchecker.exe"=

"c:\\Progs\\Warcraft III\\Frozen Throne.exe"=

"c:\\Progs\\Warcraft III\\Warcraft III.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"6112:TCP"= 6112:TCP:wc3

"6112:UDP"= 6112:UDP:wc3

"6113:TCP"= 6113:TCP:wc3

"6113:UDP"= 6113:UDP:123

"6114:TCP"= 6114:TCP:45

"6114:UDP"= 6114:UDP:231523

"6115:TCP"= 6115:TCP:listchecker

"6115:UDP"= 6115:UDP:listchecker

"6111:TCP"= 6111:TCP:listchecker

"6111:UDP"= 6111:UDP:listchecker

 

R2 MASEL;Event Log Audit;c:\sys.000\Evl.exe [2008-07-10 126976]

R2 Ndiskio;Ndiskio;\??\c:\progs\Norman\Nse\bin\NDISKIO.SYS [2008-07-11 20448]

R3 NvcMFlt;NvcMFlt;c:\windows\system32\DRIVERS\nvcw32mf.sys [2008-07-11 19512]

R3 nvcoas;Norman Virus Control on-access component;"c:\progs\Norman\Nvc\bin\nvcoas.exe" [2008-07-11 183352]

R3 NVCScheduler;Norman Virus Control Scheduler;c:\progs\Norman\Nvc\BIN\NVCSCHED.EXE [2008-07-11 146488]

S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys [2008-12-01 38496]

S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-08-02 32512]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a7f0e0c1-4f42-11dd-aade-806d6172696f}]

\Shell\AutoRun\command - D:\setup.exe

.

Innholdet i mappen 'Scheduled Tasks' (planlagte oppgaver)

 

2008-12-01 c:\windows\Tasks\GoogleUpdateTaskUser.job

- c:\users\??????????????\Lokale innstillinger\Programdata\Google\Update\GoogleUpdate.exe [2008-11-15 16:39]

 

2008-11-15 c:\windows\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job

- c:\progs\Microsoft IntelliPoint\ipoint.exe [2006-11-22 02:09]

 

2008-11-15 c:\windows\Tasks\Microsoft_Hardware_Launch_IType_exe.job

- c:\progs\Microsoft IntelliType Pro\itype.exe [2006-11-22 02:08]

.

- - - - TOMME PEKERE FJERNET - - - -

 

BHO-{1F6C23D6-854C-497f-9275-439C89CF1F68} - (no file)

 

 

.

------- Tilleggsskanning -------

.

FireFox -: Profile - c:\users\??????????????\Programdata\Mozilla\Firefox\Profiles\145bttw6.default\

FF -: plugin - c:\progs\Java\jre6\bin\new_plugin\npdeploytk.dll

FF -: plugin - c:\progs\Java\jre6\bin\new_plugin\npjp2.dll

FF -: plugin - c:\progs\Mozilla Firefox\plugins\npdeploytk.dll

FF -: plugin - c:\users\??????????????\Lokale innstillinger\Programdata\Google\Update\1.2.131.27\npGoogleOneClick6.dll

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-12-01 21:27:10

Windows 5.1.2600 Service Pack 3 NTFS

 

skanner skjulte prosesser ...

 

skanner skjulte autostart-oppføringer ...

 

skanner skjulte filer ...

 

skanning vellykket

skjulte filer: 0

 

**************************************************************************

.

------------------------ Andre Kjørende Prosesser ------------------------

.

c:\progs\Norman\Npm\Bin\elogsvc.exe

c:\progs\Norman\Npm\Bin\Zanda.exe

c:\windows\system32\scardsvr.exe

c:\progs\Java\jre6\bin\jqs.exe

c:\progs\Common\Microsoft Shared\VS7DEBUG\MDM.EXE

c:\progs\Dell\QuickSet\NicConfigSvc.exe

c:\progs\Norman\Npm\Bin\Njeeves.exe

c:\windows\system32\wbem\wmiapsrv.exe

c:\windows\system32\igfxsrvc.exe

c:\progs\Norman\NVC\bin\Nip.exe

c:\progs\Norman\NVC\bin\CClaw.exe

c:\windows\system32\rundll32.exe

c:\sys.000\svpr.exe

.

**************************************************************************

.

Tidspunkt ferdig: 2008-12-01 21:29:15 - maskinen ble startet på nytt [??????????????]

ComboFix-quarantined-files.txt 2008-12-01 20:29:11

 

Pre-Run: 10,681,327,616 byte ledig

Post-Run: 10,472,873,984 byte ledig

 

198

Lenke til kommentar
Videoannonse
Annonse

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
  • Hvem er aktive   0 medlemmer

    • Ingen innloggede medlemmer aktive
×
×
  • Opprett ny...