JarlG Skrevet 6. februar 2009 Del Skrevet 6. februar 2009 Hei! Jeg har fått som oppgave å 'fikse' en kompis sin data. Symptomene var at det var popups fra 'Antivirus Plus', dette er nå fjernet etter å ha fjernet en rootkit som hindret meg i å installere MBAM - men under søket merket jeg at det var MANGE flere problemer, i tillegg. Han hadde Norton fra før, men dette ville verken kjøres eller avinstalleres, så jeg installerte AVG til liten nytte. Det fjernet 7 trojaner, men nå vil det ikke skrus av når jeg skal kjøre ComboFix. Jeg tok allikevel sjangsen og kjørte ComboFix. Enda et problem er at jeg ikke kommer meg på nettet med denne datamaskinen, men i safe-mode with networking så kommer jeg inn på nettsider, men på sider som google så blir jeg redirectet akkurat slik som stickyen beskriver. Det står at dette kan fjernes via ComboFix, men det er ikke gjort enda. Her er MBAM og ComboFix loggene: MBAM Malwarebytes' Anti-Malware 1.33 Database version: 1654 Windows 5.1.2600 Service Pack 2 06.02.2009 18:41:47 mbam-log-2009-02-06 (18-41-47).txt Scan type: Quick Scan Objects scanned: 46968 Time elapsed: 4 minute(s), 20 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 7 Registry Values Infected: 1 Registry Data Items Infected: 1 Folders Infected: 2 Files Infected: 25 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{d5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{d032570a-5f63-4812-a094-87d007c23012} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\MSFox (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{d5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.BHO) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009 (Rogue.Multiple) -> Quarantined and deleted successfully. Files Infected: C:\WINDOWS\system32\InternetExplorer.dll (Trojan.BHO) -> Quarantined and deleted successfully. C:\WINDOWS\system32\avphl.dll (Rogue.AntivirusPlus) -> Quarantined and deleted successfully. C:\WINDOWS\system32\TDSScfub.dll (Trojan.TDSS) -> Quarantined and deleted successfully. C:\WINDOWS\system32\TDSSirxy.dll (Trojan.TDSS) -> Quarantined and deleted successfully. C:\WINDOWS\system32\TDSSktao.dll (Trojan.TDSS) -> Quarantined and deleted successfully. C:\WINDOWS\system32\TDSSnrsr.dll (Trojan.TDSS) -> Quarantined and deleted successfully. C:\WINDOWS\system32\TDSSocun.dll (Trojan.TDSS) -> Quarantined and deleted successfully. C:\WINDOWS\system32\TDSSoexh.dll (Trojan.TDSS) -> Quarantined and deleted successfully. C:\WINDOWS\system32\TDSSravu.dll (Trojan.TDSS) -> Quarantined and deleted successfully. C:\WINDOWS\system32\TDSSriqp.dll (Trojan.TDSS) -> Quarantined and deleted successfully. C:\WINDOWS\system32\drivers\TDSSpaxt.sys (Trojan.TDSS) -> Quarantined and deleted successfully. C:\WINDOWS\system32\drivers\TDSSxxou.sys (Trojan.TDSS) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\TDSS9c13.tmp (Trojan.TDSS) -> Quarantined and deleted successfully. C:\Documents and Settings\sNipp\Local Settings\Temp\~tmpa.exe (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\sNipp\Local Settings\Temp\TDSS6cf5.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\sNipp\Local Settings\Temp\TDSSc186.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\sNipp\Programdata\Microsoft\Internet Explorer\Quick Launch\Antivirus Plus.lnk (Rogue.AntivirusPlus) -> Quarantined and deleted successfully. C:\Documents and Settings\sNipp\Local Settings\Temp\TDSS6ce5.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\sNipp\Local Settings\Temp\TDSS79c6.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\TDSS97ed.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\sNipp\Local Settings\Temp\TDSSc157.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\system32\TDSSfpmp.dll (Rootkit.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\TDSSqqon.dll (Rootkit.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\TDSStkdv.log (Trojan.TDSS) -> Quarantined and deleted successfully. C:\WINDOWS\system32\TDSSwrhd.log (Trojan.TDSS) -> Quarantined and deleted successfully. ComboFix ComboFix 09-02-05.04 - sNipp 2009-02-06 22:20:04.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.649 [GMT 1:00] Kjører fra: c:\documents and settings\sNipp\Skrivebord\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated) AV: Norton Internet Security 2006 *On-access scanning enabled* (Updated) FW: Norton Internet Security 2006 *enabled* * Opprettet nytt gjenopprettingspunkt ADVARSEL -DENNE MASKINEN HAR IKKE GJENOPPRETTINGSKONSOLLEN INSTALLERT !! . ((((((((((((((((((((((((((((((((((((((( Andre slettinger ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\TDSSosvd.dat c:\windows\system32\TDSSwupe.dat E:\Autorun.inf . ((((((((((((((((((((((((((((((((((((((( Drivere/Tjenester ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_TDSSSERV.SYS -------\Service_TDSSserv.sys ((((((((((((((((((((((((((( Filer Opprettet Fra 2009-01-06 til 2009-02-06 ))))))))))))))))))))))))))))))))) . 2009-02-06 18:40 . 2009-02-06 18:40 <DIR> d--h----- C:\$AVG8.VAULT$ 2009-02-06 18:36 . 2009-02-06 18:36 <DIR> d-------- c:\documents and settings\sNipp\Programdata\Malwarebytes 2009-02-06 18:31 . 2009-02-06 18:31 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware 2009-02-06 18:31 . 2009-02-06 18:31 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-02-06 18:31 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-06 18:31 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2009-02-06 16:34 . 2009-02-06 16:34 <DIR> d-------- c:\documents and settings\sNipp\DoctorWeb 2009-02-06 16:18 . 2009-02-06 16:18 <DIR> d-------- c:\windows\system32\drivers\Avg 2009-02-06 16:18 . 2009-02-06 16:18 <DIR> d-------- c:\program files\AVG 2009-02-06 16:18 . 2009-02-06 22:17 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8 2009-02-06 16:18 . 2009-02-06 16:18 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys 2009-02-06 16:18 . 2009-02-06 16:18 76,040 --a------ c:\windows\system32\drivers\avgtdix.sys 2009-02-06 16:18 . 2009-02-06 16:18 10,520 --a------ c:\windows\system32\avgrsstx.dll 2009-02-06 15:43 . 2009-02-06 15:43 <DIR> d-------- c:\documents and settings\sNipp\Programdata\AVGTOOLBAR 2009-02-06 15:37 . 2009-02-06 15:37 <DIR> d-------- c:\documents and settings\Administrator\Application Data\AVGTOOLBAR 2009-02-06 12:29 . 2009-02-06 12:29 268 --ah----- C:\sqmdata01.sqm 2009-02-06 12:29 . 2009-02-06 12:29 244 --ah----- C:\sqmnoopt01.sqm 2009-02-06 12:16 . 2009-02-06 12:16 664 --a------ c:\windows\system32\d3d9caps.dat 2009-02-06 12:02 . 2009-02-06 12:02 268 --ah----- C:\sqmdata00.sqm 2009-02-06 12:02 . 2009-02-06 12:02 244 --ah----- C:\sqmnoopt00.sqm 2009-02-06 12:01 . 2009-02-06 15:46 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP 2009-02-06 12:01 . 2005-08-25 19:18 118,784 --a------ c:\windows\system32\MSSTDFMT.DLL 2009-02-06 12:00 . 2009-02-06 12:01 <DIR> d-------- c:\program files\SpywareBlaster . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-02-06 11:05 --------- d-----w c:\program files\Common Files\Symantec Shared 2009-02-06 10:08 --------- d-----w c:\program files\Symantec 2008-12-18 16:33 --------- d-----w c:\documents and settings\sNipp\Programdata\uTorrent 2008-12-17 18:12 --------- d-----w c:\program files\Xfire 2008-12-16 18:13 --------- d-----w c:\documents and settings\sNipp\Programdata\AdobeUM 2008-12-15 23:23 --------- d-----w c:\documents and settings\sNipp\Programdata\Xfire 2008-12-15 14:56 --------- d-----w c:\documents and settings\sNipp\Programdata\dvdcss 2008-12-15 14:28 --------- d-----w c:\documents and settings\sNipp\Programdata\Ventrilo 2008-12-15 14:23 --------- dc-h--w c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185} 2008-12-15 12:58 --------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2 2008-12-13 21:03 --------- d-----w c:\program files\Windows Live 2008-12-13 21:00 --------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller 2008-12-13 20:59 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller 2008-12-11 17:10 --------- d-----w c:\documents and settings\sNipp\Programdata\vlc 2008-12-11 17:09 --------- d-----w c:\program files\VideoLAN 2008-12-08 15:35 --------- d-----w c:\program files\Ventrilo 2008-12-08 15:35 --------- d-----w c:\program files\Common Files\Wise Installation Wizard . (((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret ))))))))))))))))))))))))))))))))))))))))))))) . . *Merk* tomme oppføringer & gyldige standardoppføringer vises ikke REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184] "Google Update"="c:\documents and settings\sNipp\Lokale innstillinger\Programdata\Google\Update\GoogleUpdate.exe" [2008-12-15 133104] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-07-20 7581696] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-06 1261336] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-16 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.XFR1"= xfcodec.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Hurtigstart.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Hurtigstart.lnk backup=c:\windows\pss\HP Photosmart Premier Hurtigstart.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Hurtigstart for Adobe Reader.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Hurtigstart for Adobe Reader.lnk backup=c:\windows\pss\Hurtigstart for Adobe Reader.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^sNipp^Start Menu^Programs^StartUp^Xfire.lnk] path=c:\documents and settings\sNipp\Start Menu\Programs\StartUp\Xfire.lnk backup=c:\windows\pss\Xfire.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp] --a------ 2005-09-17 15:27 52848 c:\program files\Common Files\Symantec Shared\ccApp.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset] --a------ 2006-06-19 09:50 40960 c:\program files\Hewlett-Packard\Default Settings\Cpqset.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] --a------ 2006-03-16 05:00 15360 c:\windows\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray] --a------ 2005-08-05 20:56 64512 c:\windows\ehome\ehtray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] --a------ 2005-02-16 22:11 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant] --a------ 2006-05-03 21:58 458752 c:\program files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz] --a------ 2005-09-30 13:33 120464 c:\program files\Norton Internet Security\CfgWiz.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] --a------ 2006-07-20 06:58 7581696 c:\windows\system32\nvcpl.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] --a------ 2006-07-20 06:58 86016 c:\windows\system32\nvmctray.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl] --a------ 2006-06-19 10:33 163840 c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService] --a------ 2006-07-19 14:14 102400 c:\program files\HP\QuickPlay\QPService.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecGuard] --a------ 2005-10-11 09:23 1187840 c:\windows\SMINST\Recguard.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSC_UserPrompt] --a------ 2004-11-09 03:45 218240 c:\program files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2005-11-10 20:03 36975 c:\program files\Java\jre1.5.0_06\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] --a------ 2006-06-17 06:22 794713 c:\program files\Synaptics\SynTP\SynTPEnh.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut] --a------ 2006-06-02 16:02 61952 c:\windows\system32\CHDAudPropShortcut.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsmqIntCert] --a------ 2006-03-16 05:00 177152 c:\windows\system32\mqrt.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] --a------ 2006-07-20 06:58 1519616 c:\windows\system32\nwiz.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\WINDOWS\\system32\\mqsvc.exe"= "c:\\Program Files\\Xfire\\Xfire.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Ventrilo\\Ventrilo.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"= "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"= R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-02-06 97928] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-02-06 875288] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-06 231704] R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-02-06 76040] R3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [2006-06-06 61952] S2 cdralw;NVIDIA Compatible Windows Miniport Driver;c:\windows\system32\DRIVERS\nvmini.sys --> c:\windows\system32\DRIVERS\nvmini.sys [?] --- Andre tjenester/drivere lastet i minnet --- *NewlyCreated* - COMHOST [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E] \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cf8e62f9-c53d-11dd-acf7-001636b91feb}] \Shell\AutoRun\command - WD_Windows_Tools\Setup.exe . Innholdet i mappen 'Scheduled Tasks' (planlagte oppgaver) 2009-02-06 c:\windows\Tasks\GoogleUpdateTaskUser.job - c:\documents and settings\sNipp\Lokale innstillinger\Programdata\Google\Update\GoogleUpdate.exe [2008-12-15 20:25] 2009-01-09 c:\windows\Tasks\Internett-tjenester.job - c:\program files\Hewlett-Packard\SDP\HPSdpApp.exe [2005-09-08 11:23] 2008-12-18 c:\windows\Tasks\Norton AntiVirus - Kjør fullstendig systemsøk - sNipp.job - c:\progra~1\NORTON~1\NORTON~1\Navw32.exe [2005-10-07 15:26] . . ------- Tilleggsskanning ------- . uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=NB_NO&c=64&bd=pavilion&pf=laptop uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=NB_NO&c=64&bd=pavilion&pf=laptop IE: &Google-søk - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html IE: &Oversett engelsk ord - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html IE: Koblinger bakover - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html IE: Lignende sider - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html IE: Øyeblikksbilde av siden i hurtigbufferen - c:\program files\Google\GoogleToolbar1.dll/cmcache.html FF - ProfilePath - c:\documents and settings\sNipp\Programdata\Mozilla\Firefox\Profiles\rpzlaqr8.default\ FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".no"); . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-06 22:24:26 Windows 5.1.2600 Service Pack 2 NTFS skanner skjulte prosesser ... skanner skjulte autostart-oppføringer ... skanner skjulte filer ... skanning vellykket skjulte filer: 0 ************************************************************************** . ------------------------ Andre Kjørende Prosesser ------------------------ . c:\program files\Common Files\Symantec Shared\ccSetMgr.exe c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe c:\program files\Common Files\Symantec Shared\ccProxy.exe c:\program files\Common Files\Symantec Shared\SNDSrvc.exe c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe c:\windows\system32\msdtc.exe c:\windows\ehome\ehrecvr.exe c:\windows\ehome\ehSched.exe c:\program files\Common Files\LightScribe\LSSrvc.exe c:\program files\Norton Internet Security\Norton AntiVirus\navapsvc.exe c:\program files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE c:\windows\system32\nvsvc32.exe c:\windows\ehome\mcrdsvc.exe c:\windows\system32\mqsvc.exe c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe c:\windows\system32\mqtgsvc.exe c:\windows\system32\dllhost.exe c:\program files\AVG\AVG8\avgrsx.exe c:\program files\AVG\AVG8\avgrsx.exe c:\program files\AVG\AVG8\avgrsx.exe . ************************************************************************** . Tidspunkt ferdig: 2009-02-06 22:26:37 - maskinen ble startet på nytt [sNipp] ComboFix-quarantined-files.txt 2009-02-06 21:26:32 Pre-Run: 9 032 769 536 bytes free Post-Run: 9,209,008,128 byte ledig 230 --- E O F --- 2009-01-09 17:55:34 Oppdager nå at ved et Full-system søk så er det blitt merket 9 infeksjoner av MBAM. Jeg poster logg av dette søket når det er ferdig. Takker for all hjelp! Lenke til kommentar
norbat Skrevet 6. februar 2009 Del Skrevet 6. februar 2009 Når søket er ferdig, kan du avinstallere Norton ved å bruke Norton Removal Tool Deretter kjører du combofix og poster ny logg. Lenke til kommentar
JarlG Skrevet 6. februar 2009 Forfatter Del Skrevet 6. februar 2009 Har nå gjort som du sa, og merkelig nok fikk jeg internett tilbake på infiserte maskinen etter jeg hadde avinstallert Norton. :O Her er ny ComboFix logg: ComboFix 09-02-06.01 - sNipp 2009-02-06 23:40:57.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.664 [GMT 1:00] Kjører fra: c:\documents and settings\sNipp\Skrivebord\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated) * Opprettet nytt gjenopprettingspunkt . ((((((((((((((((((((((((((((((((((((((( Andre slettinger ))))))))))))))))))))))))))))))))))))))))))))))))) . G:\resycled g:\resycled\boot.com . ((((((((((((((((((((((((((( Filer Opprettet Fra 2009-01-06 til 2009-02-06 ))))))))))))))))))))))))))))))))) . 2009-02-06 18:40 . 2009-02-06 22:54 <DIR> d--h----- C:\$AVG8.VAULT$ 2009-02-06 18:36 . 2009-02-06 18:36 <DIR> d-------- c:\documents and settings\sNipp\Programdata\Malwarebytes 2009-02-06 18:31 . 2009-02-06 18:31 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware 2009-02-06 18:31 . 2009-02-06 18:31 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-02-06 18:31 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-06 18:31 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2009-02-06 16:34 . 2009-02-06 16:34 <DIR> d-------- c:\documents and settings\sNipp\DoctorWeb 2009-02-06 16:18 . 2009-02-06 16:18 <DIR> d-------- c:\windows\system32\drivers\Avg 2009-02-06 16:18 . 2009-02-06 16:18 <DIR> d-------- c:\program files\AVG 2009-02-06 16:18 . 2009-02-06 22:17 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8 2009-02-06 16:18 . 2009-02-06 16:18 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys 2009-02-06 16:18 . 2009-02-06 16:18 76,040 --a------ c:\windows\system32\drivers\avgtdix.sys 2009-02-06 16:18 . 2009-02-06 16:18 10,520 --a------ c:\windows\system32\avgrsstx.dll 2009-02-06 15:43 . 2009-02-06 15:43 <DIR> d-------- c:\documents and settings\sNipp\Programdata\AVGTOOLBAR 2009-02-06 15:37 . 2009-02-06 15:37 <DIR> d-------- c:\documents and settings\Administrator\Application Data\AVGTOOLBAR 2009-02-06 12:29 . 2009-02-06 12:29 268 --ah----- C:\sqmdata01.sqm 2009-02-06 12:29 . 2009-02-06 12:29 244 --ah----- C:\sqmnoopt01.sqm 2009-02-06 12:16 . 2009-02-06 12:16 664 --a------ c:\windows\system32\d3d9caps.dat 2009-02-06 12:02 . 2009-02-06 12:02 268 --ah----- C:\sqmdata00.sqm 2009-02-06 12:02 . 2009-02-06 12:02 244 --ah----- C:\sqmnoopt00.sqm 2009-02-06 12:01 . 2009-02-06 15:46 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP 2009-02-06 12:01 . 2005-08-25 19:18 118,784 --a------ c:\windows\system32\MSSTDFMT.DLL 2009-02-06 12:00 . 2009-02-06 12:01 <DIR> d-------- c:\program files\SpywareBlaster . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-02-06 22:33 --------- d-----w c:\program files\Common Files\Symantec Shared 2008-12-18 16:33 --------- d-----w c:\documents and settings\sNipp\Programdata\uTorrent 2008-12-17 18:12 --------- d-----w c:\program files\Xfire 2008-12-16 18:13 --------- d-----w c:\documents and settings\sNipp\Programdata\AdobeUM 2008-12-15 23:23 --------- d-----w c:\documents and settings\sNipp\Programdata\Xfire 2008-12-15 14:56 --------- d-----w c:\documents and settings\sNipp\Programdata\dvdcss 2008-12-15 14:28 --------- d-----w c:\documents and settings\sNipp\Programdata\Ventrilo 2008-12-15 14:23 --------- dc-h--w c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185} 2008-12-15 12:58 --------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2 2008-12-13 21:03 --------- d-----w c:\program files\Windows Live 2008-12-13 21:00 --------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller 2008-12-13 20:59 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller 2008-12-12 17:27 3,067,392 ------w c:\windows\system32\dllcache\mshtml.dll 2008-12-11 20:37 42,320 ----a-w c:\windows\system32\xfcodec.dll 2008-12-11 17:10 --------- d-----w c:\documents and settings\sNipp\Programdata\vlc 2008-12-11 17:09 --------- d-----w c:\program files\VideoLAN 2008-12-08 15:35 --------- d-----w c:\program files\Ventrilo 2008-12-08 15:35 --------- d-----w c:\program files\Common Files\Wise Installation Wizard . ((((((((((((((((((((((((((((( SnapShot@2009-02-06_22.25.40.48 ))))))))))))))))))))))))))))))))))))))))) . - 2009-02-06 17:49:08 56,056 ----a-w c:\windows\system32\perfc009.dat + 2009-02-06 22:38:05 56,056 ----a-w c:\windows\system32\perfc009.dat - 2009-02-06 17:49:08 391,404 ----a-w c:\windows\system32\perfh009.dat + 2009-02-06 22:38:05 391,404 ----a-w c:\windows\system32\perfh009.dat . (((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret ))))))))))))))))))))))))))))))))))))))))))))) . . *Merk* tomme oppføringer & gyldige standardoppføringer vises ikke REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184] "Google Update"="c:\documents and settings\sNipp\Lokale innstillinger\Programdata\Google\Update\GoogleUpdate.exe" [2008-12-15 133104] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-07-20 7581696] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-06 1261336] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-16 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.XFR1"= xfcodec.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Hurtigstart.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Hurtigstart.lnk backup=c:\windows\pss\HP Photosmart Premier Hurtigstart.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Hurtigstart for Adobe Reader.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Hurtigstart for Adobe Reader.lnk backup=c:\windows\pss\Hurtigstart for Adobe Reader.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^sNipp^Start Menu^Programs^StartUp^Xfire.lnk] path=c:\documents and settings\sNipp\Start Menu\Programs\StartUp\Xfire.lnk backup=c:\windows\pss\Xfire.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset] --a------ 2006-06-19 09:50 40960 c:\program files\Hewlett-Packard\Default Settings\Cpqset.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] --a------ 2006-03-16 05:00 15360 c:\windows\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray] --a------ 2005-08-05 20:56 64512 c:\windows\ehome\ehtray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] --a------ 2005-02-16 22:11 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant] --a------ 2006-05-03 21:58 458752 c:\program files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] --a------ 2006-07-20 06:58 7581696 c:\windows\system32\nvcpl.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] --a------ 2006-07-20 06:58 86016 c:\windows\system32\nvmctray.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl] --a------ 2006-06-19 10:33 163840 c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService] --a------ 2006-07-19 14:14 102400 c:\program files\HP\QuickPlay\QPService.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecGuard] --a------ 2005-10-11 09:23 1187840 c:\windows\SMINST\Recguard.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2005-11-10 20:03 36975 c:\program files\Java\jre1.5.0_06\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] --a------ 2006-06-17 06:22 794713 c:\program files\Synaptics\SynTP\SynTPEnh.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut] --a------ 2006-06-02 16:02 61952 c:\windows\system32\CHDAudPropShortcut.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsmqIntCert] --a------ 2006-03-16 05:00 177152 c:\windows\system32\mqrt.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] --a------ 2006-07-20 06:58 1519616 c:\windows\system32\nwiz.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\WINDOWS\\system32\\mqsvc.exe"= "c:\\Program Files\\Xfire\\Xfire.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Ventrilo\\Ventrilo.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"= "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"= R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-02-06 97928] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-06 231704] R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-02-06 76040] R3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [2006-06-06 61952] S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-02-06 875288] S2 cdralw;NVIDIA Compatible Windows Miniport Driver;c:\windows\system32\DRIVERS\nvmini.sys --> c:\windows\system32\DRIVERS\nvmini.sys [?] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cf8e62f9-c53d-11dd-acf7-001636b91feb}] \Shell\AutoRun\command - WD_Windows_Tools\Setup.exe . Innholdet i mappen 'Scheduled Tasks' (planlagte oppgaver) 2009-02-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-985822856-2524474350-2388280304-1005.job - c:\documents and settings\sNipp\Lokale innstillinger\Programdata\Google\Update\GoogleUpdate.exe [2008-12-15 20:25] 2009-01-09 c:\windows\Tasks\Internett-tjenester.job - c:\program files\Hewlett-Packard\SDP\HPSdpApp.exe [2005-09-08 11:23] . - - - - TOMME PEKERE FJERNET - - - - MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe MSConfigStartUp-IS CfgWiz - c:\program files\Norton Internet Security\cfgwiz.exe MSConfigStartUp-SSC_UserPrompt - c:\program files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe . ------- Tilleggsskanning ------- . uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=NB_NO&c=64&bd=pavilion&pf=laptop uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=NB_NO&c=64&bd=pavilion&pf=laptop IE: &Google-søk - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html IE: &Oversett engelsk ord - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html IE: Koblinger bakover - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html IE: Lignende sider - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html IE: Øyeblikksbilde av siden i hurtigbufferen - c:\program files\Google\GoogleToolbar1.dll/cmcache.html FF - ProfilePath - c:\documents and settings\sNipp\Programdata\Mozilla\Firefox\Profiles\rpzlaqr8.default\ FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".no"); . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-06 23:42:32 Windows 5.1.2600 Service Pack 2 NTFS skanner skjulte prosesser ... skanner skjulte autostart-oppføringer ... skanner skjulte filer ... skanning vellykket skjulte filer: 0 ************************************************************************** . --------------------- DLL'er Lastet Av Kjørende Prosesser --------------------- - - - - - - - > 'winlogon.exe'(960) c:\windows\system32\avgrsstx.dll - - - - - - - > 'lsass.exe'(1072) c:\windows\system32\avgrsstx.dll . Tidspunkt ferdig: 2009-02-06 23:44:04 ComboFix-quarantined-files.txt 2009-02-06 22:44:01 ComboFix2.txt 2009-02-06 21:26:40 Pre-Run: 9 356 951 552 bytes free Post-Run: 8,918,495,232 byte ledig WindowsXP-KB310994-SP2-Pro-BootDisk-NOR.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect 210 --- E O F --- 2009-01-09 17:55:34 Lenke til kommentar
norbat Skrevet 6. februar 2009 Del Skrevet 6. februar 2009 - og hvordan går det med pc'n når. Fungerer alt slit det skal? Lenke til kommentar
JarlG Skrevet 6. februar 2009 Forfatter Del Skrevet 6. februar 2009 Sånn egentlig ser alt greit ut.. Takker for hjelp, om det er fikset nå! Og jeg som trodde det skulle bli filsletting og regedit - oppgaver. Lenke til kommentar
norbat Skrevet 6. februar 2009 Del Skrevet 6. februar 2009 (endret) Ja, loggen ser grei ut. Avintaller combofix ved å skrive combofix /u i kjør-feltet (start->kjør) Dette vil også nullstille systemgjenopprettingen slik at du ikke blir infisert ved en evt. gjenoppretting senere. Sørg forøvrig at Java, Flash player og Adobe reader er oppdatert i tillegg til Windows. Surt trygt. Endret 6. februar 2009 av norbat Lenke til kommentar
JarlG Skrevet 6. februar 2009 Forfatter Del Skrevet 6. februar 2009 Har visst ett problem til, AVG vil ikke avinstalleres. (slik at jeg kan installere på ny, det oppstod problemer forrige gang.) Er det noen måte å få avinstallert et ikke-fungerende AVG? Lenke til kommentar
norbat Skrevet 6. februar 2009 Del Skrevet 6. februar 2009 (endret) Bruk AVG Remover Endret 6. februar 2009 av norbat Lenke til kommentar
JarlG Skrevet 6. februar 2009 Forfatter Del Skrevet 6. februar 2009 Den skulle jeg spart deg for... Takker for all hjelp! PS: Er utrolig imponert over hvor fort du svarer! Lenke til kommentar
JarlG Skrevet 6. februar 2009 Forfatter Del Skrevet 6. februar 2009 Beklager dobbel-post, men må bare si at removeren ikke fungerte. Vil det oppstå noen problemer om jeg installerer et annet Antivirusprogram, når AVG ikke vil kjøre en gang? Takker for all hjelp! Lenke til kommentar
norbat Skrevet 6. februar 2009 Del Skrevet 6. februar 2009 Kan du kjøre combofix og poste loggen, så kan vi evt. fjerne noen tjenester etc. fra systemet. Lenke til kommentar
JarlG Skrevet 6. februar 2009 Forfatter Del Skrevet 6. februar 2009 Før skannen gjorde ComboFix meg oppmerksom på at AVG Free 8.0 kjører - noe som det ikke skal. Ettersom at jeg ikke kan avslutte AVG-prosessene, kjørte jeg bare skannen allikevel. Her er loggen: ComboFix 09-02-06.01 - sNipp 2009-02-07 0:35:09.3 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.611 [GMT 1:00] Kjører fra: c:\documents and settings\sNipp\Skrivebord\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated) . ((((((((((((((((((((((((((( Filer Opprettet Fra 2009-01-06 til 2009-02-06 ))))))))))))))))))))))))))))))))) . 2009-02-07 00:01 . 2009-02-07 00:01 <DIR> d-------- c:\windows\Internet Logs 2009-02-06 18:40 . 2009-02-06 22:54 <DIR> d--h----- C:\$AVG8.VAULT$ 2009-02-06 18:36 . 2009-02-06 18:36 <DIR> d-------- c:\documents and settings\sNipp\Programdata\Malwarebytes 2009-02-06 18:31 . 2009-02-06 18:31 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware 2009-02-06 18:31 . 2009-02-06 18:31 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-02-06 18:31 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-06 18:31 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2009-02-06 16:34 . 2009-02-06 16:34 <DIR> d-------- c:\documents and settings\sNipp\DoctorWeb 2009-02-06 16:18 . 2009-02-06 16:18 <DIR> d-------- c:\windows\system32\drivers\Avg 2009-02-06 16:18 . 2009-02-06 16:18 <DIR> d-------- c:\program files\AVG 2009-02-06 16:18 . 2009-02-07 00:02 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8 2009-02-06 16:18 . 2009-02-06 16:18 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys 2009-02-06 16:18 . 2009-02-06 16:18 76,040 --a------ c:\windows\system32\drivers\avgtdix.sys 2009-02-06 16:18 . 2009-02-06 16:18 10,520 --a------ c:\windows\system32\avgrsstx.dll 2009-02-06 15:43 . 2009-02-06 15:43 <DIR> d-------- c:\documents and settings\sNipp\Programdata\AVGTOOLBAR 2009-02-06 15:37 . 2009-02-06 15:37 <DIR> d-------- c:\documents and settings\Administrator\Application Data\AVGTOOLBAR 2009-02-06 12:29 . 2009-02-06 12:29 268 --ah----- C:\sqmdata01.sqm 2009-02-06 12:29 . 2009-02-06 12:29 244 --ah----- C:\sqmnoopt01.sqm 2009-02-06 12:16 . 2009-02-06 12:16 664 --a------ c:\windows\system32\d3d9caps.dat 2009-02-06 12:02 . 2009-02-06 12:02 268 --ah----- C:\sqmdata00.sqm 2009-02-06 12:02 . 2009-02-06 12:02 244 --ah----- C:\sqmnoopt00.sqm 2009-02-06 12:01 . 2009-02-06 23:48 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP 2009-02-06 12:01 . 2005-08-25 19:18 118,784 --a------ c:\windows\system32\MSSTDFMT.DLL 2009-02-06 12:00 . 2009-02-06 23:48 <DIR> d-------- c:\program files\SpywareBlaster . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-02-06 22:33 --------- d-----w c:\program files\Common Files\Symantec Shared 2008-12-18 16:33 --------- d-----w c:\documents and settings\sNipp\Programdata\uTorrent 2008-12-17 18:12 --------- d-----w c:\program files\Xfire 2008-12-16 18:13 --------- d-----w c:\documents and settings\sNipp\Programdata\AdobeUM 2008-12-15 23:23 --------- d-----w c:\documents and settings\sNipp\Programdata\Xfire 2008-12-15 14:56 --------- d-----w c:\documents and settings\sNipp\Programdata\dvdcss 2008-12-15 14:28 --------- d-----w c:\documents and settings\sNipp\Programdata\Ventrilo 2008-12-15 14:23 --------- dc-h--w c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185} 2008-12-15 12:58 --------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2 2008-12-13 21:03 --------- d-----w c:\program files\Windows Live 2008-12-13 21:00 --------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller 2008-12-13 20:59 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller 2008-12-12 17:27 3,067,392 ------w c:\windows\system32\dllcache\mshtml.dll 2008-12-11 20:37 42,320 ----a-w c:\windows\system32\xfcodec.dll 2008-12-11 17:10 --------- d-----w c:\documents and settings\sNipp\Programdata\vlc 2008-12-11 17:09 --------- d-----w c:\program files\VideoLAN 2008-12-08 15:35 --------- d-----w c:\program files\Ventrilo 2008-12-08 15:35 --------- d-----w c:\program files\Common Files\Wise Installation Wizard . (((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret ))))))))))))))))))))))))))))))))))))))))))))) . . *Merk* tomme oppføringer & gyldige standardoppføringer vises ikke REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184] "Google Update"="c:\documents and settings\sNipp\Lokale innstillinger\Programdata\Google\Update\GoogleUpdate.exe" [2008-12-15 133104] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-07-20 7581696] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-06 1261336] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-16 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.XFR1"= xfcodec.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Hurtigstart.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Hurtigstart.lnk backup=c:\windows\pss\HP Photosmart Premier Hurtigstart.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Hurtigstart for Adobe Reader.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Hurtigstart for Adobe Reader.lnk backup=c:\windows\pss\Hurtigstart for Adobe Reader.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^sNipp^Start Menu^Programs^StartUp^Xfire.lnk] path=c:\documents and settings\sNipp\Start Menu\Programs\StartUp\Xfire.lnk backup=c:\windows\pss\Xfire.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset] --a------ 2006-06-19 09:50 40960 c:\program files\Hewlett-Packard\Default Settings\Cpqset.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] --a------ 2006-03-16 05:00 15360 c:\windows\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray] --a------ 2005-08-05 20:56 64512 c:\windows\ehome\ehtray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] --a------ 2005-02-16 22:11 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant] --a------ 2006-05-03 21:58 458752 c:\program files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] --a------ 2006-07-20 06:58 7581696 c:\windows\system32\nvcpl.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] --a------ 2006-07-20 06:58 86016 c:\windows\system32\nvmctray.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl] --a------ 2006-06-19 10:33 163840 c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService] --a------ 2006-07-19 14:14 102400 c:\program files\HP\QuickPlay\QPService.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecGuard] --a------ 2005-10-11 09:23 1187840 c:\windows\SMINST\Recguard.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2005-11-10 20:03 36975 c:\program files\Java\jre1.5.0_06\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] --a------ 2006-06-17 06:22 794713 c:\program files\Synaptics\SynTP\SynTPEnh.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut] --a------ 2006-06-02 16:02 61952 c:\windows\system32\CHDAudPropShortcut.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsmqIntCert] --a------ 2006-03-16 05:00 177152 c:\windows\system32\mqrt.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] --a------ 2006-07-20 06:58 1519616 c:\windows\system32\nwiz.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\WINDOWS\\system32\\mqsvc.exe"= "c:\\Program Files\\Xfire\\Xfire.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Ventrilo\\Ventrilo.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"= "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"= R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-02-06 97928] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-06 231704] R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-02-06 76040] R3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [2006-06-06 61952] S2 cdralw;NVIDIA Compatible Windows Miniport Driver;c:\windows\system32\DRIVERS\nvmini.sys --> c:\windows\system32\DRIVERS\nvmini.sys [?] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cf8e62f9-c53d-11dd-acf7-001636b91feb}] \Shell\AutoRun\command - WD_Windows_Tools\Setup.exe . Innholdet i mappen 'Scheduled Tasks' (planlagte oppgaver) 2009-02-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-985822856-2524474350-2388280304-1005.job - c:\documents and settings\sNipp\Lokale innstillinger\Programdata\Google\Update\GoogleUpdate.exe [2008-12-15 20:25] 2009-01-09 c:\windows\Tasks\Internett-tjenester.job - c:\program files\Hewlett-Packard\SDP\HPSdpApp.exe [2005-09-08 11:23] . . ------- Tilleggsskanning ------- . uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=NB_NO&c=64&bd=pavilion&pf=laptop uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=NB_NO&c=64&bd=pavilion&pf=laptop IE: &Google-søk - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html IE: &Oversett engelsk ord - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html IE: Koblinger bakover - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html IE: Lignende sider - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html IE: Øyeblikksbilde av siden i hurtigbufferen - c:\program files\Google\GoogleToolbar1.dll/cmcache.html FF - ProfilePath - c:\documents and settings\sNipp\Programdata\Mozilla\Firefox\Profiles\rpzlaqr8.default\ FF - plugin: c:\documents and settings\sNipp\Lokale innstillinger\Programdata\Google\Update\1.2.133.33\npGoogleOneClick7.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".no"); . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-07 00:36:15 Windows 5.1.2600 Service Pack 2 NTFS skanner skjulte prosesser ... skanner skjulte autostart-oppføringer ... skanner skjulte filer ... skanning vellykket skjulte filer: 0 ************************************************************************** . --------------------- DLL'er Lastet Av Kjørende Prosesser --------------------- - - - - - - - > 'winlogon.exe'(960) c:\windows\system32\avgrsstx.dll - - - - - - - > 'lsass.exe'(1072) c:\windows\system32\avgrsstx.dll . Tidspunkt ferdig: 2009-02-07 0:37:17 ComboFix-quarantined-files.txt 2009-02-06 23:37:15 ComboFix2.txt 2009-02-06 22:44:05 Pre-Run: 9 417 052 160 bytes free Post-Run: 9,521,946,624 byte ledig 183 --- E O F --- 2009-01-09 17:55:34 Lenke til kommentar
norbat Skrevet 6. februar 2009 Del Skrevet 6. februar 2009 Hvis du har forsøkt å installere avg igjen uten at det fungerer, problemer med å avinstallere det, så gjør følgende: Klikk: Start->kjør Skriv: cmd Skriv: regsvr32 /u avgrsstx.dll (klikk Enter) Lukk cmd Åpne notisblokk og kopier inn det som står i fet skrift under, lagre fila på skrivebordet som CFScript.txt. Dra deretter fila over Combofix-iconet. Combofix vil starte igjen. Post loggen. File:: c:\windows\system32\avgrsstx.dll Folder:: c:\program files\Common Files\Symantec Shared c:\documents and settings\Administrator\Application Data\AVGTOOLBAR c:\documents and settings\sNipp\Programdata\AVGTOOLBAR c:\windows\system32\avgrsstx.dll c:\windows\system32\drivers\avgtdix.sys c:\windows\system32\drivers\avgldx86.sys c:\documents and settings\All Users\Application Data\avg8 c:\program files\AVG c:\windows\system32\drivers\Avg C:\$AVG8.VAULT$ Driver:: AvgLdx86 avg8wd AvgTdiX Registry:: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AVG8_TRAY"=- Lenke til kommentar
JarlG Skrevet 7. februar 2009 Forfatter Del Skrevet 7. februar 2009 Gjorde det, først kom det opp en feilmelding i cmd om at filen ikke var registrert, men etter ComboFix var kjørt, var ikke filen der i det hele tatt - så jeg antar det gikk fint. Her er loggen: ComboFix 09-02-06.01 - sNipp 2009-02-07 0:58:21.4 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.605 [GMT 1:00] Kjører fra: c:\documents and settings\sNipp\Skrivebord\ComboFix.exe Command switches brukt :: c:\documents and settings\sNipp\Skrivebord\CFScript.txt AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated) * Opprettet nytt gjenopprettingspunkt FILE :: c:\windows\system32\avgrsstx.dll . ((((((((((((((((((((((((((((((((((((((( Andre slettinger ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\$AVG8.VAULT$ c:\$avg8.vault$\V_00000001.fil c:\$avg8.vault$\V_00000002.fil c:\$avg8.vault$\V_00000003.fil c:\$avg8.vault$\V_00000004.fil c:\$avg8.vault$\V_00000005.fil c:\$avg8.vault$\V_00000006.fil c:\$avg8.vault$\V_00000007.fil c:\$avg8.vault$\V_00000008.fil c:\$avg8.vault$\V_00000009.fil c:\$avg8.vault$\V_00000010.fil c:\$avg8.vault$\V_00000011.fil c:\$avg8.vault$\V_00000012.fil c:\$avg8.vault$\V_00000013.fil c:\$avg8.vault$\V_00000014.fil c:\$avg8.vault$\V_00000015.fil c:\$avg8.vault$\V_00000016.fil c:\$avg8.vault$\vvfolder.idx c:\documents and settings\Administrator\Application Data\AVGTOOLBAR c:\documents and settings\All Users\Application Data\avg8 c:\documents and settings\All Users\Application Data\avg8\Cfg\krnl.cfg c:\documents and settings\All Users\Application Data\avg8\Cfg\mail.cfg c:\documents and settings\All Users\Application Data\avg8\Cfg\scan.cfg c:\documents and settings\All Users\Application Data\avg8\Cfg\sched.cfg c:\documents and settings\All Users\Application Data\avg8\Cfg\update.cfg c:\documents and settings\All Users\Application Data\avg8\Cfg\user.cfg c:\documents and settings\All Users\Application Data\avg8\dumps\avgwdsvc.exe_128784072229375000.dmp c:\documents and settings\All Users\Application Data\avg8\dumps\avgwdsvc.exe_128784072513437500.dmp c:\documents and settings\All Users\Application Data\avg8\emc\Log\emc.log c:\documents and settings\All Users\Application Data\avg8\Log\avgcfg.log c:\documents and settings\All Users\Application Data\avg8\Log\avgcfg.log.lock c:\documents and settings\All Users\Application Data\avg8\Log\avgcore.log c:\documents and settings\All Users\Application Data\avg8\Log\avgcore.log.lock c:\documents and settings\All Users\Application Data\avg8\Log\avglng.log c:\documents and settings\All Users\Application Data\avg8\Log\avglng.log.lock c:\documents and settings\All Users\Application Data\avg8\Log\avgrs.log c:\documents and settings\All Users\Application Data\avg8\Log\avgrs.log.lock c:\documents and settings\All Users\Application Data\avg8\Log\avgscan.log c:\documents and settings\All Users\Application Data\avg8\Log\avgscan.log.lock c:\documents and settings\All Users\Application Data\avg8\Log\avgsched.log c:\documents and settings\All Users\Application Data\avg8\Log\avgsched.log.lock c:\documents and settings\All Users\Application Data\avg8\Log\avgsrm.log c:\documents and settings\All Users\Application Data\avg8\Log\avgsrm.log.lock c:\documents and settings\All Users\Application Data\avg8\Log\avgui.log c:\documents and settings\All Users\Application Data\avg8\Log\avgui.log.lock c:\documents and settings\All Users\Application Data\avg8\Log\avguilog.cfg.install_backup c:\documents and settings\All Users\Application Data\avg8\Log\avgupd.log c:\documents and settings\All Users\Application Data\avg8\Log\avgupd.log.lock c:\documents and settings\All Users\Application Data\avg8\Log\avgwd.log c:\documents and settings\All Users\Application Data\avg8\Log\avgwd.log.lock c:\documents and settings\All Users\Application Data\avg8\Log\avgwdsvc.log c:\documents and settings\All Users\Application Data\avg8\Log\avgwdsvc.log.lock c:\documents and settings\All Users\Application Data\avg8\Log\avildr.log c:\documents and settings\All Users\Application Data\avg8\Log\cfglog.cfg.install_backup c:\documents and settings\All Users\Application Data\avg8\Log\commonpriv.log c:\documents and settings\All Users\Application Data\avg8\Log\commonpriv.log.lock c:\documents and settings\All Users\Application Data\avg8\Log\corelog.cfg.install_backup c:\documents and settings\All Users\Application Data\avg8\Log\history.xml c:\documents and settings\All Users\Application Data\avg8\Log\lnglog.cfg.install_backup c:\documents and settings\All Users\Application Data\avg8\Log\privlog.cfg.install_backup c:\documents and settings\All Users\Application Data\avg8\Log\publog.cfg.install_backup c:\documents and settings\All Users\Application Data\avg8\Log\rslog.cfg.install_backup c:\documents and settings\All Users\Application Data\avg8\Log\scanlog.cfg.install_backup c:\documents and settings\All Users\Application Data\avg8\Log\schedlog.cfg.install_backup c:\documents and settings\All Users\Application Data\avg8\Log\srmlog.cfg.install_backup c:\documents and settings\All Users\Application Data\avg8\Log\updlog.cfg.install_backup c:\documents and settings\All Users\Application Data\avg8\Log\vaultlog.cfg.install_backup c:\documents and settings\All Users\Application Data\avg8\Log\wdlog.cfg.install_backup c:\documents and settings\All Users\Application Data\avg8\Log\wdsvclog.cfg.install_backup c:\documents and settings\All Users\Application Data\avg8\Lsdb\cf.dat.install_backup c:\documents and settings\All Users\Application Data\avg8\Lsdb\ph.dat.install_backup c:\documents and settings\All Users\Application Data\avg8\Lsdb\sb.dat.install_backup c:\documents and settings\All Users\Application Data\avg8\Lsdb\sb.dat.xcd.install_backup c:\documents and settings\All Users\Application Data\avg8\Lsdb\sb2.dat.install_backup c:\documents and settings\All Users\Application Data\avg8\Lsdb\sc.dat.install_backup c:\documents and settings\All Users\Application Data\avg8\Lsdb\sc.dat.xcd.install_backup c:\documents and settings\All Users\Application Data\avg8\scanlogs\I_00000001.log c:\documents and settings\All Users\Application Data\avg8\scanlogs\I_00000005.log c:\documents and settings\All Users\Application Data\avg8\scanlogs\I_00000006.log c:\documents and settings\All Users\Application Data\avg8\scanlogs\I_00000007.log c:\documents and settings\All Users\Application Data\avg8\scanlogs\srm.idx c:\documents and settings\sNipp\Programdata\AVGTOOLBAR c:\program files\AVG c:\program files\AVG\AVG8\aAvgApi.exe c:\program files\AVG\AVG8\avg.snu c:\program files\AVG\AVG8\avg404.txt c:\program files\AVG\AVG8\avg7api.dll c:\program files\AVG\AVG8\avg8us.lng c:\program files\AVG\AVG8\avgabout.dll c:\program files\AVG\AVG8\avgapix.dll c:\program files\AVG\AVG8\avgbat.bav c:\program files\AVG\AVG8\avgcfgex.exe.install_backup c:\program files\AVG\AVG8\avgcfgx.dll c:\program files\AVG\AVG8\avgcmgr.exe c:\program files\AVG\AVG8\avgcorex.dll c:\program files\AVG\AVG8\avgcrlpx.dll c:\program files\AVG\AVG8\avgdumpx.exe.install_backup c:\program files\AVG\AVG8\avgemc.exe c:\program files\AVG\AVG8\avgf8us.chm c:\program files\AVG\AVG8\avgfrw.exe c:\program files\AVG\AVG8\avginet.dll c:\program files\AVG\AVG8\avgiproxy.exe c:\program files\AVG\AVG8\avglngx.dll c:\program files\AVG\AVG8\avglogx.dll c:\program files\AVG\AVG8\avgmail.dll c:\program files\AVG\AVG8\avgmvflx.dll c:\program files\AVG\AVG8\avgmwdef_us.mht c:\program files\AVG\AVG8\avgoff2k.dll c:\program files\AVG\AVG8\avgpp.dll c:\program files\AVG\AVG8\avgresf.dll c:\program files\AVG\AVG8\avgrsx.exe c:\program files\AVG\AVG8\avgscanx.dll c:\program files\AVG\AVG8\avgscanx.exe.install_backup c:\program files\AVG\AVG8\avgsched.dll c:\program files\AVG\AVG8\avgse.dll c:\program files\AVG\AVG8\avgsrmax.exe c:\program files\AVG\AVG8\avgsrmx.dll.install_backup c:\program files\AVG\AVG8\avgssie.dll c:\program files\AVG\AVG8\avgtbapi.dll c:\program files\AVG\AVG8\avgtoolbar.dll c:\program files\AVG\AVG8\avgtray.exe c:\program files\AVG\AVG8\avgui.exe c:\program files\AVG\AVG8\avguiadv.dll c:\program files\AVG\AVG8\avguires.dll c:\program files\AVG\AVG8\avgupd.dll c:\program files\AVG\AVG8\avgupd.exe c:\program files\AVG\AVG8\avgvvx.dll c:\program files\AVG\AVG8\avgwd.dll c:\program files\AVG\AVG8\avgwdsvc.exe c:\program files\AVG\AVG8\avgwdwsc.dll c:\program files\AVG\AVG8\avgxpl.dll c:\program files\AVG\AVG8\contacts_us.html c:\program files\AVG\AVG8\dbghelp.dll c:\program files\AVG\AVG8\dfncfg.dat c:\program files\AVG\AVG8\Firefox\chrome.manifest.install_backup c:\program files\AVG\AVG8\Firefox\Chrome\searchshield.jar.install_backup c:\program files\AVG\AVG8\Firefox\Components\avgssff.dll.install_backup c:\program files\AVG\AVG8\Firefox\Components\ISearchShield.xpt.install_backup c:\program files\AVG\AVG8\Firefox\install.rdf.install_backup c:\program files\AVG\AVG8\fixcfg.exe c:\program files\AVG\AVG8\Icons\background_middle_gray.gif.install_backup c:\program files\AVG\AVG8\Icons\background_middle_green.gif.install_backup c:\program files\AVG\AVG8\Icons\background_middle_orange.gif.install_backup c:\program files\AVG\AVG8\Icons\background_middle_red.gif.install_backup c:\program files\AVG\AVG8\Icons\background_middle_yellow.gif.install_backup c:\program files\AVG\AVG8\Icons\background_top_gray.gif.install_backup c:\program files\AVG\AVG8\Icons\background_top_green.gif.install_backup c:\program files\AVG\AVG8\Icons\background_top_orange.gif.install_backup c:\program files\AVG\AVG8\Icons\background_top_red.gif.install_backup c:\program files\AVG\AVG8\Icons\background_top_yellow.gif.install_backup c:\program files\AVG\AVG8\Icons\block-doc.gif.install_backup c:\program files\AVG\AVG8\Icons\blocked.gif.install_backup c:\program files\AVG\AVG8\Icons\border_bottom_gray.gif.install_backup c:\program files\AVG\AVG8\Icons\border_bottom_green.gif.install_backup c:\program files\AVG\AVG8\Icons\border_bottom_orange.gif.install_backup c:\program files\AVG\AVG8\Icons\border_bottom_red.gif.install_backup c:\program files\AVG\AVG8\Icons\border_bottom_yellow.gif.install_backup c:\program files\AVG\AVG8\Icons\border_top_gray.gif.install_backup c:\program files\AVG\AVG8\Icons\border_top_green.gif.install_backup c:\program files\AVG\AVG8\Icons\border_top_orange.gif.install_backup c:\program files\AVG\AVG8\Icons\border_top_red.gif.install_backup c:\program files\AVG\AVG8\Icons\border_top_yellow.gif.install_backup c:\program files\AVG\AVG8\Icons\box_bottom_red.gif.install_backup c:\program files\AVG\AVG8\Icons\box_top_red.gif.install_backup c:\program files\AVG\AVG8\Icons\caution.gif.install_backup c:\program files\AVG\AVG8\Icons\click_here_gray.gif.install_backup c:\program files\AVG\AVG8\Icons\click_here_green.gif.install_backup c:\program files\AVG\AVG8\Icons\click_here_orange.gif.install_backup c:\program files\AVG\AVG8\Icons\click_here_red.gif.install_backup c:\program files\AVG\AVG8\Icons\click_here_yellow.gif.install_backup c:\program files\AVG\AVG8\Icons\clock.gif.install_backup c:\program files\AVG\AVG8\Icons\close.gif.install_backup c:\program files\AVG\AVG8\Icons\icons_blocked.gif.install_backup c:\program files\AVG\AVG8\Icons\icons_caution.gif.install_backup c:\program files\AVG\AVG8\Icons\icons_close.gif.install_backup c:\program files\AVG\AVG8\Icons\icons_safe.gif.install_backup c:\program files\AVG\AVG8\Icons\icons_unknown.gif.install_backup c:\program files\AVG\AVG8\Icons\icons_warning.gif.install_backup c:\program files\AVG\AVG8\Icons\LS_Logo_Results.gif.install_backup c:\program files\AVG\AVG8\Icons\safe.gif.install_backup c:\program files\AVG\AVG8\Icons\unknown.gif.install_backup c:\program files\AVG\AVG8\Icons\warning.gif.install_backup c:\program files\AVG\AVG8\libsasl.dll c:\program files\AVG\AVG8\license_us.txt c:\program files\AVG\AVG8\saslcrammd5.dll c:\program files\AVG\AVG8\sasldigestmd5.dll c:\program files\AVG\AVG8\sasllogin.dll c:\program files\AVG\AVG8\saslplain.dll c:\program files\AVG\AVG8\setup.cfg c:\program files\AVG\AVG8\setup.dat c:\program files\AVG\AVG8\setup.exe c:\program files\AVG\AVG8\setupus.lns c:\program files\AVG\AVG8\ToolbarFF\chrome.manifest.install_backup c:\program files\AVG\AVG8\ToolbarFF\Chrome\avg.jar.install_backup c:\program files\AVG\AVG8\ToolbarFF\Chrome\Cache\overlay.dtd.install_backup c:\program files\AVG\AVG8\ToolbarFF\Chrome\Cache\overlay.xml.install_backup c:\program files\AVG\AVG8\ToolbarFF\Chrome\Cache\overlay_noavg.xml.install_backup c:\program files\AVG\AVG8\ToolbarFF\Chrome\Cache\quicksearch.xml.install_backup c:\program files\AVG\AVG8\ToolbarFF\Chrome\Cache\update.xml.install_backup c:\program files\AVG\AVG8\ToolbarFF\Chrome\Cache\yahoo.xml.install_backup c:\program files\AVG\AVG8\ToolbarFF\Components\dtfox-autocomplete.js.install_backup c:\program files\AVG\AVG8\ToolbarFF\Components\dtfox-service.js.install_backup c:\program files\AVG\AVG8\ToolbarFF\Components\vmAVGConnector.dll.install_backup c:\program files\AVG\AVG8\ToolbarFF\Components\vmIAVGConnector.xpt.install_backup c:\program files\AVG\AVG8\ToolbarFF\Components\vmIAVGDatabaseVersion.xpt.install_backup c:\program files\AVG\AVG8\ToolbarFF\Components\vmIAVGProgramVersion.xpt.install_backup c:\program files\AVG\AVG8\ToolbarFF\Components\vmIAVGSearchRatingsConfig.xpt.install_backup c:\program files\AVG\AVG8\ToolbarFF\Components\vmIAVGSurfResult.xpt.install_backup c:\program files\AVG\AVG8\ToolbarFF\install.rdf.install_backup c:\program files\AVG\AVG8\ToolbarIEcache\avglinks.bmp.install_backup c:\program files\AVG\AVG8\ToolbarIEcache\avglogo.bmp.install_backup c:\program files\AVG\AVG8\ToolbarIEcache\avgstatus.bmp.install_backup c:\program files\AVG\AVG8\ToolbarIEcache\avgstatus_error.bmp.install_backup c:\program files\AVG\AVG8\ToolbarIEcache\avgtoolbartb0502.cfg.install_backup c:\program files\AVG\AVG8\ToolbarIEcache\brandlogo.bmp.install_backup c:\program files\AVG\AVG8\ToolbarIEcache\p_yahoo.bmp.install_backup c:\program files\AVG\AVG8\ToolbarIEcache\safesearch.bmp.install_backup c:\program files\AVG\AVG8\ToolbarIEcache\safesearch_off.bmp.install_backup c:\program files\AVG\AVG8\ToolbarIEcache\safesearch_on.bmp.install_backup c:\program files\AVG\AVG8\ToolbarIEcache\safesurf.bmp.install_backup c:\program files\AVG\AVG8\ToolbarIEcache\safesurf_off.bmp.install_backup c:\program files\AVG\AVG8\ToolbarIEcache\safesurf_on.bmp.install_backup c:\program files\AVG\AVG8\ToolbarIEcache\slider.bmp.install_backup c:\program files\AVG\AVG8\updatecomps.cfg c:\program files\Common Files\Symantec Shared c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll c:\windows\system32\avgrsstx.dll c:\windows\system32\drivers\Avg c:\windows\system32\drivers\Avg\avi7.avg c:\windows\system32\drivers\Avg\incavi.avm c:\windows\system32\drivers\Avg\microavi.avg c:\windows\system32\drivers\Avg\miniavi.avg c:\windows\system32\drivers\avgldx86.sys\ c:\windows\system32\drivers\avgtdix.sys\ . ((((((((((((((((((((((((((((((((((((((( Drivere/Tjenester ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_AVG8WD -------\Legacy_AVGLDX86 -------\Legacy_AVGTDIX -------\Service_avg8wd -------\Service_AvgLdx86 -------\Service_AvgTdiX ((((((((((((((((((((((((((( Filer Opprettet Fra 2009-01-07 til 2009-02-07 ))))))))))))))))))))))))))))))))) . 2009-02-07 00:01 . 2009-02-07 00:01 <DIR> d-------- c:\windows\Internet Logs 2009-02-06 18:36 . 2009-02-06 18:36 <DIR> d-------- c:\documents and settings\sNipp\Programdata\Malwarebytes 2009-02-06 18:31 . 2009-02-06 18:31 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware 2009-02-06 18:31 . 2009-02-06 18:31 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-02-06 18:31 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-06 18:31 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2009-02-06 16:34 . 2009-02-06 16:34 <DIR> d-------- c:\documents and settings\sNipp\DoctorWeb 2009-02-06 16:18 . 2009-02-06 16:18 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys 2009-02-06 16:18 . 2009-02-06 16:18 76,040 --a------ c:\windows\system32\drivers\avgtdix.sys 2009-02-06 12:29 . 2009-02-06 12:29 268 --ah----- C:\sqmdata01.sqm 2009-02-06 12:29 . 2009-02-06 12:29 244 --ah----- C:\sqmnoopt01.sqm 2009-02-06 12:16 . 2009-02-06 12:16 664 --a------ c:\windows\system32\d3d9caps.dat 2009-02-06 12:02 . 2009-02-06 12:02 268 --ah----- C:\sqmdata00.sqm 2009-02-06 12:02 . 2009-02-06 12:02 244 --ah----- C:\sqmnoopt00.sqm 2009-02-06 12:01 . 2009-02-06 23:48 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP 2009-02-06 12:01 . 2005-08-25 19:18 118,784 --a------ c:\windows\system32\MSSTDFMT.DLL 2009-02-06 12:00 . 2009-02-06 23:48 <DIR> d-------- c:\program files\SpywareBlaster . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-18 16:33 --------- d-----w c:\documents and settings\sNipp\Programdata\uTorrent 2008-12-17 18:12 --------- d-----w c:\program files\Xfire 2008-12-16 18:13 --------- d-----w c:\documents and settings\sNipp\Programdata\AdobeUM 2008-12-15 23:23 --------- d-----w c:\documents and settings\sNipp\Programdata\Xfire 2008-12-15 14:56 --------- d-----w c:\documents and settings\sNipp\Programdata\dvdcss 2008-12-15 14:28 --------- d-----w c:\documents and settings\sNipp\Programdata\Ventrilo 2008-12-15 14:23 --------- dc-h--w c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185} 2008-12-15 12:58 --------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2 2008-12-13 21:03 --------- d-----w c:\program files\Windows Live 2008-12-13 21:00 --------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller 2008-12-13 20:59 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller 2008-12-11 17:10 --------- d-----w c:\documents and settings\sNipp\Programdata\vlc 2008-12-11 17:09 --------- d-----w c:\program files\VideoLAN 2008-12-08 15:35 --------- d-----w c:\program files\Ventrilo 2008-12-08 15:35 --------- d-----w c:\program files\Common Files\Wise Installation Wizard . ((((((((((((((((((((((((((((( SnapShot@2009-02-07_ 0.36.36,70 ))))))))))))))))))))))))))))))))))))))))) . + 2005-10-20 19:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE . (((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret ))))))))))))))))))))))))))))))))))))))))))))) . . *Merk* tomme oppføringer & gyldige standardoppføringer vises ikke REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184] "Google Update"="c:\documents and settings\sNipp\Lokale innstillinger\Programdata\Google\Update\GoogleUpdate.exe" [2008-12-15 133104] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-07-20 7581696] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-16 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.XFR1"= xfcodec.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Hurtigstart.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Hurtigstart.lnk backup=c:\windows\pss\HP Photosmart Premier Hurtigstart.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Hurtigstart for Adobe Reader.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Hurtigstart for Adobe Reader.lnk backup=c:\windows\pss\Hurtigstart for Adobe Reader.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^sNipp^Start Menu^Programs^StartUp^Xfire.lnk] path=c:\documents and settings\sNipp\Start Menu\Programs\StartUp\Xfire.lnk backup=c:\windows\pss\Xfire.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset] --a------ 2006-06-19 09:50 40960 c:\program files\Hewlett-Packard\Default Settings\Cpqset.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] --a------ 2006-03-16 05:00 15360 c:\windows\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray] --a------ 2005-08-05 20:56 64512 c:\windows\ehome\ehtray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] --a------ 2005-02-16 22:11 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant] --a------ 2006-05-03 21:58 458752 c:\program files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] --a------ 2006-07-20 06:58 7581696 c:\windows\system32\nvcpl.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] --a------ 2006-07-20 06:58 86016 c:\windows\system32\nvmctray.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl] --a------ 2006-06-19 10:33 163840 c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService] --a------ 2006-07-19 14:14 102400 c:\program files\HP\QuickPlay\QPService.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecGuard] --a------ 2005-10-11 09:23 1187840 c:\windows\SMINST\Recguard.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2005-11-10 20:03 36975 c:\program files\Java\jre1.5.0_06\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] --a------ 2006-06-17 06:22 794713 c:\program files\Synaptics\SynTP\SynTPEnh.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut] --a------ 2006-06-02 16:02 61952 c:\windows\system32\CHDAudPropShortcut.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsmqIntCert] --a------ 2006-03-16 05:00 177152 c:\windows\system32\mqrt.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] --a------ 2006-07-20 06:58 1519616 c:\windows\system32\nwiz.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\WINDOWS\\system32\\mqsvc.exe"= "c:\\Program Files\\Xfire\\Xfire.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Ventrilo\\Ventrilo.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= R3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [2006-06-06 61952] S2 cdralw;NVIDIA Compatible Windows Miniport Driver;c:\windows\system32\DRIVERS\nvmini.sys --> c:\windows\system32\DRIVERS\nvmini.sys [?] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cf8e62f9-c53d-11dd-acf7-001636b91feb}] \Shell\AutoRun\command - WD_Windows_Tools\Setup.exe . Innholdet i mappen 'Scheduled Tasks' (planlagte oppgaver) 2009-02-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-985822856-2524474350-2388280304-1005.job - c:\documents and settings\sNipp\Lokale innstillinger\Programdata\Google\Update\GoogleUpdate.exe [2008-12-15 20:25] 2009-01-09 c:\windows\Tasks\Internett-tjenester.job - c:\program files\Hewlett-Packard\SDP\HPSdpApp.exe [2005-09-08 11:23] . . ------- Tilleggsskanning ------- . uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=NB_NO&c=64&bd=pavilion&pf=laptop uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=NB_NO&c=64&bd=pavilion&pf=laptop IE: &Google-søk - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html IE: &Oversett engelsk ord - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html IE: Koblinger bakover - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html IE: Lignende sider - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html IE: Øyeblikksbilde av siden i hurtigbufferen - c:\program files\Google\GoogleToolbar1.dll/cmcache.html FF - ProfilePath - c:\documents and settings\sNipp\Programdata\Mozilla\Firefox\Profiles\rpzlaqr8.default\ FF - plugin: c:\documents and settings\sNipp\Lokale innstillinger\Programdata\Google\Update\1.2.133.33\npGoogleOneClick7.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".no"); . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-07 01:01:11 Windows 5.1.2600 Service Pack 2 NTFS skanner skjulte prosesser ... skanner skjulte autostart-oppføringer ... skanner skjulte filer ... skanning vellykket skjulte filer: 0 ************************************************************************** . ------------------------ Andre Kjørende Prosesser ------------------------ . c:\windows\system32\msdtc.exe c:\windows\ehome\ehrecvr.exe c:\windows\ehome\ehSched.exe c:\program files\Common Files\LightScribe\LSSrvc.exe c:\windows\system32\nvsvc32.exe c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe c:\windows\ehome\mcrdsvc.exe c:\windows\system32\mqsvc.exe c:\windows\system32\mqtgsvc.exe c:\windows\system32\dllhost.exe c:\program files\Windows Live\Messenger\usnsvc.exe c:\windows\system32\wscntfy.exe . ************************************************************************** . Tidspunkt ferdig: 2009-02-07 1:03:15 - maskinen ble startet på nytt ComboFix-quarantined-files.txt 2009-02-07 00:03:12 ComboFix2.txt 2009-02-06 23:37:19 ComboFix3.txt 2009-02-06 22:44:05 Pre-Run: 9 493 082 112 bytes free Post-Run: 9,419,100,160 byte ledig 432 --- E O F --- 2009-01-09 17:55:34 Tusen takk! Lenke til kommentar
Anbefalte innlegg
Opprett en konto eller logg inn for å kommentere
Du må være et medlem for å kunne skrive en kommentar
Opprett konto
Det er enkelt å melde seg inn for å starte en ny konto!
Start en kontoLogg inn
Har du allerede en konto? Logg inn her.
Logg inn nå