BendItLikeBender Skrevet 6. august 2009 Del Skrevet 6. august 2009 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:12:46, on 06.08.2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Programfiler\Java\jre6\bin\jusched.exe C:\Programfiler\Logitech\G-series Software\LGDCore.exe C:\Programfiler\Logitech\G-series Software\LCDMon.exe C:\Programfiler\MSI\Live Update 3\LMonitor.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\system32\RunDLL32.exe C:\WINDOWS\SOUNDMAN.EXE C:\Programfiler\Logitech\G-series Software\Applets\LCDClock.exe C:\Programfiler\Logitech\G-series Software\Applets\LCDMedia.exe C:\WINDOWS\system32\ctfmon.exe D:\Steam\Steam.exe C:\Programfiler\Creative\Shared Files\CamTray.exe C:\Programfiler\Windows Live\Messenger\msnmsgr.exe C:\Programfiler\Skype\Phone\Skype.exe C:\Programfiler\Messenger\msmsgs.exe C:\Programfiler\Logitech\SetPoint\SetPoint.exe C:\Programfiler\Fellesfiler\Logitech\KhalShared\KHALMNPR.EXE F:\Hamachi\hamachi.exe C:\Programfiler\Skype\Plugin Manager\skypePM.exe C:\WINDOWS\ATKKBService.exe C:\Programfiler\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\Programfiler\Windows Live\Contacts\wlcomm.exe F:\Mozilla Firefox\firefox.exe C:\Programfiler\Skype\Toolbars\Shared\SkypeNames.exe F:\Spotify\spotify.exe F:\VideoLAN\vlc.exe F:\uTorrent\uTorrent.exe C:\Documents and Settings\All Users\Skrivebord\Hijackthis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://tw.msi.com.tw/autobios/VerChk/LSeri...nction=LMonitor R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programfiler\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programfiler\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [GameFace Messenger] C:\Programfiler\GameFace Messenger\GameFace.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Adobe Reader\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [Launch LGDCore] "C:\Programfiler\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE O4 - HKLM\..\Run: [Launch LCDMon] "C:\Programfiler\Logitech\G-series Software\LCDMon.exe" O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [LiveMonitor] C:\Programfiler\MSI\Live Update 3\LMonitor.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [VF0060 STISvc] RunDLL32.exe V0060Pin.dll,RunDLL32EP 513 O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [steam] "D:\Steam\Steam.exe" -silent O4 - HKCU\..\Run: [Creative WebCam Tray] C:\Programfiler\Creative\Shared Files\CamTray.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [skype] "C:\Programfiler\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [DAEMON Tools Lite] F:\Daemon Tools\DAEMON Tools Lite\daemon.exe -autorun O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\msmsgs.exe" /background O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: hamachi.lnk = F:\Hamachi\hamachi.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Programfiler\Logitech\SetPoint\SetPoint.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock...ash/swflash.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FELLES~1\Skype\SKYPE4~1.DLL O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programfiler\Java\jre6\bin\jqs.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe Takk for svar på forhånd Lenke til kommentar
Svenni212000 Skrevet 6. august 2009 Del Skrevet 6. august 2009 Jeg har ikke noe med det, men hvorfor har du programmene spredt overalt? - kjenner jeg ikke til GameFace, men slike programmer pleier ofte å være ulumske. [VF0060 STISvc] RunDLL32.exe kan være infisert, dog antaglivis fra en sikker kilde. Tilhører antaglivis Creative Cam. - Du har også mange programmer som ikke trenger å starte sammen med Windows: ¤ nwiz.exe ¤ GameFace.exe ¤ Reader_sl.exe ¤ jusched.exe ¤ LGDCore.exe (?) ¤ LCDMon.exe (?) ¤ KHALMNPR.EXE (?) ¤ LMonitor.exe ¤ NvMcTray.dll ¤ dumprep 0 -k ¤ SOUNDMAN.EXE ¤ ctfmon.exe ¤ Steam.exe ¤ CamTray.exe ¤ msnmsgr.exe ¤ Skype.exe ¤ daemon.exe (?) ¤ SetPoint.exe (?) PS: Prosessor merket med (?) bør du være forsiktig med å deaktivere, les først gjennom og se om du benytter deg av dens funksjoner før du deaktivcerer disse. De andre kan du trygt deaktivere fra oppstart uten noe fare, og er høyst anbefalt fra min side, det vil frigjør en del systemressurser. Du kan bruke CCleaner for å enkelt aktivere/deaktivere disse oppstartsprosessene PPS: Du kan for at vi skal være mer sikkre, kjøre MBAM og poste loggen her i denne tråden. https://www.diskusjon.no/index.php?showtopic=691246 Lenke til kommentar
BendItLikeBender Skrevet 6. august 2009 Forfatter Del Skrevet 6. august 2009 (endret) Har mange partisjoner, liker å ha det ryddig MBAM Klikk for å se/fjerne innholdet nedenfor Malwarebytes' Anti-Malware 1.40Databaseversjon: 2571 Windows 5.1.2600 Service Pack 3 06.08.2009 21:00:02 mbam-log-2009-08-06 (21-00-02).txt Skanntype: Rask Skann Objekter skannet: 83699 Tid tilbakelagt: 3 minute(s), 20 second(s) Minneprosesser infisert: 0 Minnemoduler infisert: 0 Registernøkler infisert: 1 Registerverdier infisert: 0 Registerfiler infisert: 0 Mapper infisert: 0 Filer infisert: 1 Minneprosesser infisert: (Ingen mistenkelige filer funnet) Minnemoduler infisert: (Ingen mistenkelige filer funnet) Registernøkler infisert: HKEY_CLASSES_ROOT\CLSID\{58101905-d80f-4788-96f6-986a8186178a} (Trojan.Agent) -> Quarantined and deleted successfully. Registerverdier infisert: (Ingen mistenkelige filer funnet) Registerfiler infisert: (Ingen mistenkelige filer funnet) Mapper infisert: (Ingen mistenkelige filer funnet) Filer infisert: C:\WINDOWS\system32\flashd32.dll (Trojan.Agent) -> Quarantined and deleted successfully. Combofix Klikk for å se/fjerne innholdet nedenfor ComboFix 09-08-04.04 - Clinkz 06.08.2009 21:02.1.2 - NTFSx86Microsoft Windows XP Home Edition 5.1.2600.3.1252.47.1044.18.2047.1284 [GMT 2:00] Kjører fra: c:\documents and settings\Clinkz\Skrivebord\ComboFix.exe ADVARSEL -DENNE MASKINEN HAR IKKE GJENOPPRETTINGSKONSOLLEN INSTALLERT !! . ((((((((((((((((((((((((((((((((((((((( Andre slettinger ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\Drivers\krso.sys . ((((((((((((((((((((((((((((((((((((((( Drivere/Tjenester ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_wprpg ((((((((((((((((((((((((((( Filer Opprettet Fra 2009-07-06 til 2009-08-06 ))))))))))))))))))))))))))))))))) . 2009-08-06 18:52 . 2009-08-06 18:52 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Malwarebytes 2009-08-06 18:52 . 2009-08-03 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-06 18:52 . 2009-08-06 18:52 -------- d-----w- c:\documents and settings\All Users\Programdata\Malwarebytes 2009-08-06 18:52 . 2009-08-03 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-08-05 19:55 . 2009-08-05 19:55 152576 ----a-w- c:\documents and settings\Clinkz\Programdata\Sun\Java\jre1.6.0_15\lzma.dll 2009-08-03 00:47 . 2009-08-03 00:47 -------- d-----w- c:\documents and settings\All Users\Programdata\Blizzard 2009-08-03 00:46 . 2009-08-03 00:46 -------- d-----w- c:\programfiler\Fellesfiler\Blizzard Entertainment 2009-08-02 18:35 . 2009-08-02 18:35 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\Identities 2009-08-02 07:01 . 2009-08-02 07:01 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache 2009-08-02 07:01 . 2009-08-02 07:01 -------- d-sh--w- c:\documents and settings\Clinkz\IETldCache 2009-08-02 06:18 . 2009-07-19 16:48 11067392 -c----w- c:\windows\system32\dllcache\ieframe.dll 2009-08-02 06:18 . 2009-07-03 17:01 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll 2009-08-02 06:18 . 2009-07-03 17:01 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll 2009-08-02 06:18 . 2009-07-03 17:01 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll 2009-08-02 06:18 . 2009-07-03 17:01 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll 2009-08-02 06:18 . 2009-07-03 17:01 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll 2009-08-02 06:18 . 2009-08-02 06:18 -------- d-----w- c:\windows\ie8updates 2009-08-02 06:18 . 2009-07-01 07:08 101376 -c----w- c:\windows\system32\dllcache\iecompat.dll 2009-08-02 06:17 . 2009-08-02 06:18 -------- dc-h--w- c:\windows\ie8 2009-07-20 16:50 . 2009-07-20 16:50 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Ubisoft 2009-07-20 16:46 . 2009-07-20 16:46 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys 2009-07-20 16:46 . 2009-07-20 16:46 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys 2009-07-19 14:48 . 2009-07-19 14:48 -------- d-----w- c:\programfiler\DIFX 2009-07-19 14:46 . 2009-07-19 14:46 -------- d-----w- c:\programfiler\Realtek AC97 2009-07-17 17:47 . 2009-07-17 18:20 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\Aspyr 2009-07-17 02:04 . 2009-08-02 07:00 -------- d-----w- c:\windows\system32\nb-no 2009-07-17 02:04 . 2009-07-17 02:04 -------- d-----w- c:\windows\system32\no 2009-07-17 02:04 . 2009-07-17 02:04 -------- d-----w- c:\windows\system32\bits 2009-07-17 02:04 . 2009-07-17 02:04 -------- d-----w- c:\windows\l2schemas 2009-07-17 02:03 . 2009-07-17 02:03 -------- d-----w- c:\windows\ServicePackFiles 2009-07-17 02:01 . 2009-07-17 02:01 -------- d-----w- c:\windows\EHome 2009-07-16 05:50 . 2009-07-16 05:50 60416 ----a-w- c:\windows\ALCFDRTM.EXE 2009-07-15 22:57 . 2009-07-21 00:40 -------- d-----w- c:\documents and settings\All Users\Programdata\TrackMania 2009-07-15 07:50 . 2009-07-15 07:50 -------- d-----w- c:\documents and settings\NetworkService\Lokale innstillinger\Programdata\Apple 2009-07-14 15:41 . 2008-10-16 12:06 268648 ----a-w- c:\windows\system32\mucltui.dll 2009-07-14 15:41 . 2008-10-16 12:06 208744 ----a-w- c:\windows\system32\muweb.dll 2009-07-14 13:35 . 2009-07-14 13:35 -------- d-----w- c:\programfiler\Fellesfiler\DirectX 2009-07-14 13:35 . 2009-07-14 13:35 -------- d-----w- c:\windows\system32\AGEIA 2009-07-14 13:35 . 2009-07-14 13:35 -------- d-----w- c:\programfiler\AGEIA Technologies 2009-07-14 13:35 . 2009-07-14 13:35 -------- d-----w- c:\programfiler\Fellesfiler\Wise Installation Wizard 2009-07-14 04:01 . 2009-07-14 04:01 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Creative 2009-07-14 03:36 . 2009-07-14 03:36 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\CAPCOM 2009-07-14 03:18 . 2009-07-14 03:18 -------- d-----w- c:\programfiler\Microsoft Games for Windows - LIVE 2009-07-14 03:18 . 2009-07-14 03:18 -------- d-----w- c:\windows\system32\xlive 2009-07-14 02:45 . 2009-08-02 08:02 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\Adobe 2009-07-14 02:45 . 2009-07-14 03:11 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\VirtuaTennis2009 2009-07-14 02:43 . 2009-07-14 02:43 63904 ----a-w- c:\documents and settings\LocalService\Lokale innstillinger\Programdata\FontCache3.0.0.0.dat 2009-07-14 02:43 . 2009-07-14 02:43 -------- d-----w- c:\programfiler\MSBuild 2009-07-14 02:43 . 2009-07-14 02:43 -------- d-----w- c:\windows\system32\XPSViewer 2009-07-14 02:43 . 2009-07-14 02:43 -------- d-----w- c:\programfiler\Reference Assemblies 2009-07-14 02:43 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll 2009-07-14 02:41 . 2009-07-14 02:41 -------- d-----w- c:\programfiler\MSXML 6.0 2009-07-14 01:26 . 2009-07-14 01:26 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Apple Computer 2009-07-14 01:25 . 2009-07-14 01:25 -------- d-----w- c:\documents and settings\Clinkz\Programdata\dvdcss 2009-07-14 00:52 . 2009-07-14 00:52 -------- d-----w- c:\windows\Sun 2009-07-14 00:50 . 2009-07-22 09:34 -------- d-----w- c:\documents and settings\Clinkz\Programdata\mIRC 2009-07-13 23:56 . 2009-07-13 23:56 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\GHOSTBUSTERS 2009-07-13 23:30 . 2009-07-13 23:30 -------- d-----w- c:\programfiler\Realtek 2009-07-13 23:30 . 2009-06-24 08:43 831488 ----a-w- c:\windows\RtlExUpd.dll 2009-07-13 22:17 . 2009-07-13 22:17 -------- d-----w- c:\windows\Logs 2009-07-13 21:51 . 2009-07-13 21:51 -------- d-----w- c:\programfiler\Atari 2009-07-13 21:31 . 2009-07-15 18:27 8 ----a-w- c:\windows\system32\nvModes.dat 2009-07-13 21:30 . 2009-07-13 21:30 -------- d-----w- c:\documents and settings\All Users\Programdata\nView_Profiles 2009-07-13 21:27 . 2009-02-09 11:18 290816 ----a-w- c:\windows\system32\nvwrsth.dll 2009-07-13 21:27 . 2009-02-09 11:18 253952 ----a-w- c:\windows\system32\nvrsth.dll 2009-07-13 21:27 . 2009-02-09 11:18 401408 ----a-w- c:\windows\system32\nvcuvid.dll 2009-07-13 21:27 . 2006-06-01 15:22 1011712 ----a-w- c:\windows\system32\nvcpluir.dll 2009-07-13 21:25 . 2009-07-13 21:25 -------- d-----w- c:\programfiler\My Company Name 2009-07-13 21:18 . 2009-08-06 10:35 -------- d-----w- c:\documents and settings\Clinkz\Programdata\vlc 2009-07-13 21:14 . 2004-08-03 20:29 63488 ------w- c:\windows\system32\drivers\atinxsxx.sys 2009-07-13 21:08 . 2009-07-13 21:08 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\Macromedia 2009-07-13 21:07 . 2009-07-13 21:07 56 ---ha-w- c:\windows\system32\ezsidmv.dat 2009-07-13 21:07 . 2009-08-06 14:07 -------- d-----w- c:\documents and settings\Clinkz\Programdata\skypePM 2009-07-13 21:06 . 2009-07-13 21:06 45056 ----a-r- c:\documents and settings\Clinkz\Programdata\Microsoft\Installer\{885A63EA-382B-4DD4-A755-14809B8557D6}\ARPPRODUCTICON.exe 2009-07-13 21:06 . 2009-07-13 21:07 -------- d-----w- c:\programfiler\Fellesfiler\Macromedia 2009-07-13 21:06 . 2009-08-02 06:23 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Spotify 2009-07-13 21:06 . 2009-07-13 21:06 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\Spotify 2009-07-13 21:05 . 2009-07-13 21:05 -------- d-----w- c:\windows\Downloaded Installations 2009-07-13 21:00 . 2001-08-17 21:59 3072 ----a-w- c:\windows\system32\drivers\audstub.sys 2009-07-13 21:00 . 2009-07-13 21:00 -------- d-----w- c:\windows\system32\Lang 2009-07-13 21:00 . 2008-04-14 16:22 21504 ----a-w- c:\windows\system32\hidserv.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-08-06 19:06 . 2009-07-13 20:06 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Hamachi 2009-08-06 19:04 . 2009-07-13 20:54 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Skype 2009-08-06 18:49 . 2009-07-13 20:42 -------- d-----w- c:\documents and settings\Clinkz\Programdata\uTorrent 2009-08-05 20:05 . 2009-07-13 19:52 -------- d--h--w- c:\programfiler\InstallShield Installation Information 2009-07-22 10:08 . 2009-07-13 20:24 13688 ----a-w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\GDIPFONTCACHEV1.DAT 2009-07-19 15:04 . 2004-08-04 12:00 75854 ----a-w- c:\windows\system32\perfc014.dat 2009-07-19 15:04 . 2004-08-04 12:00 436116 ----a-w- c:\windows\system32\perfh014.dat 2009-07-19 14:56 . 2009-07-13 20:29 -------- d-----w- c:\programfiler\Setup Files 2009-07-17 02:06 . 2009-07-13 19:17 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat 2009-07-16 23:46 . 2009-07-13 20:05 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys 2009-07-13 22:20 . 2009-07-13 22:20 -------- d--h--r- c:\documents and settings\Clinkz\Programdata\SecuROM 2009-07-13 21:39 . 2009-07-13 20:45 -------- d-----w- c:\documents and settings\Clinkz\Programdata\DAEMON Tools Lite 2009-07-13 20:59 . 2009-07-13 20:59 -------- d-----w- c:\documents and settings\All Users\Programdata\DAEMON Tools Lite 2009-07-13 20:59 . 2009-07-13 20:59 -------- d-----w- c:\programfiler\DAEMON Tools Toolbar 2009-07-13 20:54 . 2009-07-13 20:54 -------- d-----r- c:\programfiler\Skype 2009-07-13 20:54 . 2009-07-13 20:54 -------- d-----w- c:\programfiler\Fellesfiler\Skype 2009-07-13 20:54 . 2009-07-13 20:54 -------- d-----w- c:\documents and settings\All Users\Programdata\Skype 2009-07-13 20:48 . 2009-07-13 20:47 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Winamp 2009-07-13 20:45 . 2009-07-13 20:45 721904 ----a-w- c:\windows\system32\drivers\sptd.sys 2009-07-13 20:35 . 2009-07-13 20:35 0 ----a-w- c:\windows\nsreg.dat 2009-07-13 20:31 . 2009-07-13 20:31 -------- d-----w- c:\programfiler\Windows Live 2009-07-13 20:31 . 2009-07-13 20:31 -------- d-----w- c:\programfiler\Microsoft 2009-07-13 20:31 . 2009-07-13 20:31 -------- d-----w- c:\programfiler\Windows Live SkyDrive 2009-07-13 20:31 . 2009-07-13 20:31 -------- d-----w- c:\programfiler\MSI 2009-07-13 20:27 . 2009-07-13 20:27 -------- d-----w- c:\programfiler\Fellesfiler\Windows Live 2009-07-13 20:23 . 2009-07-13 19:56 -------- d-----w- c:\programfiler\GameFace Messenger 2009-07-13 20:17 . 2009-07-13 20:15 -------- d-----w- c:\programfiler\Creative 2009-07-13 20:15 . 2009-07-13 19:50 -------- d-----w- c:\programfiler\Fellesfiler\InstallShield 2009-07-13 20:13 . 2009-07-13 20:08 -------- d-----w- c:\programfiler\Logitech 2009-07-13 20:13 . 2009-07-13 20:13 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Logitech 2009-07-13 20:13 . 2009-07-13 20:13 10134 ----a-r- c:\documents and settings\Clinkz\Programdata\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe 2009-07-13 20:13 . 2009-07-13 20:13 -------- d-----w- c:\programfiler\Fellesfiler\LogiShared 2009-07-13 20:11 . 2009-07-13 20:11 10134 ----a-r- c:\documents and settings\Clinkz\Programdata\Microsoft\Installer\{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}\ARPPRODUCTICON.exe 2009-07-13 20:11 . 2009-07-13 20:11 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf 2009-07-13 20:11 . 2009-07-13 20:11 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf 2009-07-13 20:10 . 2009-07-13 20:10 -------- d-----w- c:\programfiler\Fellesfiler\Logitech 2009-07-13 20:10 . 2009-07-13 20:10 10134 ----a-r- c:\documents and settings\Clinkz\Programdata\Microsoft\Installer\{56918C0C-0D87-4CA6-92BF-4975A43AC719}\ARPPRODUCTICON.exe 2009-07-13 20:10 . 2009-07-13 20:10 -------- d-----w- c:\documents and settings\Clinkz\Programdata\InstallShield 2009-07-13 20:09 . 2009-07-13 20:09 -------- d-----w- c:\documents and settings\All Users\Programdata\LogiShrd 2009-07-13 20:08 . 2009-07-13 20:08 -------- d-----w- c:\documents and settings\All Users\Programdata\Logitech 2009-07-13 20:03 . 2009-07-13 20:03 -------- d-----w- c:\documents and settings\All Users\Programdata\Apple Computer 2009-07-13 20:03 . 2009-07-13 20:03 -------- d-----w- c:\programfiler\Apple Software Update 2009-07-13 20:03 . 2009-07-13 20:03 -------- d-----w- c:\documents and settings\All Users\Programdata\Apple 2009-07-13 20:02 . 2009-07-13 20:02 410984 ----a-w- c:\windows\system32\deploytk.dll 2009-07-13 20:02 . 2009-07-13 20:02 -------- d-----w- c:\programfiler\Java 2009-07-13 20:02 . 2009-07-13 20:02 152576 ----a-w- c:\documents and settings\Clinkz\Programdata\Sun\Java\jre1.6.0_13\lzma.dll 2009-07-13 20:01 . 2009-07-13 20:01 -------- d-----w- c:\programfiler\Fellesfiler\Adobe AIR 2009-07-13 20:01 . 2009-07-13 20:00 -------- d-----w- c:\programfiler\Fellesfiler\Adobe 2009-07-13 19:56 . 2009-07-13 19:56 737280 ----a-w- c:\windows\iun6002.exe 2009-07-13 19:56 . 2009-07-13 19:56 -------- d-----w- c:\programfiler\ASUSTeK 2009-07-13 19:52 . 2009-07-13 19:52 -------- d-----w- c:\programfiler\Realtek Sound Manager 2009-07-13 19:52 . 2009-07-13 19:52 -------- d-----w- c:\programfiler\AvRack 2009-07-13 19:18 . 2009-07-13 19:18 -------- d-----w- c:\programfiler\microsoft frontpage 2009-07-13 19:17 . 2009-07-13 19:17 -------- d-----w- c:\programfiler\Elektroniske tjenester 2009-07-13 19:16 . 2009-07-13 19:16 -------- d-----w- c:\programfiler\Fellesfiler\Tjenester 2009-07-13 19:15 . 2009-07-13 19:15 21704 ----a-w- c:\windows\system32\emptyregdb.dat 2009-07-03 17:01 . 2004-08-04 12:00 915456 ----a-w- c:\windows\system32\wininet.dll 2009-06-16 14:43 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll 2009-06-16 14:43 . 2004-08-04 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll 2009-06-03 19:11 . 2004-08-04 12:00 1294336 ----a-w- c:\windows\system32\quartz.dll . (((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret ))))))))))))))))))))))))))))))))))))))))))))) . . *Merk* tomme oppføringer & gyldige standardoppføringer vises ikke REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-09 13680640] "Launch LGDCore"="c:\programfiler\Logitech\G-series Software\LGDCore.exe" [2006-03-06 1122304] "Launch LCDMon"="c:\programfiler\Logitech\G-series Software\LCDMon.exe" [2006-03-06 497152] "LiveMonitor"="c:\programfiler\MSI\Live Update 3\LMonitor.exe" [2009-02-24 498688] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-09 86016] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-04-11 56080] "VF0060 STISvc"="V0060Pin.dll" - c:\windows\system32\V0060Pin.dll [2004-11-01 36864] "SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-11-17 577536] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] c:\documents and settings\Clinkz\Start-meny\Programmer\Oppstart\ hamachi.lnk - f:\hamachi\hamachi.exe [2009-2-5 625952] c:\documents and settings\All Users\Start-meny\Programmer\Oppstart\ Logitech SetPoint.lnk - c:\programfiler\Logitech\SetPoint\SetPoint.exe [2009-7-13 692224] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "f:\\uTorrent\\uTorrent.exe"= "f:\\Garena\\Garena.exe"= "f:\\Spotify\\spotify.exe"= "d:\\Overlord II\\Overlord2.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Programfiler\\Skype\\Phone\\Skype.exe"= R2 wmcmgc;Windows Management Configuration;c:\windows\System32\svchost.exe -k netsvcs [04.08.2004 14:00 14336] S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\Clinkz\LOKALE~1\Temp\PAFBA.tmp --> c:\docume~1\Clinkz\LOKALE~1\Temp\PAFBA.tmp [?] S3 V0060VID;Creative WebCam Live! Ultra;c:\windows\system32\drivers\V0060Vid.sys [15.07.2009 00:41 196409] --- Andre tjenester/drivere lastet i minnet --- *NewlyCreated* - WEBNTACCESS *Deregistered* - WEBNTACCESS HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs wmcmgc [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Innholdet i mappen 'Scheduled Tasks' (planlagte oppgaver) 2009-08-05 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\programfiler\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34] . . ------- Tilleggsskanning ------- . uInternet Connection Wizard,ShellNext = hxxp://tw.msi.com.tw/autobios/VerChk/LSeries.asp?MSIOCXVersion=3.76&WorkFunction=LMonitor FF - ProfilePath - c:\documents and settings\Clinkz\Programdata\Mozilla\Firefox\Profiles\67k6v12c.default\ FF - component: f:\mozilla firefox\components\FFComm.dll FF - component: f:\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll FF - plugin: f:\adobe reader\Reader\browser\nppdf32.dll FF - plugin: f:\mozilla firefox\plugins\npoctoshape.dll FF - plugin: f:\quicktime\Plugins\npqtplugin.dll FF - plugin: f:\quicktime\Plugins\npqtplugin2.dll FF - plugin: f:\quicktime\Plugins\npqtplugin3.dll FF - plugin: f:\quicktime\Plugins\npqtplugin4.dll FF - plugin: f:\quicktime\Plugins\npqtplugin5.dll FF - plugin: f:\quicktime\Plugins\npqtplugin6.dll FF - plugin: f:\quicktime\Plugins\npqtplugin7.dll ---- FIREFOX POLICIES ---- f:\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); f:\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); f:\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); f:\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); f:\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); f:\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); f:\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); f:\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); f:\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); f:\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); f:\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); f:\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); f:\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); f:\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); f:\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); f:\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); f:\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); f:\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); f:\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); f:\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".no"); f:\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); f:\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); f:\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); f:\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); f:\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); f:\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); f:\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); f:\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-08-06 21:06 Windows 5.1.2600 Service Pack 3 NTFS skanner skjulte prosesser ... skanner skjulte autostart-oppføringer ... skanner skjulte filer ... skanning vellykket skjulte filer: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine] "ImagePath"="\??\c:\docume~1\Clinkz\LOKALE~1\Temp\PAFBA.tmp" . --------------------- LÅSTE REGISTERNØKLER --------------------- [HKEY_USERS\S-1-5-21-329068152-1844823847-682003330-1004\Software\SecuROM\License information*] "datasecu"=hex:25,47,3f,41,60,9a,c2,f0,93,11,89,3a,53,31,e2,19,fd,cc,67,ab,f4, a2,2d,2b,f7,06,cc,c7,ee,d1,49,67,89,59,d6,6c,1a,41,28,1b,16,a9,42,77,3a,3a,\ "rkeysecu"=hex:8c,c2,22,e8,15,86,f7,44,b3,d5,d3,99,33,14,11,2b . --------------------- DLL'er Lastet Av Kjørende Prosesser --------------------- - - - - - - - > 'explorer.exe'(2540) c:\programfiler\Logitech\SetPoint\GameHook.dll c:\programfiler\Logitech\SetPoint\lgscroll.dll c:\windows\system32\webcheck.dll . ------------------------ Andre Kjørende Prosesser ------------------------ . c:\windows\system32\rundll32.exe c:\windows\system32\rundll32.exe c:\programfiler\Logitech\G-series Software\Applets\LCDClock.exe c:\programfiler\Fellesfiler\Logitech\KhalShared\KHALMNPR.exe c:\windows\ATKKBService.exe c:\programfiler\Java\jre6\bin\jqs.exe c:\windows\system32\nvsvc32.exe c:\windows\system32\wdfmgr.exe c:\windows\system32\wscntfy.exe . ************************************************************************** . Tidspunkt ferdig: 2009-08-06 21:08 - maskinen ble startet på nytt ComboFix-quarantined-files.txt 2009-08-06 19:08 Pre-Run: 16 755 998 720 byte ledig Post-Run: 17 031 151 616 byte ledig 315 --- E O F --- 2009-08-02 06:18 Endret 6. august 2009 av BendItLikeBender Lenke til kommentar
snippsat Skrevet 6. august 2009 Del Skrevet 6. august 2009 Kopiere fet tekst under bildet->åpne notisblokk og lim inn. Lagre på skrivebordet som CFScript.txt Gjør som på bildet combofix vil starte,Post logg c:\combofix.txt File:: c:\docume~1\Clinkz\LOKALE~1\Temp\PAFBA.tmp Driver:: GarenaPEngine Lenke til kommentar
BendItLikeBender Skrevet 6. august 2009 Forfatter Del Skrevet 6. august 2009 (endret) Ny combofix logg Klikk for å se/fjerne innholdet nedenfor ComboFix 09-08-06.01 - Clinkz 06.08.2009 23:26.3.2 - NTFSx86Microsoft Windows XP Home Edition 5.1.2600.3.1252.47.1044.18.2047.995 [GMT 2:00] Kjører fra: c:\documents and settings\Clinkz\Skrivebord\ComboFix.exe Command switches brukt :: c:\documents and settings\Clinkz\Skrivebord\CFScript.txt.txt ADVARSEL -DENNE MASKINEN HAR IKKE GJENOPPRETTINGSKONSOLLEN INSTALLERT !! FILE :: "c:\docume~1\Clinkz\LOKALE~1\Temp\PAFBA.tmp" . ((((((((((((((((((((((((((((((((((((((( Andre slettinger ))))))))))))))))))))))))))))))))))))))))))))))))) . . ((((((((((((((((((((((((((((((((((((((( Drivere/Tjenester ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_GARENAPENGINE -------\Service_GarenaPEngine ((((((((((((((((((((((((((( Filer Opprettet Fra 2009-07-06 til 2009-08-06 ))))))))))))))))))))))))))))))))) . 2009-08-06 18:52 . 2009-08-06 18:52 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Malwarebytes 2009-08-06 18:52 . 2009-08-03 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-06 18:52 . 2009-08-06 18:52 -------- d-----w- c:\documents and settings\All Users\Programdata\Malwarebytes 2009-08-06 18:52 . 2009-08-03 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-08-05 19:55 . 2009-08-05 19:55 152576 ----a-w- c:\documents and settings\Clinkz\Programdata\Sun\Java\jre1.6.0_15\lzma.dll 2009-08-03 00:47 . 2009-08-03 00:47 -------- d-----w- c:\documents and settings\All Users\Programdata\Blizzard 2009-08-03 00:46 . 2009-08-03 00:46 -------- d-----w- c:\programfiler\Fellesfiler\Blizzard Entertainment 2009-08-02 18:35 . 2009-08-02 18:35 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\Identities 2009-08-02 07:01 . 2009-08-02 07:01 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache 2009-08-02 07:01 . 2009-08-02 07:01 -------- d-sh--w- c:\documents and settings\Clinkz\IETldCache 2009-08-02 06:18 . 2009-07-19 16:48 11067392 -c----w- c:\windows\system32\dllcache\ieframe.dll 2009-08-02 06:18 . 2009-07-03 17:01 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll 2009-08-02 06:18 . 2009-07-03 17:01 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll 2009-08-02 06:18 . 2009-07-03 17:01 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll 2009-08-02 06:18 . 2009-07-03 17:01 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll 2009-08-02 06:18 . 2009-07-03 17:01 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll 2009-08-02 06:18 . 2009-08-02 06:18 -------- d-----w- c:\windows\ie8updates 2009-08-02 06:18 . 2009-07-01 07:08 101376 -c----w- c:\windows\system32\dllcache\iecompat.dll 2009-08-02 06:17 . 2009-08-02 06:18 -------- dc-h--w- c:\windows\ie8 2009-07-20 16:50 . 2009-07-20 16:50 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Ubisoft 2009-07-20 16:46 . 2009-07-20 16:46 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys 2009-07-20 16:46 . 2009-07-20 16:46 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys 2009-07-19 14:48 . 2009-07-19 14:48 -------- d-----w- c:\programfiler\DIFX 2009-07-19 14:46 . 2009-07-19 14:46 -------- d-----w- c:\programfiler\Realtek AC97 2009-07-17 17:47 . 2009-07-17 18:20 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\Aspyr 2009-07-17 02:04 . 2009-08-02 07:00 -------- d-----w- c:\windows\system32\nb-no 2009-07-17 02:04 . 2009-07-17 02:04 -------- d-----w- c:\windows\system32\no 2009-07-17 02:04 . 2009-07-17 02:04 -------- d-----w- c:\windows\system32\bits 2009-07-17 02:04 . 2009-07-17 02:04 -------- d-----w- c:\windows\l2schemas 2009-07-17 02:03 . 2009-07-17 02:03 -------- d-----w- c:\windows\ServicePackFiles 2009-07-17 02:01 . 2009-07-17 02:01 -------- d-----w- c:\windows\EHome 2009-07-16 05:50 . 2009-07-16 05:50 60416 ----a-w- c:\windows\ALCFDRTM.EXE 2009-07-15 22:57 . 2009-07-21 00:40 -------- d-----w- c:\documents and settings\All Users\Programdata\TrackMania 2009-07-15 07:50 . 2009-07-15 07:50 -------- d-----w- c:\documents and settings\NetworkService\Lokale innstillinger\Programdata\Apple 2009-07-14 15:41 . 2008-10-16 12:06 268648 ----a-w- c:\windows\system32\mucltui.dll 2009-07-14 15:41 . 2008-10-16 12:06 208744 ----a-w- c:\windows\system32\muweb.dll 2009-07-14 13:35 . 2009-07-14 13:35 -------- d-----w- c:\programfiler\Fellesfiler\DirectX 2009-07-14 13:35 . 2009-07-14 13:35 -------- d-----w- c:\windows\system32\AGEIA 2009-07-14 13:35 . 2009-07-14 13:35 -------- d-----w- c:\programfiler\AGEIA Technologies 2009-07-14 13:35 . 2009-07-14 13:35 -------- d-----w- c:\programfiler\Fellesfiler\Wise Installation Wizard 2009-07-14 04:01 . 2009-07-14 04:01 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Creative 2009-07-14 03:36 . 2009-07-14 03:36 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\CAPCOM 2009-07-14 03:18 . 2009-07-14 03:18 -------- d-----w- c:\programfiler\Microsoft Games for Windows - LIVE 2009-07-14 03:18 . 2009-07-14 03:18 -------- d-----w- c:\windows\system32\xlive 2009-07-14 02:45 . 2009-08-02 08:02 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\Adobe 2009-07-14 02:45 . 2009-07-14 03:11 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\VirtuaTennis2009 2009-07-14 02:43 . 2009-07-14 02:43 63904 ----a-w- c:\documents and settings\LocalService\Lokale innstillinger\Programdata\FontCache3.0.0.0.dat 2009-07-14 02:43 . 2009-07-14 02:43 -------- d-----w- c:\programfiler\MSBuild 2009-07-14 02:43 . 2009-07-14 02:43 -------- d-----w- c:\windows\system32\XPSViewer 2009-07-14 02:43 . 2009-07-14 02:43 -------- d-----w- c:\programfiler\Reference Assemblies 2009-07-14 02:43 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll 2009-07-14 02:41 . 2009-07-14 02:41 -------- d-----w- c:\programfiler\MSXML 6.0 2009-07-14 01:26 . 2009-07-14 01:26 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Apple Computer 2009-07-14 01:25 . 2009-07-14 01:25 -------- d-----w- c:\documents and settings\Clinkz\Programdata\dvdcss 2009-07-14 00:52 . 2009-07-14 00:52 -------- d-----w- c:\windows\Sun 2009-07-14 00:50 . 2009-07-22 09:34 -------- d-----w- c:\documents and settings\Clinkz\Programdata\mIRC 2009-07-13 23:56 . 2009-07-13 23:56 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\GHOSTBUSTERS 2009-07-13 23:30 . 2009-07-13 23:30 -------- d-----w- c:\programfiler\Realtek 2009-07-13 23:30 . 2009-06-24 08:43 831488 ----a-w- c:\windows\RtlExUpd.dll 2009-07-13 22:17 . 2009-07-13 22:17 -------- d-----w- c:\windows\Logs 2009-07-13 21:51 . 2009-07-13 21:51 -------- d-----w- c:\programfiler\Atari 2009-07-13 21:31 . 2009-07-15 18:27 8 ----a-w- c:\windows\system32\nvModes.dat 2009-07-13 21:30 . 2009-07-13 21:30 -------- d-----w- c:\documents and settings\All Users\Programdata\nView_Profiles 2009-07-13 21:27 . 2009-02-09 11:18 290816 ----a-w- c:\windows\system32\nvwrsth.dll 2009-07-13 21:27 . 2009-02-09 11:18 253952 ----a-w- c:\windows\system32\nvrsth.dll 2009-07-13 21:27 . 2009-02-09 11:18 401408 ----a-w- c:\windows\system32\nvcuvid.dll 2009-07-13 21:27 . 2006-06-01 15:22 1011712 ----a-w- c:\windows\system32\nvcpluir.dll 2009-07-13 21:25 . 2009-07-13 21:25 -------- d-----w- c:\programfiler\My Company Name 2009-07-13 21:18 . 2009-08-06 10:35 -------- d-----w- c:\documents and settings\Clinkz\Programdata\vlc 2009-07-13 21:14 . 2004-08-03 20:29 63488 ------w- c:\windows\system32\drivers\atinxsxx.sys 2009-07-13 21:08 . 2009-07-13 21:08 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\Macromedia 2009-07-13 21:07 . 2009-07-13 21:07 56 ---ha-w- c:\windows\system32\ezsidmv.dat 2009-07-13 21:07 . 2009-08-06 14:07 -------- d-----w- c:\documents and settings\Clinkz\Programdata\skypePM 2009-07-13 21:06 . 2009-07-13 21:06 45056 ----a-r- c:\documents and settings\Clinkz\Programdata\Microsoft\Installer\{885A63EA-382B-4DD4-A755-14809B8557D6}\ARPPRODUCTICON.exe 2009-07-13 21:06 . 2009-07-13 21:07 -------- d-----w- c:\programfiler\Fellesfiler\Macromedia 2009-07-13 21:06 . 2009-08-02 06:23 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Spotify 2009-07-13 21:06 . 2009-07-13 21:06 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\Spotify 2009-07-13 21:05 . 2009-07-13 21:05 -------- d-----w- c:\windows\Downloaded Installations 2009-07-13 21:00 . 2001-08-17 21:59 3072 ----a-w- c:\windows\system32\drivers\audstub.sys 2009-07-13 21:00 . 2009-07-13 21:00 -------- d-----w- c:\windows\system32\Lang 2009-07-13 21:00 . 2008-04-14 16:22 21504 ----a-w- c:\windows\system32\hidserv.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-08-06 21:30 . 2009-07-13 20:06 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Hamachi 2009-08-06 19:04 . 2009-07-13 20:54 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Skype 2009-08-06 18:49 . 2009-07-13 20:42 -------- d-----w- c:\documents and settings\Clinkz\Programdata\uTorrent 2009-08-05 20:05 . 2009-07-13 19:52 -------- d--h--w- c:\programfiler\InstallShield Installation Information 2009-07-22 10:08 . 2009-07-13 20:24 13688 ----a-w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\GDIPFONTCACHEV1.DAT 2009-07-19 15:04 . 2004-08-04 12:00 75854 ----a-w- c:\windows\system32\perfc014.dat 2009-07-19 15:04 . 2004-08-04 12:00 436116 ----a-w- c:\windows\system32\perfh014.dat 2009-07-19 14:56 . 2009-07-13 20:29 -------- d-----w- c:\programfiler\Setup Files 2009-07-17 02:06 . 2009-07-13 19:17 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat 2009-07-16 23:46 . 2009-07-13 20:05 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys 2009-07-13 22:20 . 2009-07-13 22:20 -------- d--h--r- c:\documents and settings\Clinkz\Programdata\SecuROM 2009-07-13 21:39 . 2009-07-13 20:45 -------- d-----w- c:\documents and settings\Clinkz\Programdata\DAEMON Tools Lite 2009-07-13 20:59 . 2009-07-13 20:59 -------- d-----w- c:\documents and settings\All Users\Programdata\DAEMON Tools Lite 2009-07-13 20:59 . 2009-07-13 20:59 -------- d-----w- c:\programfiler\DAEMON Tools Toolbar 2009-07-13 20:54 . 2009-07-13 20:54 -------- d-----r- c:\programfiler\Skype 2009-07-13 20:54 . 2009-07-13 20:54 -------- d-----w- c:\programfiler\Fellesfiler\Skype 2009-07-13 20:54 . 2009-07-13 20:54 -------- d-----w- c:\documents and settings\All Users\Programdata\Skype 2009-07-13 20:48 . 2009-07-13 20:47 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Winamp 2009-07-13 20:45 . 2009-07-13 20:45 721904 ----a-w- c:\windows\system32\drivers\sptd.sys 2009-07-13 20:35 . 2009-07-13 20:35 0 ----a-w- c:\windows\nsreg.dat 2009-07-13 20:31 . 2009-07-13 20:31 -------- d-----w- c:\programfiler\Windows Live 2009-07-13 20:31 . 2009-07-13 20:31 -------- d-----w- c:\programfiler\Microsoft 2009-07-13 20:31 . 2009-07-13 20:31 -------- d-----w- c:\programfiler\Windows Live SkyDrive 2009-07-13 20:31 . 2009-07-13 20:31 -------- d-----w- c:\programfiler\MSI 2009-07-13 20:27 . 2009-07-13 20:27 -------- d-----w- c:\programfiler\Fellesfiler\Windows Live 2009-07-13 20:23 . 2009-07-13 19:56 -------- d-----w- c:\programfiler\GameFace Messenger 2009-07-13 20:17 . 2009-07-13 20:15 -------- d-----w- c:\programfiler\Creative 2009-07-13 20:15 . 2009-07-13 19:50 -------- d-----w- c:\programfiler\Fellesfiler\InstallShield 2009-07-13 20:13 . 2009-07-13 20:08 -------- d-----w- c:\programfiler\Logitech 2009-07-13 20:13 . 2009-07-13 20:13 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Logitech 2009-07-13 20:13 . 2009-07-13 20:13 10134 ----a-r- c:\documents and settings\Clinkz\Programdata\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe 2009-07-13 20:13 . 2009-07-13 20:13 -------- d-----w- c:\programfiler\Fellesfiler\LogiShared 2009-07-13 20:11 . 2009-07-13 20:11 10134 ----a-r- c:\documents and settings\Clinkz\Programdata\Microsoft\Installer\{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}\ARPPRODUCTICON.exe 2009-07-13 20:11 . 2009-07-13 20:11 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf 2009-07-13 20:11 . 2009-07-13 20:11 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf 2009-07-13 20:10 . 2009-07-13 20:10 -------- d-----w- c:\programfiler\Fellesfiler\Logitech 2009-07-13 20:10 . 2009-07-13 20:10 10134 ----a-r- c:\documents and settings\Clinkz\Programdata\Microsoft\Installer\{56918C0C-0D87-4CA6-92BF-4975A43AC719}\ARPPRODUCTICON.exe 2009-07-13 20:10 . 2009-07-13 20:10 -------- d-----w- c:\documents and settings\Clinkz\Programdata\InstallShield 2009-07-13 20:09 . 2009-07-13 20:09 -------- d-----w- c:\documents and settings\All Users\Programdata\LogiShrd 2009-07-13 20:08 . 2009-07-13 20:08 -------- d-----w- c:\documents and settings\All Users\Programdata\Logitech 2009-07-13 20:03 . 2009-07-13 20:03 -------- d-----w- c:\documents and settings\All Users\Programdata\Apple Computer 2009-07-13 20:03 . 2009-07-13 20:03 -------- d-----w- c:\programfiler\Apple Software Update 2009-07-13 20:03 . 2009-07-13 20:03 -------- d-----w- c:\documents and settings\All Users\Programdata\Apple 2009-07-13 20:02 . 2009-07-13 20:02 410984 ----a-w- c:\windows\system32\deploytk.dll 2009-07-13 20:02 . 2009-07-13 20:02 -------- d-----w- c:\programfiler\Java 2009-07-13 20:02 . 2009-07-13 20:02 152576 ----a-w- c:\documents and settings\Clinkz\Programdata\Sun\Java\jre1.6.0_13\lzma.dll 2009-07-13 20:01 . 2009-07-13 20:01 -------- d-----w- c:\programfiler\Fellesfiler\Adobe AIR 2009-07-13 20:01 . 2009-07-13 20:00 -------- d-----w- c:\programfiler\Fellesfiler\Adobe 2009-07-13 19:56 . 2009-07-13 19:56 737280 ----a-w- c:\windows\iun6002.exe 2009-07-13 19:56 . 2009-07-13 19:56 -------- d-----w- c:\programfiler\ASUSTeK 2009-07-13 19:52 . 2009-07-13 19:52 -------- d-----w- c:\programfiler\Realtek Sound Manager 2009-07-13 19:52 . 2009-07-13 19:52 -------- d-----w- c:\programfiler\AvRack 2009-07-13 19:18 . 2009-07-13 19:18 -------- d-----w- c:\programfiler\microsoft frontpage 2009-07-13 19:17 . 2009-07-13 19:17 -------- d-----w- c:\programfiler\Elektroniske tjenester 2009-07-13 19:16 . 2009-07-13 19:16 -------- d-----w- c:\programfiler\Fellesfiler\Tjenester 2009-07-13 19:15 . 2009-07-13 19:15 21704 ----a-w- c:\windows\system32\emptyregdb.dat 2009-07-03 17:01 . 2004-08-04 12:00 915456 ----a-w- c:\windows\system32\wininet.dll 2009-06-16 14:43 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll 2009-06-16 14:43 . 2004-08-04 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll 2009-06-03 19:11 . 2004-08-04 12:00 1294336 ----a-w- c:\windows\system32\quartz.dll . ((((((((((((((((((((((((((((( SnapShot@2009-08-06_19.06.33 ))))))))))))))))))))))))))))))))))))))))) . + 2009-08-06 21:29 . 2009-08-06 21:29 16384 c:\windows\Temp\Perflib_Perfdata_7c4.dat . (((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret ))))))))))))))))))))))))))))))))))))))))))))) . . *Merk* tomme oppføringer & gyldige standardoppføringer vises ikke REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\programfiler\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885400] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-09 13680640] "Launch LGDCore"="c:\programfiler\Logitech\G-series Software\LGDCore.exe" [2006-03-06 1122304] "Launch LCDMon"="c:\programfiler\Logitech\G-series Software\LCDMon.exe" [2006-03-06 497152] "LiveMonitor"="c:\programfiler\MSI\Live Update 3\LMonitor.exe" [2009-02-24 498688] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-09 86016] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-04-11 56080] "VF0060 STISvc"="V0060Pin.dll" - c:\windows\system32\V0060Pin.dll [2004-11-01 36864] "SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-11-17 577536] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] c:\documents and settings\Clinkz\Start-meny\Programmer\Oppstart\ hamachi.lnk - f:\hamachi\hamachi.exe [2009-2-5 625952] c:\documents and settings\All Users\Start-meny\Programmer\Oppstart\ Logitech SetPoint.lnk - c:\programfiler\Logitech\SetPoint\SetPoint.exe [2009-7-13 692224] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "f:\\uTorrent\\uTorrent.exe"= "f:\\Garena\\Garena.exe"= "f:\\Spotify\\spotify.exe"= "d:\\Overlord II\\Overlord2.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Programfiler\\Skype\\Phone\\Skype.exe"= R2 wmcmgc;Windows Management Configuration;c:\windows\System32\svchost.exe -k netsvcs [04.08.2004 14:00 14336] R3 V0060VID;Creative WebCam Live! Ultra;c:\windows\system32\drivers\V0060Vid.sys [15.07.2009 00:41 196409] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs wmcmgc [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Innholdet i mappen 'Scheduled Tasks' (planlagte oppgaver) 2009-08-05 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\programfiler\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34] . . ------- Tilleggsskanning ------- . uInternet Connection Wizard,ShellNext = hxxp://tw.msi.com.tw/autobios/VerChk/LSeries.asp?MSIOCXVersion=3.76&WorkFunction=LMonitor FF - ProfilePath - c:\documents and settings\Clinkz\Programdata\Mozilla\Firefox\Profiles\67k6v12c.default\ FF - component: f:\mozilla firefox\components\FFComm.dll FF - component: f:\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll FF - plugin: f:\adobe reader\Reader\browser\nppdf32.dll FF - plugin: f:\mozilla firefox\plugins\npoctoshape.dll FF - plugin: f:\quicktime\Plugins\npqtplugin.dll FF - plugin: f:\quicktime\Plugins\npqtplugin2.dll FF - plugin: f:\quicktime\Plugins\npqtplugin3.dll FF - plugin: f:\quicktime\Plugins\npqtplugin4.dll FF - plugin: f:\quicktime\Plugins\npqtplugin5.dll FF - plugin: f:\quicktime\Plugins\npqtplugin6.dll FF - plugin: f:\quicktime\Plugins\npqtplugin7.dll ---- FIREFOX POLICIES ---- f:\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); f:\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); f:\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); f:\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); f:\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); f:\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); f:\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); f:\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); f:\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); f:\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); f:\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); f:\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); f:\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); f:\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); f:\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); f:\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); f:\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); f:\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); f:\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); f:\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".no"); f:\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); f:\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); f:\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); f:\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); f:\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); f:\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); f:\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); f:\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-08-06 23:30 Windows 5.1.2600 Service Pack 3 NTFS skanner skjulte prosesser ... skanner skjulte autostart-oppføringer ... skanner skjulte filer ... skanning vellykket skjulte filer: 0 ************************************************************************** . --------------------- LÅSTE REGISTERNØKLER --------------------- [HKEY_USERS\S-1-5-21-329068152-1844823847-682003330-1004\Software\SecuROM\License information*] "datasecu"=hex:25,47,3f,41,60,9a,c2,f0,93,11,89,3a,53,31,e2,19,fd,cc,67,ab,f4, a2,2d,2b,f7,06,cc,c7,ee,d1,49,67,89,59,d6,6c,1a,41,28,1b,16,a9,42,77,3a,3a,\ "rkeysecu"=hex:8c,c2,22,e8,15,86,f7,44,b3,d5,d3,99,33,14,11,2b . --------------------- DLL'er Lastet Av Kjørende Prosesser --------------------- - - - - - - - > 'explorer.exe'(3700) c:\programfiler\Logitech\SetPoint\GameHook.dll c:\programfiler\Logitech\SetPoint\lgscroll.dll c:\windows\system32\webcheck.dll . ------------------------ Andre Kjørende Prosesser ------------------------ . c:\windows\system32\rundll32.exe c:\windows\system32\rundll32.exe c:\programfiler\Logitech\G-series Software\Applets\LCDClock.exe c:\programfiler\Fellesfiler\Logitech\KhalShared\KHALMNPR.exe c:\windows\ATKKBService.exe c:\programfiler\Java\jre6\bin\jqs.exe c:\windows\system32\nvsvc32.exe c:\windows\system32\wdfmgr.exe c:\windows\system32\wscntfy.exe . ************************************************************************** . Tidspunkt ferdig: 2009-08-06 23:31 - maskinen ble startet på nytt ComboFix-quarantined-files.txt 2009-08-06 21:31 ComboFix2.txt 2009-08-06 21:21 ComboFix3.txt 2009-08-06 19:08 Pre-Run: 17 037 234 176 byte ledig Post-Run: 16 993 800 192 byte ledig 321 --- E O F --- 2009-08-02 06:18 Endret 6. august 2009 av BendItLikeBender Lenke til kommentar
snippsat Skrevet 6. august 2009 Del Skrevet 6. august 2009 Da ser det bra ut. Du kan fjerne combofix ved å skrive combofix /u fra kjør-vinduet. Denne kommandoen gjør at filer i karantene og backups blir slette. Systemgjenopprettingsmappa nullstilt etc. Sjekk om software er oppdatert Secunia Surf trygt. Lenke til kommentar
Anbefalte innlegg
Opprett en konto eller logg inn for å kommentere
Du må være et medlem for å kunne skrive en kommentar
Opprett konto
Det er enkelt å melde seg inn for å starte en ny konto!
Start en kontoLogg inn
Har du allerede en konto? Logg inn her.
Logg inn nå