Gå til innhold

Virus? teksmelding på youtube.


Anbefalte innlegg

Skrev inn www.youtube.com i adressefeltet.

Da siden dukket opp stod følgende tekst helt øverst på siden:

<!-- machid: ZARg7-aAGviec4ueInc--yrA_HH230wW3Ul_1xNa81ysY08s0VuOqg -->

 

Er dette noen form for virus/spy ware?

 

NB! Bruker firefox.

 

Edit: Refererer VuOgg til en videofil kanskje?

Endret av JFTech
Lenke til kommentar
Videoannonse
Annonse

Malwarebytes' log:

 

Malwarebytes' Anti-Malware 1.34

Databaseversjon: 1795

Windows 6.0.6001 Service Pack 1

 

23.02.2009 07:16:59

mbam-log-2009-02-23 (07-16-59).txt

 

Skanntype: Rask Skann

Objekter skannet: 57879

Tid tilbakelagt: 2 minute(s), 58 second(s)

 

Minneprosesser infisert: 0

Minnemoduler infisert: 0

Registernøkler infisert: 0

Registerverdier infisert: 0

Registerfiler infisert: 0

Mapper infisert: 0

Filer infisert: 0

 

Minneprosesser infisert:

(Ingen mistenkelige filer funnet)

 

Minnemoduler infisert:

(Ingen mistenkelige filer funnet)

 

Registernøkler infisert:

(Ingen mistenkelige filer funnet)

 

Registerverdier infisert:

(Ingen mistenkelige filer funnet)

 

Registerfiler infisert:

(Ingen mistenkelige filer funnet)

 

Mapper infisert:

(Ingen mistenkelige filer funnet)

 

Filer infisert:

(Ingen mistenkelige filer funnet)

 

 

 

Combofixes log:

 

ComboFix 09-02-21.01 - bgates 2009-02-23 7:32:04.1 - NTFSx86

Microsoft® Windows Vista™ Business 6.0.6001.1.1252.1.1044.18.2030.983 [GMT 1:00]

Kjører fra: c:\users\bgates\Desktop\ComboFix.exe

FW: COMODO Firewall *enabled*

.

 

((((((((((((((((((((((((((( Filer Opprettet Fra 2009-01-23 til 2009-02-23 )))))))))))))))))))))))))))))))))

.

 

2009-02-23 07:12 . 2009-02-23 07:12 <DIR> d-------- c:\users\bgates\AppData\Roaming\Malwarebytes

2009-02-23 07:12 . 2009-02-23 07:12 <DIR> d-------- c:\users\All Users\Malwarebytes

2009-02-23 07:12 . 2009-02-23 07:12 <DIR> d-------- c:\programdata\Malwarebytes

2009-02-23 07:12 . 2009-02-23 07:12 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware

2009-02-23 07:12 . 2009-02-11 10:19 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys

2009-02-23 07:12 . 2009-02-11 10:19 15,504 --a------ c:\windows\System32\drivers\mbam.sys

2009-02-23 00:37 . 2009-02-23 00:37 <DIR> d-------- c:\windows\CtDrvInstall

2009-02-23 00:37 . 2009-02-23 00:54 <DIR> d-------- C:\WebCam

2009-02-22 04:24 . 2009-02-22 04:26 <DIR> d-------- c:\users\bgates\AppData\Roaming\Python-Eggs

2009-02-22 04:24 . 2009-02-22 04:30 <DIR> d-------- c:\users\bgates\.elisa-0.5

2009-02-18 23:42 . 2009-02-18 23:42 <DIR> d-------- c:\users\bgates\AppData\Roaming\Thunderbird

2009-02-18 23:42 . 2009-02-22 18:46 <DIR> d-------- c:\program files\Mozilla Thunderbird

2009-02-18 10:02 . 2009-02-18 10:02 <DIR> d-------- c:\program files\MSECache

2009-02-12 01:06 . 2009-01-15 04:36 1,383,424 --a------ c:\windows\System32\mshtml.tlb

2009-02-12 01:06 . 2009-01-15 07:11 827,392 --a------ c:\windows\System32\wininet.dll

2009-02-06 18:52 . 2009-02-06 18:52 49,504 --a------ c:\windows\System32\sirenacm.dll

2009-01-30 17:50 . 2008-06-20 02:14 781,344 --a------ c:\windows\System32\PresentationNative_v0300.dll

2009-01-30 17:50 . 2008-06-20 02:14 622,080 --a------ c:\windows\System32\icardagt.exe

2009-01-30 17:50 . 2008-06-20 02:14 326,160 --a------ c:\windows\System32\PresentationHost.exe

2009-01-30 17:50 . 2008-06-20 02:14 105,016 --a------ c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll

2009-01-30 17:50 . 2008-06-20 02:14 97,800 --a------ c:\windows\System32\infocardapi.dll

2009-01-30 17:50 . 2008-06-20 02:14 43,544 --a------ c:\windows\System32\PresentationHostProxy.dll

2009-01-30 17:50 . 2008-06-20 02:14 37,384 --a------ c:\windows\System32\infocardcpl.cpl

2009-01-30 17:50 . 2008-06-20 02:14 11,264 --a------ c:\windows\System32\icardres.dll

2009-01-30 17:45 . 2008-07-27 19:03 282,112 --a------ c:\windows\System32\mscoree.dll

2009-01-30 17:45 . 2008-07-27 19:03 158,720 --a------ c:\windows\System32\mscorier.dll

2009-01-30 17:45 . 2008-07-27 19:03 96,760 --a------ c:\windows\System32\dfshim.dll

2009-01-30 17:45 . 2008-07-27 19:03 83,968 --a------ c:\windows\System32\mscories.dll

2009-01-30 17:45 . 2008-07-27 19:03 41,984 --a------ c:\windows\System32\netfxperf.dll

2009-01-27 01:17 . 2009-01-27 01:17 <DIR> d-------- c:\users\bgates\AppData\Roaming\Songbird2

2009-01-27 01:16 . 2009-01-27 01:16 <DIR> d-------- c:\users\All Users\SongbirdVLC

2009-01-27 01:16 . 2009-01-27 01:16 <DIR> d-------- c:\programdata\SongbirdVLC

2009-01-27 01:16 . 2009-01-27 01:18 <DIR> d-------- c:\program files\Songbird

2009-01-26 17:20 . 2009-01-26 17:20 <DIR> d-------- c:\windows\solcache

2009-01-26 17:20 . 1998-06-10 13:07 1,053,184 --a------ c:\windows\System32\SierraNW.dll

2009-01-26 17:20 . 1997-09-18 00:00 490,256 --a------ c:\windows\System32\Oleaut32.1

2009-01-26 17:20 . 1998-06-10 13:05 231,936 --a------ c:\windows\System32\SNWValid.dll

2009-01-26 17:20 . 1997-07-14 14:57 11,104 --a------ c:\windows\System32\Snwvalid.hlp

2009-01-26 17:17 . 2009-01-26 17:20 <DIR> d-------- C:\SIERRA

2009-01-26 17:17 . 2009-01-26 17:20 <DIR> d-------- c:\program files\Sierra On-Line

2009-01-26 17:16 . 1998-01-23 12:22 304,128 --a------ c:\windows\IsUninst.exe

2009-01-26 17:16 . 2009-01-26 17:20 461 --a------ c:\windows\SIERRA.INI

2009-01-25 19:59 . 2009-01-25 19:59 <DIR> d-------- c:\program files\FLAC

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-02-23 06:51 78,454 ----a-w c:\users\All Users\nvModes.dat

2009-02-23 06:51 78,454 ----a-w c:\programdata\nvModes.dat

2009-02-23 01:09 --------- d-----w c:\programdata\Google Updater

2009-02-22 20:29 28,688 ----a-w c:\windows\system32\drivers\cmdhlp.sys

2009-02-22 18:18 --------- d-----w c:\programdata\comodo

2009-02-22 18:12 155,384 ----a-w c:\windows\System32\guard32.dll

2009-02-22 18:12 108,560 ----a-w c:\windows\system32\drivers\cmdguard.sys

2009-02-12 00:06 --------- d-----w c:\program files\Windows Mail

2009-02-04 16:49 --------- d-----w c:\users\bgates\AppData\Roaming\Move Networks

2009-01-22 21:12 64,160 ----a-w c:\windows\system32\drivers\Lbd.sys

2009-01-22 21:12 15,688 ----a-w c:\windows\System32\lsdelete.exe

2009-01-22 21:12 --------- d-----w c:\programdata\Lavasoft

2009-01-22 21:10 --------- dc-h--w c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}

2009-01-22 21:10 --------- d-----w c:\program files\Lavasoft

2009-01-22 16:19 --------- d-----r c:\users\bgates\AppData\Roaming\Brother

2009-01-16 01:09 --------- d-----w c:\users\bgates\AppData\Roaming\vlc

2009-01-14 16:26 --------- d-----w c:\programdata\NVIDIA

2009-01-13 22:20 --------- d-----w c:\program files\Windows Live SkyDrive

2009-01-13 22:20 --------- d-----w c:\program files\Windows Live

2009-01-13 22:20 --------- d-----w c:\program files\Microsoft

2009-01-13 22:17 --------- d-----w c:\program files\Common Files\Windows Live

2009-01-13 20:42 --------- d-----w c:\users\bgates\AppData\Roaming\Foxit

2009-01-13 15:19 --------- d-----w c:\program files\Alex Feinman

2009-01-13 14:28 --------- d-----w c:\users\bgates\AppData\Roaming\Canneverbe_Limited

2009-01-11 22:29 52,838 ----a-w c:\users\bgates\AppData\Roaming\nvModes.dat

2009-01-11 22:08 --------- d-----w c:\program files\Windows Journal

2009-01-11 18:09 --------- d-----w c:\users\bgates\AppData\Roaming\Download Manager

2009-01-11 01:11 --------- d-----w c:\program files\Google

2009-01-09 17:55 --------- d-----w c:\program files\MetaGeek

2008-12-28 00:36 --------- d-----w c:\program files\Lenovo

2008-12-28 00:36 --------- d-----w c:\program files\Common Files\Lenovo

2008-12-26 16:06 --------- d-----w c:\program files\DivX

2008-12-21 20:46 410,984 ----a-w c:\windows\System32\deploytk.dll

2008-06-24 22:39 174 --sha-w c:\program files\desktop.ini

.

 

(((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret )))))))))))))))))))))))))))))))))))))))))))))

.

.

*Merk* tomme oppføringer & gyldige standardoppføringer vises ikke

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885400]

"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-03-24 68464]

"PWMTRV"="c:\progra~1\ThinkPad\UTILIT~1\PWMTR32V.DLL" [2008-09-25 632096]

"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BTVLogEx.DLL" [2008-09-25 214576]

"LenovoOobeOffers"="c:\swtools\LenovoWelcome\LenovoOobeOffers.exe" [2006-12-29 28672]

"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-11-22 820520]

"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-07-10 1282048]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-21 136600]

"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-18 266497]

"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" [2009-02-22 1850616]

"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]

"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-10-11 29984]

"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-10-11 46368]

"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]

"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2008-02-19 1089536]

"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-12-21 86016]

"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 487424]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-09 13543968]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-09 92704]

"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-01-29 509784]

"COMODO Internet Security"="c:\program files\COMODO\Firewall\cfp.exe" [2009-02-22 1850616]

"TpShocks"="TpShocks.exe" [2007-03-29 c:\windows\System32\TpShocks.exe]

 

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

BTTray.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2007-03-29 719664]

Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-10-20 50688]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"DisableCAD"= 1 (0x1)

"EnableUIADesktopToggle"= 0 (0x0)

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2008-08-26 21:01 352256 c:\program files\SUPERAntiSpyware\SASWINLO.DLL

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]

2007-03-14 21:17 89600 c:\windows\System32\psqlpwd.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Notification Packages REG_MULTI_SZ scecli psqlpwd ACGina

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{625AB171-CD24-44F2-B6DB-5B7F72DDA632}"= UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA

"{66EBAE38-EC23-4B49-BAFE-CD7A6FD02C99}"= TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA

"{FFBFEB1E-6CB7-48BF-A83D-835420C56663}"= UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB

"{DD194550-3FB6-45ED-A764-A396970ADD35}"= TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB

"{82666D66-B21F-49D5-83C2-ABEE9F1B8EF6}"= TCP:54925:BrotherNetwork Scanner

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]

"EnableFirewall"= 0 (0x0)

 

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [2009-01-22 64160]

R0 Shockprf;Shockprf;c:\windows\System32\drivers\ApsX86.sys [2007-03-02 100656]

R0 TPDIGIMN;TPDIGIMN;c:\windows\System32\drivers\ApsHM86.sys [2007-03-02 19760]

R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\System32\drivers\cmdguard.sys [2008-07-16 108560]

R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\System32\drivers\cmdhlp.sys [2008-07-16 28688]

R1 lenovo.smi;Lenovo System Interface Driver;c:\windows\System32\drivers\smiif32.sys [2008-05-12 13480]

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2008-05-28 8944]

R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2008-05-28 55024]

R1 TPPWRIF;TPPWRIF;c:\windows\System32\drivers\TPPWR32V.SYS [2007-10-20 12080]

R2 BRA_Scheduler;Brother BRAdminPro Scheduler;c:\program files\Brother\BRAdmin Professional 3\bratimer.exe [2008-10-10 65536]

R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]

R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2006-04-14 28933976]

R2 Power Manager DBC Service;Power Manager DBC Service;c:\program files\ThinkPad\Utilities\PWMDBSVC.exe [2008-10-27 66848]

R2 smihlp;SMI Helper Driver (smihlp);c:\program files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [2007-03-14 11152]

R2 TPHKSVC;Visning på skjermen;c:\program files\Lenovo\HOTKEY\TPHKSVC.exe [2007-07-09 58736]

R3 TVTI2C;Lenovo SM bus driver;c:\windows\System32\drivers\tvti2c.sys [2006-09-13 35264]

R3 WSDPrintDevice;WSD-utskriftsstøtte via UMB;c:\windows\System32\drivers\WSDPrint.sys [2008-06-24 16896]

S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [2006-11-02 167936]

S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-05-28 7408]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

bthsvcs REG_MULTI_SZ BthServ

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{934ecea7-7eaf-11dc-b675-806e6f6e6963}]

\shell\AutoRun\command - D:\autorun.exe

.

Innholdet i mappen 'Scheduled Tasks' (planlagte oppgaver)

 

2009-02-05 c:\windows\Tasks\Ad-Aware Update (Weekly).job

- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-02 22:12]

 

2009-02-23 c:\windows\Tasks\Google Software Updater.job

- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-11 02:09]

 

2009-02-23 c:\windows\Tasks\User_Feed_Synchronization-{7FB51E8E-F57E-4D8A-916A-1207E2509139}.job

- c:\windows\system32\msfeedssync.exe [2008-01-19 08:33]

.

.

------- Tilleggsskanning -------

.

uStart Page = hxxp://www.google.no/

DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.2.cab

FF - ProfilePath - c:\users\bgates\AppData\Roaming\Mozilla\Firefox\Profiles\8at0zbr6.default\

FF - component: c:\users\bgates\AppData\Roaming\Mozilla\Firefox\Profiles\8at0zbr6.default\extensions\[email protected]\platform\WINNT_x86-msvc\components\ubiquity.dll

FF - plugin: c:\program files\Google\Google Updater\2.4.1441.4352\npCIDetect13.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll

FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll

FF - plugin: c:\program files\Opera\program\plugins\npFoxitReaderPlugin.dll

 

---- FIREFOX POLICIES ----

c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".no");

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-02-23 07:51:50

Windows 6.0.6001 Service Pack 1 NTFS

 

detected NTDLL code modification:

ZwClose, ZwOpenFile

 

skanner skjulte prosesser ...

 

skanner skjulte autostart-oppføringer ...

 

skanner skjulte filer ...

 

 

c:\users\bgates\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt 65 bytes

c:\users\bgates\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt 64 bytes

c:\users\bgates\AppData\Roaming\Microsoft\Windows\Cookies\bgates@msn[2].txt 300 bytes

 

skanning vellykket

skjulte filer: 3

 

**************************************************************************

.

--------------------- DLL'er Lastet Av Kjørende Prosesser ---------------------

 

- - - - - - - > 'winlogon.exe'(1344)

c:\windows\system32\guard32.dll

 

- - - - - - - > 'lsass.exe'(680)

c:\windows\system32\guard32.dll

c:\windows\system32\psqlpwd.dll

c:\program files\ThinkVantage Fingerprint Software\homefus2.dll

c:\program files\ThinkVantage Fingerprint Software\infra.dll

 

- - - - - - - > 'Explorer.exe'(5244)

c:\windows\system32\guard32.dll

c:\windows\system32\btmmhook.dll

.

------------------------ Andre Kjørende Prosesser ------------------------

.

c:\windows\System32\ibmpmsvc.exe

c:\windows\System32\nvvsvc.exe

c:\program files\COMODO\Firewall\cmdagent.exe

c:\windows\System32\audiodg.exe

c:\windows\System32\rundll32.exe

c:\program files\ThinkVantage Fingerprint Software\upeksvr.exe

c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe

c:\windows\System32\AEADISRV.EXE

c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe

c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe

c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe

c:\windows\System32\TPHDEXLG.exe

c:\program files\Common Files\Lenovo\Scheduler\tvtsched.exe

c:\windows\System32\drivers\XAudio.exe

c:\program files\Lenovo\System Update\SUService.exe

c:\windows\System32\wbem\unsecapp.exe

c:\windows\System32\conime.exe

c:\windows\System32\rundll32.exe

c:\program files\Lenovo\HOTKEY\TPONSCR.exe

c:\program files\Lenovo\ZOOM\TpScrex.exe

c:\program files\Synaptics\SynTP\SynTPLpr.exe

c:\windows\System32\rundll32.exe

c:\program files\Brother\ControlCenter3\BrccMCtl.exe

c:\program files\Brother\Brmfcmon\BrMfimon.exe

c:\program files\Windows Media Player\wmpnetwk.exe

c:\program files\ThinkPad\Utilities\PWMUIAux.EXE

c:\windows\System32\dllhost.exe

.

**************************************************************************

.

Tidspunkt ferdig: 2009-02-23 7:58:23 - maskinen ble startet på nytt

ComboFix-quarantined-files.txt 2009-02-23 06:58:13

 

Pre-Run: 131 329 855 488 byte ledig

Post-Run: 131,395,932,160 byte ledig

 

262 --- E O F --- 2009-02-20 16:08:48

 

 

Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
×
×
  • Opprett ny...