Gå til innhold

Hjelp til og se over logg COMBOFIX


Anbefalte innlegg

kan noen se over logg? hva kan jeg gjøre?

 

 

 

ComboFix 11-08-02.02 - Admin 01.08.2011 19:15:16.1.2 - x64

Microsoft Windows 7 Ultimate 6.1.7600.0.1252.47.1033.18.4061.2631 [GMT 2:00]

Kjører fra: c:\users\Admin\Desktop\ComboFix.exe

SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Opprettet nytt gjenopprettingspunkt

.

.

((((((((((((((((((((((((((((((((((((((( Andre slettinger )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\programdata\Local

c:\users\Pilot\AppData\Roaming\Dated.dat

c:\users\Pilot\AppData\Roaming\delme.bat

c:\users\Pilot\AppData\Roaming\Dir

c:\users\Pilot\AppData\Roaming\Dir\Dated.dat

c:\users\Pilot\AppData\Roaming\lovely.ini

c:\users\Pilot\AppData\Roaming\Pilot3SQLite3.dll

c:\users\Pilot\AppData\Roaming\Sysutils_Update

c:\users\Public\Documents\dll

c:\windows\iun6002.exe

c:\windows\system32\no

c:\windows\system32\no\AuthFWSnapIn.Resources.dll

c:\windows\system32\no\AuthFWWizFwk.Resources.dll

c:\windows\SysWow64\no

c:\windows\SysWow64\no\AuthFWSnapIn.Resources.dll

c:\windows\SysWow64\no\AuthFWWizFwk.Resources.dll

c:\windows\SysWow64\Windupdt

c:\windows\SysWow64\Windupdt\winupdate.exe

D:\AUTORUN.INF

.

.

((((((((((((((((((((((((((( Filer Opprettet Fra 2011-07-01 til 2011-08-01 )))))))))))))))))))))))))))))))))

.

.

2011-08-02 22:06 . 2011-03-29 23:22 -------- d-----w- c:\program files (x86)\SpeedFan

2011-08-01 17:28 . 2011-08-01 17:28 -------- d-----w- c:\users\Default\AppData\Local\temp

2011-07-29 22:08 . 2011-07-29 22:08 69856 ----a-w- c:\windows\SysWow64\drivers\LxrSge10d.sys

2011-07-29 22:08 . 2011-07-29 22:08 49152 ----a-w- c:\windows\SysWow64\LxrSge10s.exe

2011-07-29 22:08 . 2011-07-29 22:08 282624 ----a-w- c:\windows\LxrSGe11e.dll

2011-07-29 22:08 . 2011-07-29 22:08 1605632 ----a-w- c:\windows\LxrJDLApp.exe

2011-07-29 22:08 . 2011-07-29 22:08 146432 ----a-w- c:\windows\SysWow64\LxrDPart.exe

2011-07-26 23:28 . 2011-08-01 16:33 -------- d-----w- c:\users\Admin

2011-07-22 22:47 . 2011-07-22 22:47 -------- d-----w- c:\windows\system32\%LOCALAPPDATA%

2011-07-13 15:42 . 2011-07-13 15:45 -------- d-----w- c:\users\Pilot\AppData\Roaming\FreeCall

2011-07-13 15:42 . 2011-07-13 15:42 -------- d-----w- c:\program files (x86)\FreeCall.com

2011-07-12 22:39 . 2011-07-22 17:51 -------- d-----w- c:\users\Pilot\AppData\Roaming\Bitcoin

2011-07-10 21:18 . 2011-07-10 21:18 -------- d-----w- c:\users\Pilot\AppData\Roaming\FS2Crew2010

2011-07-10 21:18 . 2011-07-10 21:18 92828 ----a-w- c:\program files (x86)\Microsoft Games\Microsoft Flight Simulator X\unFS2Crew2010_FSX_IFly737NG_Voice_Control.exe

2011-07-09 00:14 . 2011-07-09 00:20 589647 ----a-w- c:\program files (x86)\Microsoft Games\Microsoft Flight Simulator X\Un-iFly737FSX.exe

2011-07-08 00:30 . 2011-07-08 00:30 -------- d-----w- c:\program files\Active Data Recovery Software

2011-07-07 08:36 . 2011-07-07 08:36 -------- d-----w- c:\users\Pilot\AppData\Local\Chris_Pietschmann_(http__

2011-07-07 08:32 . 2011-07-07 08:33 -------- d-----w- c:\program files (x86)\Virtual Router

2011-07-07 01:27 . 2011-07-07 01:27 -------- d-----w- c:\users\Pilot\AppData\Roaming\Easeware

2011-07-07 01:27 . 2011-07-07 01:27 -------- d-----w- c:\program files\Easeware

2011-07-06 22:04 . 2011-07-06 22:04 -------- d-s---w- c:\windows\SysWow64\Microsoft

2011-07-06 20:01 . 2011-07-06 20:01 0 ---ha-w- c:\users\Pilot\AppData\Local\BIT4EF.tmp

2011-07-06 19:50 . 2011-07-06 19:50 -------- d-----w- c:\users\Pilot\AppData\Roaming\Option

2011-07-06 19:37 . 2011-07-06 19:37 -------- d-----w- c:\program files (x86)\Telenor

2011-07-06 06:13 . 2011-07-07 23:15 -------- d-----w- C:\pmSystemsDemo

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-05-24 17:14 . 2010-09-14 01:07 270720 ------w- c:\windows\system32\MpSigStub.exe

2011-05-17 02:08 . 2011-05-17 02:08 0 ---ha-w- c:\users\Pilot\AppData\Local\BITD541.tmp

2011-05-09 22:00 . 2011-06-05 03:40 8718160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7113B0C8-5FE3-4C71-BC77-A3F09FFE15D8}\mpengine.dll

2010-12-12 22:25 . 2010-12-12 22:25 75776 ----a-w- c:\program files (x86)\BeatlesBlog.SimConnect.dll

2010-12-12 22:25 . 2010-12-12 22:25 745472 ----a-w- c:\program files (x86)\Fluent.dll

2010-12-12 22:25 . 2010-12-12 22:25 57344 ----a-w- c:\program files (x86)\FSUIPCClient.dll

2010-12-12 22:25 . 2010-12-12 22:25 147312 ----a-w- c:\program files (x86)\sqlceer35EN.dll

2010-12-12 22:25 . 2010-12-12 22:25 66048 ----a-w- c:\program files (x86)\MapReset.exe

2010-12-12 22:25 . 2010-12-12 22:25 52224 ----a-w- c:\program files (x86)\Charts.dll

2010-12-12 22:25 . 2010-12-12 22:25 48640 ----a-w- c:\program files (x86)\FlightInstruments.dll

2010-12-12 22:25 . 2010-12-12 22:25 1594880 ----a-w- c:\program files (x86)\PlanG.exe

2010-12-12 22:25 . 2010-12-12 22:25 124416 ----a-w- c:\program files (x86)\FS.dll

2010-12-12 22:25 . 2010-12-12 22:25 640880 ----a-w- c:\program files (x86)\sqlceqp35.dll

2010-12-12 22:25 . 2010-12-12 22:25 63344 ----a-w- c:\program files (x86)\sqlceme35.dll

2010-12-12 22:25 . 2010-12-12 22:25 342384 ----a-w- c:\program files (x86)\sqlceca35.dll

2010-12-12 22:25 . 2010-12-12 22:25 296816 ----a-w- c:\program files (x86)\System.Data.SqlServerCe.dll

2010-12-12 22:25 . 2010-12-12 22:25 270336 ----a-w- c:\program files (x86)\ClearAllSettings.exe

2010-12-12 22:25 . 2010-12-12 22:25 231280 ----a-w- c:\program files (x86)\System.Data.SqlServerCe.Entity.dll

2010-12-12 22:25 . 2010-12-12 22:25 169328 ----a-w- c:\program files (x86)\sqlceoledb35.dll

2010-12-12 22:25 . 2010-12-12 22:25 83312 ----a-w- c:\program files (x86)\sqlcecompact35.dll

2010-12-12 22:25 . 2010-12-12 22:25 361840 ----a-w- c:\program files (x86)\sqlcese35.dll

.

.

------- Sigcheck -------

Note: Unsigned files aren't necessarily malware.

.

[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll

[-] 2010-10-17 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7600.16385] .. c:\windows\system32\user32.dll

.

[-] 2010-10-17 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7600.16385] .. c:\windows\SysWOW64\user32.dll

[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll

.

(((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret )))))))))))))))))))))))))))))))))))))))))))))

.

.

*Merk* tomme oppføringer & gyldige standardoppføringer vises ikke

REGEDIT4

.

[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{1AD61D5B-58A3-4592-9B34-DC84688FF805}]

2010-08-20 13:57 107328 ----a-w- c:\program files (x86)\PDF Suite 2010\PDFIEHelper.dll

.

[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]

2010-10-18 10:26 3908192 ----a-w- c:\program files (x86)\Softonic-Eng7\tbSof0.dll

.

[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{5CFCAFF6-5BB0-4864-B626-021C99ED82E5}]

2010-12-13 16:03 107344 ----a-w- c:\program files (x86)\Soda PDF\PDFIEHelper.dll

.

[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]

2010-10-11 14:12 1244040 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]

"{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}"= "c:\program files (x86)\Softonic-Eng7\tbSof0.dll" [2010-10-18 3908192]

"{980EB9EC-6EB5-4258-BDDB-EFE25C5F99EF}"= "c:\program files (x86)\Soda PDF\PDFIEPlugin.dll" [2010-12-13 725840]

"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2010-10-11 1244040]

.

[HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]

.

[HKEY_CLASSES_ROOT\clsid\{980eb9ec-6eb5-4258-bddb-efe25c5f99ef}]

[HKEY_CLASSES_ROOT\SodaPDFIEPlugin.PDFIEConverter.1]

[HKEY_CLASSES_ROOT\TypeLib\{EA100F6A-F239-4E91-9EA6-8B47CAD4EF0D}]

[HKEY_CLASSES_ROOT\SodaPDFIEPlugin.PDFIEConverter]

.

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]

[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]

[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]

[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 4240760]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-11-11 442536]

"PWRISOVM.EXE"="c:\program files (x86)\PowerISO\PWRISOVM.EXE" [2010-04-12 180224]

"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-15 35736]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-15 932288]

"Matrox PowerDesk"="c:\program files (x86)\Matrox Graphics\PowerDesk\Matrox.PDesk.Startup.exe" [2010-05-21 846152]

"DRPU PC Data Manager(Basic)"="c:\program files (x86)\DRPU PC Data Manager(Basic)\pcdm.exe" [2010-10-06 2839728]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]

"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2011-05-25 1951112]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

GamersFirst LIVE!.lnk - c:\program files (x86)\GamersFirst\LIVE!\Live.exe [2010-7-7 2805104]

Virtual Router Manager.lnk - c:\windows\Installer\{8DB05F7E-1F7A-4CC0-882F-375B97F04CD4}\_E6D9769DD20AF384865041.exe [2011-7-7 22486]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 gupdate;Googles oppdateringstjeneste (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-09-14 136176]

R2 Virtual Router;VirtualRouterService;c:\program files (x86)\Virtual Router\VirtualRouterService.exe [2009-11-18 12288]

R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]

R3 EWSASERV;EWSA Control Service;c:\program files (x86)\Elcomsoft Password Recovery\Elcomsoft Wireless Security Auditor\ewsaserv64.exe [2011-04-16 82224]

R3 gupdatem;Google-oppdatering-tjenesten (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-09-14 136176]

R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [2010-10-14 19952]

R3 SaiH0464;SaiH0464;c:\windows\system32\DRIVERS\SaiH0464.sys [x]

R3 WatAdminSvc;WatAdminSvc; [x]

R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files (x86)\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-10 47128]

R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-10 369688]

S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]

S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\AESTSr64.exe [2009-03-03 89600]

S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]

S2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x64.sys [x]

S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-05-25 2275720]

S2 Matrox.Pdesk3.ServicesHost;Matrox.Pdesk3.ServicesHost;c:\program files (x86)\Matrox Graphics\PowerDesk\Matrox.PDesk.Services.exe [2010-05-21 3645256]

S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]

S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x]

S2 PDF Suite 2010 Service;PDF Suite 2010 Service;c:\program files (x86)\PDF Suite 2010\ConversionService.exe [2010-08-20 799552]

S2 SesamService;Sesam Control Service;c:\program files (x86)\Telenor\mobilt bredband\Sesam\BIN\SecMIPService.exe [2009-02-17 1237800]

S2 Soda PDF Service;Soda PDF Service;c:\program files (x86)\Soda PDF\ConversionService.exe [2010-12-13 807760]

S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]

S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x]

S3 HideMyIpSRV;HideMyIpSRV;c:\program files (x86)\Hide My IP\HideMyIpSrv.exe [2010-07-06 3039536]

S3 k57nd60a;Broadcom NetLink Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]

S4 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]

S4 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

Akamai REG_MULTI_SZ Akamai

.

Innholdet i mappen 'Scheduled Tasks' (planlagte oppgaver)

.

2011-07-07 c:\windows\Tasks\DriverNavigator Scheduled Scan.job

- c:\program files\Easeware\DriverNavigator\DriverNavigator.exe [2011-07-07 08:43]

.

2011-08-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-09-22 01:08]

.

2011-08-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-09-22 01:08]

.

2011-07-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2640786973-4079037601-862572936-1000Core.job

- c:\users\Pilot\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-14 01:08]

.

2011-08-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2640786973-4079037601-862572936-1000UA.job

- c:\users\Pilot\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-14 01:08]

.

2011-08-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2640786973-4079037601-862572936-1007Core.job

- c:\users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-01 22:21]

.

2011-08-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2640786973-4079037601-862572936-1007UA.job

- c:\users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-01 22:21]

.

2011-06-04 c:\windows\Tasks\Norton Security Scan for Pilot.job

- c:\program files (x86)\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-10-03 07:48]

.

.

--------- x86-64 -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-10-13 3863040]

"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-01-21 487424]

"QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2010-04-01 3217056]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"LoadAppInit_DLLs"=0x0

.

------- Tilleggsskanning -------

.

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

LSP: c:\windows\system32\HMIPCore.dll

FF - ProfilePath -

.

- - - - TOMME PEKERE FJERNET - - - -

.

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)

WebBrowser-{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3} - (no file)

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe

AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe

AddRemove-pc12_FSX - c:\windows\iun6002.exe

AddRemove-{9F6186D4-1CE0-48CE-8072-296A6225EC52}_is1 - c:\aerosystems\unins000.exe

.

.

.

--------------------- LÅSTE REGISTERNØKLER ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10i.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.10"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10i.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10i.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10i.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

Tidspunkt ferdig: 2011-08-01 19:40:34

ComboFix-quarantined-files.txt 2011-08-01 17:40

.

Pre-Run: 46 120 259 584 byte ledig

Post-Run: 59 618 594 816 byte ledig

.

- - End Of File - - 0D8556AF177DE1667C3696D51D4E71FB

Lenke til kommentar
Videoannonse
Annonse
  fsx v1.1 skrev (På 2.8.2011 den 17.23):

kan noen se over logg? hva kan jeg gjøre?

 

 

Hai!

 

Combofix skal ikke brukes för man er sikker at systemet er infisert. Scan alltid först med Malwarebytes:

 

> https://www.diskusjon.no/index.php?showtopic=691246 (Punkt 1 Malwarebytes Anti Malware)

 

Full Scan og post hele loggen!

 

Combofix loggen seg ikke helt kosher ut, men Malwarebytes vil vise mer.

 

Og: Bruker du SQL Server?

Endret av TheGenius
Lenke til kommentar
  fsx v1.1 skrev (På 3.8.2011 den 16.44):

sjekka C:\Windows\system og det er bare en fil der? er det normalt?

 

He er crashdump

 

Hai!

 

Vi trenger log fra Malwarebytes Anti Malware, eller kommer vi ikke videre her.

 

Bot PC i safe mode og scan med Malwarebytes der, post log.

Lenke til kommentar

her er logg, men systemet crasher vis jeg kjører malwarebytes lenge

 

Malwarebytes' Anti-Malware 1.51.1.1800

www.malwarebytes.org

 

Database version: 7384

 

Windows 6.1.7600

Internet Explorer 8.0.7600.16385

 

05.08.2011 20:34:24

mbam-log-2011-08-05 (20-34-24).txt

 

Scan type: Full scan (C:\|)

Objects scanned: 310954

Time elapsed: 1 hour(s), 8 minute(s), 31 second(s)

 

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

 

Memory Processes Infected:

(No malicious items detected)

 

Memory Modules Infected:

(No malicious items detected)

 

Registry Keys Infected:

(No malicious items detected)

 

Registry Values Infected:

(No malicious items detected)

 

Registry Data Items Infected:

(No malicious items detected)

 

Folders Infected:

(No malicious items detected)

 

Files Infected:

c:\Qoobox\quarantine\C\Windows\SysWOW64\Windupdt\winupdate.exe.vir (Malware.Generic) -> Quarantined and deleted successfully.

Lenke til kommentar

Her er loggen av "SFC /scannow" som sjekker OS

 

  Vis skjult innhold

 

 

Lenke til kommentar
  fsx v1.1 skrev (På 5.8.2011 den 18.30):

her er logg, men systemet crasher vis jeg kjører malwarebytes lenge

 

Jeg anbefaler her en frisk start > installere Windows ny eller bruke "Recovery CD" til sette systemet tilbake.

 

Grunn:

 

Systemet var/er Malware infisert

 

Systemet crasher/ og lager problemer

 

Tipps for fremtiden:

 

Du burde endre en del ting med PCen din.

 

1. Aktiviser Firewall og install et alltid oppdatert Antivirusprogramm (Windows Defender er IKKE det)

Bra er > http://www.microsoft.com/nb-no/security_essentials/default.aspx

 

2. Ditt system var veldig utdatert. Det er veldig viktig alltid ä installere de nyeste Updates fra Windows sin update side og holde ALLE programmene updatet

> http://secunia.com/vulnerability_scanning/personal/

 

3. Informer deg om Internet sikkerhet:

> http://www.norman.com/security_center/books_general_white_papers_etc./no

Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
×
×
  • Opprett ny...