Gå til innhold

[Løst] Hjelp,fjerne malware med logger(oppdatert ny log)


Anbefalte innlegg

Hei!

 

Fjerner malware på en PC,kan noen se over loggene?

 

ComboFix 10-08-31.02 - Arne 01.09.2010 16:21:12.2.1 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.47.1033.18.759.544 [GMT 2:00]

Kjører fra: c:\documents and settings\Arne\Desktop\Fjerne drit\ComboFix.exe

.

 

((((((((((((((((((((((((((((((((((((((( Andre slettinger )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\documents and settings\Arne\Local Settings\Application Data\Windows Server

c:\documents and settings\Arne\Local Settings\Application Data\Windows Server\flags.ini

c:\documents and settings\Arne\Local Settings\Application Data\Windows Server\server.dat

c:\documents and settings\Arne\Local Settings\Application Data\Windows Server\uses32.dat

c:\windows\system32\drivers\npf.sys

c:\windows\system32\Packet.dll

c:\windows\system32\wpcap.dll

 

Infisert kopi av c:\windows\system32\userinit.exe ble funnet og desinfisert

Gjenopprettet kopi fra - c:\windows\ERDNT\cache\userinit.exe

 

Infisert kopi av c:\windows\system32\winlogon.exe ble funnet og desinfisert

Gjenopprettet kopi fra - c:\windows\ERDNT\cache\winlogon.exe

 

c:\windows\explorer.exe . . . er infisert!!

 

.

((((((((((((((((((((((((((((((((((((((( Drivere/Tjenester )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Legacy_NPF

-------\Service_NPF

 

 

((((((((((((((((((((((((((( Filer Opprettet Fra 2010-08-01 til 2010-09-01 )))))))))))))))))))))))))))))))))

.

 

2010-08-31 12:51 . 2008-04-14 00:12 26112 ----a-w- c:\windows\system32\stu2.exe

2010-08-18 15:27 . 2010-08-18 15:27 -------- d-----w- c:\documents and settings\Birgit\Local Settings\Application Data\Ahead

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-09-01 14:07 . 2009-10-09 13:35 117760 ----a-w- c:\documents and settings\Arne\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL

2010-09-01 13:49 . 2009-08-26 15:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-08-31 18:35 . 2009-11-26 16:37 -------- d-----w- c:\documents and settings\Arne\Application Data\Spotify

2010-06-30 12:31 . 2003-03-31 12:00 149504 ----a-w- c:\windows\system32\schannel.dll

2010-06-24 12:22 . 2004-01-21 14:16 916480 ----a-w- c:\windows\system32\wininet.dll

2010-06-23 13:44 . 2003-03-31 12:00 1851904 ----a-w- c:\windows\system32\win32k.sys

2010-06-21 15:27 . 2003-03-31 12:00 354304 ----a-w- c:\windows\system32\drivers\srv.sys

2010-06-17 14:03 . 2003-03-31 12:00 80384 ----a-w- c:\windows\system32\iccvid.dll

2010-06-14 14:31 . 2009-08-26 14:21 744448 ----a-w- c:\windows\PCHealth\HelpCtr\Binaries\helpsvc.exe

2010-06-14 07:41 . 2003-03-31 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll

2009-12-07 22:59 . 2009-12-07 22:59 70 ----a-w- c:\program files\listen.pls

2009-10-27 17:28 . 2009-10-27 17:28 41984 --sha-r- c:\windows\system32\Npcgord.dll

.

 

------- Sigcheck -------

 

[7] 2008-04-14 . ED0EF0A136DEC83DF69F04118870003E . 507904 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\winlogon.exe

[7] 2008-04-14 . ED0EF0A136DEC83DF69F04118870003E . 507904 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\winlogon.exe

[-] 2008-04-14 . 4ECA7C20FAB5072693796F289D96FC82 . 507904 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe

[7] 2004-08-04 . 01C3346C241652F43AED8E2149881BFE . 502272 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\winlogon.exe

 

[-] 2008-04-14 . 512ACC98CE6525CADF2B71DCB412B350 . 1033728 . . [6.00.2900.5512] . . c:\windows\explorer.exe

[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\ERDNT\cache\explorer.exe

[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe

[7] 2004-08-04 . A0732187050030AE399B241436565E64 . 1032192 . . [6.00.2900.2180] . . c:\windows\$NtServicePackUninstall$\explorer.exe

.

(((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret )))))))))))))))))))))))))))))))))))))))))))))

.

.

*Merk* tomme oppføringer & gyldige standardoppføringer vises ikke

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 143360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IgfxTray"="c:\windows\System32\igfxtray.exe" [2003-10-02 155648]

"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-10-02 118784]

"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2009-10-29 15:14 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

@="Driver"

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

"c:\\Documents and Settings\\Arne\\Desktop\\Spotify Installer.exe"=

"c:\\Documents and Settings\\Birgit\\Desktop\\Spotify Installer.exe"=

"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=

 

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [05.08.2009 16:06 9968]

R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [05.08.2009 16:06 74480]

S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [18.01.2010 21:18 13224]

S3 OMNUSB;Omnikey AG CardMan 2020 USB Smart Card Reader;c:\windows\system32\drivers\sccmusbm.sys [26.08.2009 17:12 23936]

S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [05.08.2009 16:06 7408]

.

.

------- Tilleggsskanning -------

.

uStart Page = hxxp://www.sol.no/

uInternet Connection Wizard,ShellNext = iexplore

.

- - - - TOMME PEKERE FJERNET - - - -

 

URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

BHO-{A3BC75A2-1F87-4686-AA43-5347D756017C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

 

 

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-09-01 16:45

Windows 5.1.2600 Service Pack 3 NTFS

 

skanner skjulte prosesser ...

 

skanner skjulte autostart-oppføringer ...

 

skanner skjulte filer ...

 

skanning vellykket

skjulte filer: 0

 

**************************************************************************

.

--------------------- DLL'er Lastet Av Kjørende Prosesser ---------------------

 

- - - - - - - > 'winlogon.exe'(636)

c:\program files\SUPERAntiSpyware\SASWINLO.DLL

c:\windows\system32\WININET.dll

 

- - - - - - - > 'explorer.exe'(2824)

c:\windows\system32\WININET.dll

c:\program files\Common Files\Ahead\Lib\NeroSearchBar.dll

c:\program files\Common Files\Ahead\Lib\MFC71U.DLL

c:\program files\Common Files\Ahead\Lib\BCGCBPRO800u.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

.

------------------------ Andre Kjørende Prosesser ------------------------

.

c:\windows\System32\SCardSvr.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\program files\Common Files\LightScribe\LSSrvc.exe

c:\windows\system32\HPZipm12.exe

c:\windows\system32\wdfmgr.exe

c:\windows\system32\wscntfy.exe

c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe

c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe

.

**************************************************************************

.

Tidspunkt ferdig: 2010-09-01 16:48:51 - maskinen ble startet på nytt

ComboFix-quarantined-files.txt 2010-09-01 14:48

ComboFix2.txt 2009-10-29 15:28

 

Pre-Run: 6 437 556 224 bytes free

Post-Run: 7 190 642 688 bytes free

 

- - End Of File - - 02DE65F1B911CF453AC553DF219E1AAD

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

 

Database version: 4521

 

Windows 5.1.2600 Service Pack 3 (Safe Mode)

Internet Explorer 8.0.6001.18702

 

01.09.2010 16:04:07

mbam-log-2010-09-01 (16-04-07).txt

 

Scan type: Quick scan

Objects scanned: 181397

Time elapsed: 13 minute(s), 13 second(s)

 

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 1

Registry Data Items Infected: 2

Folders Infected: 0

Files Infected: 15

 

Memory Processes Infected:

(No malicious items detected)

 

Memory Modules Infected:

(No malicious items detected)

 

Registry Keys Infected:

(No malicious items detected)

 

Registry Values Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sniffer (Trojan.Downloader) -> Quarantined and deleted successfully.

 

Registry Data Items Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Malware.Packer.Gen) -> Data: c:\windows\system32\userinit.exe -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Malware.Packer.Gen) -> Data: system32\userinit.exe -> Quarantined and deleted successfully.

 

Folders Infected:

(No malicious items detected)

 

Files Infected:

C:\WINDOWS\temp\_ex-08.exe (Trojan.Downloader) -> Quarantined and deleted successfully.

C:\Documents and Settings\Arne\Local Settings\temp\fixversion70702.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.

C:\Documents and Settings\Arne\Local Settings\temp\ie4.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.

C:\Documents and Settings\Arne\Local Settings\temp\ie5.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.

C:\Documents and Settings\Arne\Local Settings\Application Data\671360.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully.

C:\Documents and Settings\Arne\Local Settings\Temporary Internet Files\Content.IE5\3RI9NBCA\setup480[2].exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.

C:\Documents and Settings\Arne\Local Settings\Temporary Internet Files\Content.IE5\3RI9NBCA\yo[2].exe (Trojan.Downloader) -> Quarantined and deleted successfully.

C:\Documents and Settings\Arne og Birgit\Local Settings\Temporary Internet Files\Content.IE5\ZR7SSQYH\casinoclassic[1].exe (Adware.Casino) -> Quarantined and deleted successfully.

C:\Documents and Settings\Arne\Start Menu\Programs\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully.

C:\Documents and Settings\Arne\Local Settings\temp\0.4471086893133479.exe (Trojan.Dropper) -> Quarantined and deleted successfully.

C:\Documents and Settings\Arne\Local Settings\temp\ffollower.exe (Trojan.Dropper) -> Quarantined and deleted successfully.

C:\Documents and Settings\Arne\Local Settings\temp\ie3.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

C:\Documents and Settings\Arne\Local Settings\temp\q1.exe (Trojan.Clicker) -> Quarantined and deleted successfully.

C:\Documents and Settings\Arne\Local Settings\temp\teste1_p.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\Documents and Settings\Arne\Local Settings\Application Data\Windows Server\admin.txt (Malware.Trace) -> Quarantined and deleted successfully.

Endret av Stian V.H
Lenke til kommentar
Videoannonse
Annonse

Åpne notisblokk og kopier inn det som står i fet skrift under, lagre fila på skrivebordet som CFScript.txt.

Dra deretter fila over Combofix-iconet. Combofix vil starte igjen. Post loggen.

 

file::

c:\windows\system32\stu2.exe

 

FCOPY::

c:\windows\ERDNT\cache\explorer.exe|c:\windows\explorer.exe

Lenke til kommentar

AVG kommer ikke med virus advarsel lenger etter jeg fulgte instruksen.

 

Her er den nye ComboFix loggen,ser det bra ut nå?

 

 

 

 

 

 

ComboFix 10-09-01.04 - Arne 02.09.2010 16:25:25.3.1 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.47.1033.18.759.534 [GMT 2:00]

Kjører fra: c:\documents and settings\Arne\Desktop\ComboFix.exe

Command switches brukt :: c:\documents and settings\Arne\Desktop\CFScript.txt.txt

* Opprettet nytt gjenopprettingspunkt

 

FILE ::

"c:\windows\system32\stu2.exe"

.

 

((((((((((((((((((((((((((((((((((((((( Andre slettinger )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\windows\system32\stu2.exe

 

Infisert kopi av c:\windows\system32\winlogon.exe ble funnet og desinfisert

Gjenopprettet kopi fra - c:\windows\ERDNT\cache\winlogon.exe

 

Infisert kopi av c:\windows\explorer.exe ble funnet og desinfisert

Gjenopprettet kopi fra - c:\windows\ERDNT\cache\explorer.exe

 

.

--------------- FCopy ---------------

 

c:\windows\ERDNT\cache\explorer.exe --> c:\windows\explorer.exe

.

((((((((((((((((((((((((((( Filer Opprettet Fra 2010-08-02 til 2010-09-02 )))))))))))))))))))))))))))))))))

.

 

2010-09-01 14:59 . 2010-09-01 14:59 52224 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll

2010-08-18 15:27 . 2010-08-18 15:27 -------- d-----w- c:\documents and settings\Birgit\Local Settings\Application Data\Ahead

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-09-01 14:59 . 2009-10-29 14:53 117760 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL

2010-09-01 14:07 . 2009-10-09 13:35 117760 ----a-w- c:\documents and settings\Arne\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL

2010-09-01 13:49 . 2009-08-26 15:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-08-31 18:35 . 2009-11-26 16:37 -------- d-----w- c:\documents and settings\Arne\Application Data\Spotify

2010-06-30 12:31 . 2003-03-31 12:00 149504 ----a-w- c:\windows\system32\schannel.dll

2010-06-24 12:22 . 2004-01-21 14:16 916480 ----a-w- c:\windows\system32\wininet.dll

2010-06-23 13:44 . 2003-03-31 12:00 1851904 ----a-w- c:\windows\system32\win32k.sys

2010-06-21 15:27 . 2003-03-31 12:00 354304 ----a-w- c:\windows\system32\drivers\srv.sys

2010-06-17 14:03 . 2003-03-31 12:00 80384 ----a-w- c:\windows\system32\iccvid.dll

2010-06-14 14:31 . 2009-08-26 14:21 744448 ----a-w- c:\windows\PCHealth\HelpCtr\Binaries\helpsvc.exe

2010-06-14 07:41 . 2003-03-31 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll

2009-12-07 22:59 . 2009-12-07 22:59 70 ----a-w- c:\program files\listen.pls

2009-10-27 17:28 . 2009-10-27 17:28 41984 --sha-r- c:\windows\system32\Npcgord.dll

.

 

(((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret )))))))))))))))))))))))))))))))))))))))))))))

.

.

*Merk* tomme oppføringer & gyldige standardoppføringer vises ikke

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 143360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IgfxTray"="c:\windows\System32\igfxtray.exe" [2003-10-02 155648]

"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-10-02 118784]

"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2009-10-29 15:14 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

@="Driver"

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

"c:\\Documents and Settings\\Arne\\Desktop\\Spotify Installer.exe"=

"c:\\Documents and Settings\\Birgit\\Desktop\\Spotify Installer.exe"=

"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=

 

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [05.08.2009 16:06 9968]

R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [05.08.2009 16:06 74480]

S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [18.01.2010 21:18 13224]

S3 OMNUSB;Omnikey AG CardMan 2020 USB Smart Card Reader;c:\windows\system32\drivers\sccmusbm.sys [26.08.2009 17:12 23936]

S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [05.08.2009 16:06 7408]

.

.

------- Tilleggsskanning -------

.

uStart Page = hxxp://www.sol.no/

uInternet Connection Wizard,ShellNext = iexplore

.

- - - - TOMME PEKERE FJERNET - - - -

 

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)

 

 

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-09-02 16:30

Windows 5.1.2600 Service Pack 3 NTFS

 

skanner skjulte prosesser ...

 

skanner skjulte autostart-oppføringer ...

 

skanner skjulte filer ...

 

skanning vellykket

skjulte filer: 0

 

**************************************************************************

.

--------------------- DLL'er Lastet Av Kjørende Prosesser ---------------------

 

- - - - - - - > 'winlogon.exe'(636)

c:\program files\SUPERAntiSpyware\SASWINLO.DLL

c:\windows\system32\WININET.dll

 

- - - - - - - > 'explorer.exe'(2732)

c:\windows\system32\WININET.dll

c:\program files\Common Files\Ahead\Lib\NeroSearchBar.dll

c:\program files\Common Files\Ahead\Lib\MFC71U.DLL

c:\program files\Common Files\Ahead\Lib\BCGCBPRO800u.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

.

------------------------ Andre Kjørende Prosesser ------------------------

.

c:\windows\System32\SCardSvr.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\program files\Common Files\LightScribe\LSSrvc.exe

c:\windows\system32\HPZipm12.exe

c:\windows\system32\wdfmgr.exe

c:\windows\system32\wscntfy.exe

c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe

c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe

.

**************************************************************************

.

Tidspunkt ferdig: 2010-09-02 16:33:49 - maskinen ble startet på nytt

ComboFix-quarantined-files.txt 2010-09-02 14:33

ComboFix2.txt 2010-09-01 14:48

 

Pre-Run: 7 241 203 712 bytes free

Post-Run: 7 367 073 792 bytes free

 

- - End Of File - - 50E82EAA8CFD2EBF734BAC8DD042EAA8

Endret av Stian V.H
Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
  • Hvem er aktive   0 medlemmer

    • Ingen innloggede medlemmer aktive
×
×
  • Opprett ny...