killerbanana Skrevet 17. april 2008 Del Skrevet 17. april 2008 (endret) vi har en data som har blitt overtatt av en liten snik, med andre ord, en trojan vundo. Og han vil bare ha selskap, så han får andre kjipinger til å komme. Og vi kommer ikke inn på internett, så vi får ikke lastet ned noe som helst. Hva kan vi gjøre? Endret 19. april 2008 av killerbanana Lenke til kommentar
r2d290 Skrevet 17. april 2008 Del Skrevet 17. april 2008 (endret) Alternativ1: Boot trykk f8 flere ganger,velg sikkerhetmodus med nettverk. Alternativ2: Last ned de følgende filene med en annen maskin, og flytt dem over med minnepinne Gjør dette. Last ned HijackThis legg i egen mappe på skrivebordet. Start programmet og velg "Trykk "do a systemscan and save a logfile"" . Loggfilen kopierer du og limer inn i posten din. Helst med skjult tekst [1skjul] logg her [1/skjul] fjern 1 for skjult tekst. Endret 17. april 2008 av r2d290 Lenke til kommentar
killerbanana Skrevet 17. april 2008 Forfatter Del Skrevet 17. april 2008 vi har lastet ned og flyttet over, men får ikke åpnet filen. I tillegg fjerner den automatisk .exe bak filen. Lenke til kommentar
r2d290 Skrevet 17. april 2008 Del Skrevet 17. april 2008 (endret) vi har lastet ned og flyttet over, men får ikke åpnet filen. I tillegg fjerner den automatisk .exe bak filen. Hmm... prøv å gjøre det andre alternativet med sikkerhetsmodus. Hvis det ikke fungerer, kan du prøve en blanding: last ned fila fra en annen maskin, start den infiserte maskina i sikkerhetsmodus (uten internett), og legg hijackthis-fila inn hit. Prøv deretter å kjøre denne hijackthis-fila i sikkerhetsmoduset... det at maskina fjerner .exe, tipper jeg har med at du har skjult filetternavn for kjente filtyper på denne maskina. For å se filetternavnet, kan du gå inn i min datamaskin->verktøy->mappealternativer, og fjerne haken for "skjul filetternavn for kjente filetternavn" (eller no sånt... sitter ikke i windows nå, så er ikke helt sikker) edit: sjekk også at hijackthis-fila fungerer på en annen maskin (for å fjerne muligheten av at det kan være hijackthisfila som er ødelagt) Endret 17. april 2008 av r2d290 Lenke til kommentar
killerbanana Skrevet 17. april 2008 Forfatter Del Skrevet 17. april 2008 Logfile Klikk for å se/fjerne innholdet nedenfor Logfile of Trend Micro HijackThis v2.0.2Scan saved at 17:49:47, on 17.04.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\WLTRAY.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\rundll32.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\WINDOWS\AcerOrbiCam.exe C:\Program Files\Picasa2\PicasaMediaDetector.exe C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE C:\DOCUME~1\PSYCHO~1\LOCALS~1\Temp\RtkBtMnt.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\WINDOWS\system32\wuauclt.exe C:\PROGRA~1\LAUNCH~1\LManager.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe C:\Program Files\DAEMON Tools Lite\daemon.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\system32\igfxext.exe C:\WINDOWS\system32\igfxsrvc.exe C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: (no name) - {F4D76F09-7896-458a-890F-E1F05C46069F} - (no file) O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [Acer OrbiCam] C:\WINDOWS\AcerOrbiCam.exe O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [beep for long support] C:\Documents and Settings\All Users.WINDOWS\Application Data\view name beep for\proc style.exe O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe" O4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [1d0f117a] rundll32.exe "C:\WINDOWS\system32\aybcipvj.dll",b O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKCU\..\Run: [way tool] C:\DOCUME~1\PSYCHO~1\APPLIC~1\DRIVEB~1\FunkObjSeek.exe O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users.WINDOWS\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ww\msntabres.dll.mui/229?9db251d1bef749bbaca2e3b8e0774ab8 O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ww\msntabres.dll.mui/230?9db251d1bef749bbaca2e3b8e0774ab8 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/contr...vex/TmHcmsX.CAB O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by120fd.bay120.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab O23 - Service: Automatisk LiveUpdate-planlegging - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE -- End of file - 10926 bytes Klikk for å se/fjerne innholdet nedenfor Lenke til kommentar
snippsat Skrevet 17. april 2008 Del Skrevet 17. april 2008 Hei! Du for prøve og lage en logg til. Last Combofix ned ,legg på skrivebordet. Ikke klikk på vindu mens programet kjører. post logg C:\combofix.txt Lenke til kommentar
killerbanana Skrevet 17. april 2008 Forfatter Del Skrevet 17. april 2008 ser ut til at dataen fungerer sånn den skal igjen nå, så tusen takk for hjelpen Men har ett spørsmål til, har to operativsystem på dataen, og bruker bare det ene, så er det noen som vet hvordan man fjerner det som ikke er i bruk? Lenke til kommentar
snippsat Skrevet 17. april 2008 Del Skrevet 17. april 2008 (endret) Fikk du kjørt combofix? Skull hatt loggen,det er ting som bør fjernes. Dette så jeg hijackthis loggen. Det er rimlig greit og fjerne,men trenger combofix loggen. Endret 17. april 2008 av SNIPPSAT Lenke til kommentar
killerbanana Skrevet 17. april 2008 Forfatter Del Skrevet 17. april 2008 Fikk fjernet 28 virus med combofix tingen, men jeg klarer ikke å finne ut hvor loggen har lagt seg Lenke til kommentar
snippsat Skrevet 17. april 2008 Del Skrevet 17. april 2008 (endret) Under root c:\(ikke mapper) combofix.txt du kan godt søke,viss du ikke finner den. Endret 17. april 2008 av SNIPPSAT Lenke til kommentar
killerbanana Skrevet 17. april 2008 Forfatter Del Skrevet 17. april 2008 Klikk for å se/fjerne innholdet nedenfor ComboFix 08-04-16.5 - Psychopath 2008-04-17 20:15:17.2 - FAT32x86Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.564 [GMT 2:00] Running from: C:\Documents and Settings\Psychopath\My Documents\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! Klikk for å se/fjerne innholdet nedenfor Detter var det eneste jeg fant, men den så så liten ut Lenke til kommentar
snippsat Skrevet 17. april 2008 Del Skrevet 17. april 2008 (endret) Ta et søk først "combofix.txt" Kunne du kjørt den en til gang til. Last Combofix ned ,legg på skrivebordet. Her ser du fra posten min før,du skulle legge den på skrivebordet. Kan godt laste ned på nytt og kjøre,legg den nå på skrivebordet. Da ligger loggen under c:\ combofix.txt Endret 17. april 2008 av SNIPPSAT Lenke til kommentar
killerbanana Skrevet 17. april 2008 Forfatter Del Skrevet 17. april 2008 Sånn da Klikk for å se/fjerne innholdet nedenfor ComboFix 08-04-16.5 - Psychopath 2008-04-17 21:19:14.3 - FAT32x86Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.558 [GMT 2:00] Running from: C:\Documents and Settings\Psychopath\My Documents\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((( Files Created from 2008-03-17 to 2008-04-17 ))))))))))))))))))))))))))))))) . 2008-04-17 20:21 . 2008-04-17 20:21 <DIR> d--hs---- C:\FOUND.011 2008-04-17 19:10 . 2008-04-17 19:10 <DIR> d-------- C:\Program Files\Alwil Software 2008-04-17 19:10 . 2008-03-29 19:45 1,146,232 --a------ C:\WINDOWS\system32\aswBoot.exe 2008-04-17 19:10 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx 2008-04-17 19:10 . 2008-03-29 19:23 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr 2008-04-17 19:10 . 2008-03-29 19:35 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys 2008-04-17 19:10 . 2008-01-17 17:34 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys 2008-04-17 19:10 . 2008-03-29 19:31 75,856 --a------ C:\WINDOWS\system32\drivers\aswSP.sys 2008-04-17 19:10 . 2008-03-29 19:27 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys 2008-04-17 19:10 . 2008-03-29 19:26 26,944 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys 2008-04-17 19:10 . 2008-03-29 19:29 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys 2008-04-17 19:10 . 2008-03-29 19:35 20,560 --a------ C:\WINDOWS\system32\drivers\aswFsBlk.sys 2008-04-17 18:12 . 2008-04-17 18:12 <DIR> d-------- C:\VundoFix Backups 2008-04-17 17:48 . 2008-04-17 17:48 <DIR> d-------- C:\Program Files\Trend Micro 2008-04-17 16:24 . 2008-04-17 16:24 <DIR> d--h----- C:\WINDOWS\PIF 2008-04-16 16:20 . 2008-04-16 16:20 <DIR> d--hs---- C:\FOUND.010 2008-04-16 15:02 . 2008-04-16 15:02 <DIR> d-------- C:\Program Files\DAEMON Tools Lite 2008-04-16 14:57 . 2008-04-16 14:57 <DIR> d-------- C:\Documents and Settings\Psychopath\Application Data\DAEMON Tools 2008-04-15 20:42 . 2008-04-17 14:36 714 ---hs---- C:\WINDOWS\system32\shdakxsq.ini 2008-04-14 20:51 . 2008-04-14 20:51 354 ---hs---- C:\WINDOWS\system32\jagaevxi.ini 2008-04-13 20:47 . 2008-04-14 20:47 294 ---hs---- C:\WINDOWS\system32\wjbjnqij.ini 2008-04-12 20:46 . 2008-04-12 20:47 1,770 ---hs---- C:\WINDOWS\system32\khqtgqfl.ini 2008-04-11 20:44 . 2008-04-12 20:45 1,710 ---hs---- C:\WINDOWS\system32\amnkxvro.ini 2008-04-10 19:26 . 2008-04-11 20:44 1,306 ---hs---- C:\WINDOWS\system32\cadxdmsn.ini 2008-04-09 19:31 . 2008-04-10 18:05 1,186 ---hs---- C:\WINDOWS\system32\rcevadll.ini 2008-04-08 19:27 . 2008-04-09 19:31 1,006 ---hs---- C:\WINDOWS\system32\chklojfa.ini 2008-04-08 18:06 . 2008-04-08 18:06 <DIR> d--hs---- C:\FOUND.009 2008-04-07 19:22 . 2008-04-08 18:15 886 ---hs---- C:\WINDOWS\system32\kjlsckbe.ini 2008-04-06 19:20 . 2008-04-07 19:04 818 ---hs---- C:\WINDOWS\system32\limdyjxh.ini 2008-04-05 19:19 . 2008-04-07 19:20 706 ---hs---- C:\WINDOWS\system32\yykbkinr.ini 2008-04-04 18:14 . 2008-04-05 19:15 354 ---hs---- C:\WINDOWS\system32\lxnmnuqf.ini 2008-04-03 21:22 . 2008-04-03 21:22 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-04-03 21:22 . 2008-04-03 21:22 1,409 --a------ C:\WINDOWS\QTFont.for 2008-04-03 18:13 . 2008-04-04 15:29 894 ---hs---- C:\WINDOWS\system32\ksbnganl.ini 2008-04-02 18:13 . 2008-04-03 16:43 714 ---hs---- C:\WINDOWS\system32\bhiuinkp.ini 2008-04-01 18:09 . 2008-04-02 14:08 594 ---hs---- C:\WINDOWS\system32\mmgvpkth.ini 2008-03-31 21:16 . 2008-04-01 02:00 594 ---hs---- C:\WINDOWS\system32\afnbseme.ini 2008-03-30 22:23 . 2008-03-31 21:10 534 ---hs---- C:\WINDOWS\system32\pddmknfy.ini 2008-03-29 21:17 . 2008-03-30 22:17 414 ---hs---- C:\WINDOWS\system32\xcmnynpg.ini 2008-03-29 20:07 . 2008-03-29 21:09 354 ---hs---- C:\WINDOWS\system32\ggahnfwk.ini 2008-03-28 20:01 . 2008-04-17 14:35 101,091 --a------ C:\WINDOWS\BM1e3c22e6.xml . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-04-17 18:27 2,752 ----a-w C:\WINDOWS\system32\PerfStringBackup.TMP 2008-04-16 12:57 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys 2008-03-14 05:50 --------- d-----w C:\Program Files\EA GAMES 2008-03-06 19:32 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf 2008-03-06 19:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys 2008-03-06 19:32 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat 2008-03-03 13:57 --------- d-sh--w C:\Program Files\Common Files\WindowsLiveInstaller 2008-03-03 13:56 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\WLInstaller 2008-02-19 12:48 --------- d-----w C:\Program Files\Den lengste reisen 2008-02-19 11:03 --------- d-----w C:\Program Files\directx 2008-02-17 13:14 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec 2007-03-31 08:02 44,541,440 ----a-w C:\Program Files\fsavcs_603_spion-og_virusvern_internetshield_webscan_emailscan_(komplett).msi 2007-03-16 12:49 19,994,184 ----a-w C:\Program Files\QuickTimeInstaller.exe 2007-03-15 17:50 727,138,334 ----a-w C:\Program Files\MyCDExtra.ncd 2007-03-12 17:59 552,448 ----a-w C:\Program Files\matpakke.pps 2007-03-10 16:18 6,718,976 ----a-w C:\Program Files\winamp533_full_emusic-7plus.exe 2007-03-05 18:06 4,003,432 ----a-w C:\Program Files\SweetImSetup.exe 2007-02-28 18:04 9,453,630 ----a-w C:\Program Files\vlc-0.8.6a-win32.exe 2007-02-28 14:08 4,222,516 ----a-w C:\Program Files\ABC-win32-v3.1.exe 2007-02-27 21:14 1,002,752 ----a-w C:\Program Files\JournalViewer1.5_KB886179_ENU.exe 2007-02-27 21:13 7,290,120 ----a-w C:\Program Files\setup.exe 2006-02-19 01:28 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll . Klikk for å se/fjerne innholdet nedenfor Lenke til kommentar
snippsat Skrevet 17. april 2008 Del Skrevet 17. april 2008 (endret) Det er ikke hele loggen. Du kan gjøre dette,når du gjør dette vil combofix starte. Prøv da og få med hele loggen. Riktig for skjult tekst. [1skjul] logg her [1/skjul] fjern 1 for skjult tekst. Du har en dobbel skjul greie. Kopiere fet tekst->lim inn i notisblokk. Lagre på skrivebordet som CFScript.txt. Gjør som på bildet,Post logg c:\combofix.txt File:: C:\WINDOWS\system32\shdakxsq.ini C:\WINDOWS\system32\jagaevxi.ini C:\WINDOWS\system32\wjbjnqij.ini C:\WINDOWS\system32\khqtgqfl.ini C:\WINDOWS\system32\amnkxvro.ini C:\WINDOWS\system32\cadxdmsn.ini C:\WINDOWS\system32\rcevadll.ini C:\WINDOWS\system32\chklojfa.ini C:\WINDOWS\system32\kjlsckbe.ini C:\WINDOWS\system32\limdyjxh.ini C:\WINDOWS\system32\yykbkinr.ini C:\WINDOWS\system32\lxnmnuqf.ini C:\WINDOWS\system32\ksbnganl.ini C:\WINDOWS\system32\bhiuinkp.ini C:\WINDOWS\system32\mmgvpkth.ini C:\WINDOWS\system32\afnbseme.ini C:\WINDOWS\system32\pddmknfy.ini C:\WINDOWS\system32\xcmnynpg.ini C:\WINDOWS\system32\ggahnfwk.ini Folder:: C:\VundoFix Backups Endret 17. april 2008 av SNIPPSAT Lenke til kommentar
killerbanana Skrevet 17. april 2008 Forfatter Del Skrevet 17. april 2008 Klikk for å se/fjerne innholdet nedenfor Logfile of Trend Micro HijackThis v2.0.2Scan saved at 21:55, on 2008-04-17 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\WLTRAY.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\WINDOWS\AcerOrbiCam.exe C:\Program Files\Picasa2\PicasaMediaDetector.exe C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\PROGRA~1\LAUNCH~1\LManager.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\DAEMON Tools Lite\daemon.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\igfxext.exe C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe C:\DOCUME~1\PSYCHO~1\LOCALS~1\Temp\RtkBtMnt.exe C:\Program Files\Internet Explorer\iexplore.exe c:\program files\winamp toolbar\WinampTbServer.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Windows Live Toolbar\msn_sl.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: (no name) - {F4D76F09-7896-458a-890F-E1F05C46069F} - (no file) O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [Acer OrbiCam] C:\WINDOWS\AcerOrbiCam.exe O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [beep for long support] C:\Documents and Settings\All Users.WINDOWS\Application Data\view name beep for\proc style.exe O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKCU\..\Run: [way tool] C:\DOCUME~1\PSYCHO~1\APPLIC~1\DRIVEB~1\FunkObjSeek.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users.WINDOWS\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ww\msntabres.dll.mui/229?9db251d1bef749bbaca2e3b8e0774ab8 O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ww\msntabres.dll.mui/230?9db251d1bef749bbaca2e3b8e0774ab8 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/contr...vex/TmHcmsX.CAB O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by120fd.bay120.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab O20 - Winlogon Notify: efcabxv - efcabxv.dll (file missing) O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing) O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: PsExec (PSEXESVC) - Unknown owner - C:\WINDOWS\PSEXESVC.EXE (file missing) O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE -- End of file - 10712 bytes Klikk for å se/fjerne innholdet nedenfor Da prøvde vi med den andre Lenke til kommentar
snippsat Skrevet 17. april 2008 Del Skrevet 17. april 2008 (endret) Skal ikke ha HijackThis logg ennå,nå følger du det i post 14. Endret 17. april 2008 av SNIPPSAT Lenke til kommentar
killerbanana Skrevet 19. april 2008 Forfatter Del Skrevet 19. april 2008 Beklager at det tok så lang tid. her er loggen (forhåpentligvis) Klikk for å se/fjerne innholdet nedenfor ComboFix 08-04-16.5 - Psychopath 2008-04-19 11:41:47.3 - FAT32x86Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.566 [GMT 2:00] Running from: C:\Documents and Settings\Psychopath\My Documents\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((( Files Created from 2008-03-19 to 2008-04-19 ))))))))))))))))))))))))))))))) . 2008-04-19 11:36 . 2008-04-19 11:36 <DIR> d--hs---- C:\FOUND.013 2008-04-18 12:08 . 2008-04-18 12:08 <DIR> d-------- C:\Program Files\TSBin 2008-04-18 12:08 . 2008-04-18 12:08 <DIR> d-------- C:\Program Files\CSBin 2008-04-18 12:08 . 2006-02-07 02:47 278,528 --a------ C:\Program Files\Sims2EP3_Uninst.exe 2008-04-18 12:07 . 2008-04-18 12:07 <DIR> d-------- C:\Program Files\TSData 2008-04-17 21:25 . 2008-04-17 21:25 <DIR> d--hs---- C:\FOUND.012 2008-04-17 20:21 . 2008-04-17 20:21 <DIR> d--hs---- C:\FOUND.011 2008-04-17 19:10 . 2008-04-17 19:10 <DIR> d-------- C:\Program Files\Alwil Software 2008-04-17 19:10 . 2008-03-29 19:45 1,146,232 --a------ C:\WINDOWS\system32\aswBoot.exe 2008-04-17 19:10 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx 2008-04-17 19:10 . 2008-03-29 19:23 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr 2008-04-17 19:10 . 2008-03-29 19:35 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys 2008-04-17 19:10 . 2008-01-17 17:34 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys 2008-04-17 19:10 . 2008-03-29 19:31 75,856 --a------ C:\WINDOWS\system32\drivers\aswSP.sys 2008-04-17 19:10 . 2008-03-29 19:27 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys 2008-04-17 19:10 . 2008-03-29 19:26 26,944 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys 2008-04-17 19:10 . 2008-03-29 19:29 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys 2008-04-17 19:10 . 2008-03-29 19:35 20,560 --a------ C:\WINDOWS\system32\drivers\aswFsBlk.sys 2008-04-17 18:12 . 2008-04-17 18:12 <DIR> d-------- C:\VundoFix Backups 2008-04-17 17:48 . 2008-04-17 17:48 <DIR> d-------- C:\Program Files\Trend Micro 2008-04-17 16:24 . 2008-04-17 16:24 <DIR> d--h----- C:\WINDOWS\PIF 2008-04-16 16:20 . 2008-04-16 16:20 <DIR> d--hs---- C:\FOUND.010 2008-04-16 15:02 . 2008-04-16 15:02 <DIR> d-------- C:\Program Files\DAEMON Tools Lite 2008-04-16 14:57 . 2008-04-16 14:57 <DIR> d-------- C:\Documents and Settings\Psychopath\Application Data\DAEMON Tools 2008-04-15 20:42 . 2008-04-17 14:36 714 ---hs---- C:\WINDOWS\system32\shdakxsq.ini 2008-04-14 20:51 . 2008-04-14 20:51 354 ---hs---- C:\WINDOWS\system32\jagaevxi.ini 2008-04-13 20:47 . 2008-04-14 20:47 294 ---hs---- C:\WINDOWS\system32\wjbjnqij.ini 2008-04-12 20:46 . 2008-04-12 20:47 1,770 ---hs---- C:\WINDOWS\system32\khqtgqfl.ini 2008-04-11 20:44 . 2008-04-12 20:45 1,710 ---hs---- C:\WINDOWS\system32\amnkxvro.ini 2008-04-10 19:26 . 2008-04-11 20:44 1,306 ---hs---- C:\WINDOWS\system32\cadxdmsn.ini 2008-04-09 19:31 . 2008-04-10 18:05 1,186 ---hs---- C:\WINDOWS\system32\rcevadll.ini 2008-04-08 19:27 . 2008-04-09 19:31 1,006 ---hs---- C:\WINDOWS\system32\chklojfa.ini 2008-04-08 18:06 . 2008-04-08 18:06 <DIR> d--hs---- C:\FOUND.009 2008-04-07 19:22 . 2008-04-08 18:15 886 ---hs---- C:\WINDOWS\system32\kjlsckbe.ini 2008-04-06 19:20 . 2008-04-07 19:04 818 ---hs---- C:\WINDOWS\system32\limdyjxh.ini 2008-04-05 19:19 . 2008-04-07 19:20 706 ---hs---- C:\WINDOWS\system32\yykbkinr.ini 2008-04-04 18:14 . 2008-04-05 19:15 354 ---hs---- C:\WINDOWS\system32\lxnmnuqf.ini 2008-04-03 21:22 . 2008-04-03 21:22 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-04-03 21:22 . 2008-04-03 21:22 1,409 --a------ C:\WINDOWS\QTFont.for 2008-04-03 18:13 . 2008-04-04 15:29 894 ---hs---- C:\WINDOWS\system32\ksbnganl.ini 2008-04-02 18:13 . 2008-04-03 16:43 714 ---hs---- C:\WINDOWS\system32\bhiuinkp.ini 2008-04-01 18:09 . 2008-04-02 14:08 594 ---hs---- C:\WINDOWS\system32\mmgvpkth.ini 2008-03-31 21:16 . 2008-04-01 02:00 594 ---hs---- C:\WINDOWS\system32\afnbseme.ini 2008-03-30 22:23 . 2008-03-31 21:10 534 ---hs---- C:\WINDOWS\system32\pddmknfy.ini 2008-03-29 21:17 . 2008-03-30 22:17 414 ---hs---- C:\WINDOWS\system32\xcmnynpg.ini 2008-03-29 20:07 . 2008-03-29 21:09 354 ---hs---- C:\WINDOWS\system32\ggahnfwk.ini 2008-03-28 20:01 . 2008-04-17 14:35 101,091 --a------ C:\WINDOWS\BM1e3c22e6.xml . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-04-19 09:41 2,752 ----a-w C:\WINDOWS\system32\PerfStringBackup.TMP 2008-04-16 12:57 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys 2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys 2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys 2008-03-14 05:50 --------- d-----w C:\Program Files\EA GAMES 2008-03-06 19:32 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf 2008-03-06 19:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys 2008-03-06 19:32 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat 2008-03-03 13:57 --------- d-sh--w C:\Program Files\Common Files\WindowsLiveInstaller 2008-03-03 13:56 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\WLInstaller 2008-03-01 16:36 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll 2008-02-29 08:55 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe 2008-02-29 08:55 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe 2008-02-22 10:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe 2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll 2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\dllcache\gdi32.dll 2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll 2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll 2008-02-20 05:32 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll 2008-02-19 12:48 --------- d-----w C:\Program Files\Den lengste reisen 2008-02-19 11:03 --------- d-----w C:\Program Files\directx 2008-02-15 05:44 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll 2007-03-31 08:02 44,541,440 ----a-w C:\Program Files\fsavcs_603_spion-og_virusvern_internetshield_webscan_emailscan_(komplett).msi 2007-03-16 12:49 19,994,184 ----a-w C:\Program Files\QuickTimeInstaller.exe 2007-03-15 17:50 727,138,334 ----a-w C:\Program Files\MyCDExtra.ncd 2007-03-12 17:59 552,448 ----a-w C:\Program Files\matpakke.pps 2007-03-10 16:18 6,718,976 ----a-w C:\Program Files\winamp533_full_emusic-7plus.exe 2007-03-05 18:06 4,003,432 ----a-w C:\Program Files\SweetImSetup.exe 2007-02-28 18:04 9,453,630 ----a-w C:\Program Files\vlc-0.8.6a-win32.exe 2007-02-28 14:08 4,222,516 ----a-w C:\Program Files\ABC-win32-v3.1.exe 2007-02-27 21:14 1,002,752 ----a-w C:\Program Files\JournalViewer1.5_KB886179_ENU.exe 2007-02-27 21:13 7,290,120 ----a-w C:\Program Files\setup.exe 2006-02-19 01:28 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll 2006-02-06 22:42 10,134 ----a-w C:\Program Files\Sims2EP3.ico . ((((((((((((((((((((((((((((( snapshot@2008-04-17_19.00.44.29 ))))))))))))))))))))))))))))))))))))))))) . - 2008-04-17 16:57:12 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2008-04-19 09:36:56 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2007-12-07 01:21:46 124,928 ------w C:\WINDOWS\ie7updates\KB947864-IE7\advpack.dll + 2007-12-19 22:01:06 347,136 ------w C:\WINDOWS\ie7updates\KB947864-IE7\dxtmsft.dll + 2007-12-07 01:21:46 214,528 ------w C:\WINDOWS\ie7updates\KB947864-IE7\dxtrans.dll + 2007-12-07 01:21:46 133,120 ------w C:\WINDOWS\ie7updates\KB947864-IE7\extmgr.dll + 2007-12-07 01:21:46 63,488 ------w C:\WINDOWS\ie7updates\KB947864-IE7\icardie.dll + 2007-12-06 10:00:58 70,656 ------w C:\WINDOWS\ie7updates\KB947864-IE7\ie4uinit.exe + 2007-12-07 01:21:46 153,088 ------w C:\WINDOWS\ie7updates\KB947864-IE7\ieakeng.dll + 2007-12-07 01:21:46 230,400 ------w C:\WINDOWS\ie7updates\KB947864-IE7\ieaksie.dll + 2007-12-06 03:59:52 161,792 ------w C:\WINDOWS\ie7updates\KB947864-IE7\ieakui.dll + 2007-12-07 01:21:46 383,488 ------w C:\WINDOWS\ie7updates\KB947864-IE7\ieapfltr.dll + 2007-12-07 01:21:46 384,512 ------w C:\WINDOWS\ie7updates\KB947864-IE7\iedkcs32.dll + 2007-12-07 01:21:46 6,066,176 ------w C:\WINDOWS\ie7updates\KB947864-IE7\ieframe.dll + 2007-12-07 01:21:46 44,544 ------w C:\WINDOWS\ie7updates\KB947864-IE7\iernonce.dll + 2007-12-07 01:21:46 267,776 ------w C:\WINDOWS\ie7updates\KB947864-IE7\iertutil.dll + 2007-12-06 10:00:58 13,824 ------w C:\WINDOWS\ie7updates\KB947864-IE7\ieudinit.exe + 2007-12-06 10:01:26 625,664 ------w C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe + 2007-12-07 01:21:48 27,648 ------w C:\WINDOWS\ie7updates\KB947864-IE7\jsproxy.dll + 2007-12-07 01:21:48 459,264 ------w C:\WINDOWS\ie7updates\KB947864-IE7\msfeeds.dll + 2007-12-07 01:21:48 52,224 ------w C:\WINDOWS\ie7updates\KB947864-IE7\msfeedsbs.dll + 2007-12-08 04:21:48 3,592,192 ------w C:\WINDOWS\ie7updates\KB947864-IE7\mshtml.dll + 2007-12-07 01:21:48 478,208 ------w C:\WINDOWS\ie7updates\KB947864-IE7\mshtmled.dll + 2007-12-07 01:21:48 193,024 ------w C:\WINDOWS\ie7updates\KB947864-IE7\msrating.dll + 2007-12-07 01:21:48 671,232 ------w C:\WINDOWS\ie7updates\KB947864-IE7\mstime.dll + 2007-12-07 01:21:48 102,912 ------w C:\WINDOWS\ie7updates\KB947864-IE7\occache.dll + 2008-01-11 04:53:32 44,544 ------w C:\WINDOWS\ie7updates\KB947864-IE7\pngfilt.dll + 2007-03-06 01:22:40 213,216 ------w C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe + 2007-03-06 01:23:52 371,424 ------w C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\updspapi.dll + 2007-12-07 01:21:48 105,984 ------w C:\WINDOWS\ie7updates\KB947864-IE7\url.dll + 2007-12-07 01:21:48 1,159,680 ------w C:\WINDOWS\ie7updates\KB947864-IE7\urlmon.dll + 2007-12-07 01:21:48 233,472 ------w C:\WINDOWS\ie7updates\KB947864-IE7\webcheck.dll + 2007-12-07 01:21:48 824,832 ------w C:\WINDOWS\ie7updates\KB947864-IE7\wininet.dll - 2008-03-21 01:03:00 12,288 ----a-r C:\WINDOWS\Installer\{91120414-6000-11D3-8CFE-0150048383C9}\cagicon.exe + 2008-04-17 22:05:34 12,288 ----a-r C:\WINDOWS\Installer\{91120414-6000-11D3-8CFE-0150048383C9}\cagicon.exe - 2008-03-21 01:03:00 135,168 ----a-r C:\WINDOWS\Installer\{91120414-6000-11D3-8CFE-0150048383C9}\misc.exe + 2008-04-17 22:05:32 135,168 ----a-r C:\WINDOWS\Installer\{91120414-6000-11D3-8CFE-0150048383C9}\misc.exe - 2008-03-21 01:03:00 11,264 ----a-r C:\WINDOWS\Installer\{91120414-6000-11D3-8CFE-0150048383C9}\mspicons.exe + 2008-04-17 22:05:34 11,264 ----a-r C:\WINDOWS\Installer\{91120414-6000-11D3-8CFE-0150048383C9}\mspicons.exe - 2008-03-21 01:03:00 27,136 ----a-r C:\WINDOWS\Installer\{91120414-6000-11D3-8CFE-0150048383C9}\oisicon.exe + 2008-04-17 22:05:34 27,136 ----a-r C:\WINDOWS\Installer\{91120414-6000-11D3-8CFE-0150048383C9}\oisicon.exe - 2008-03-21 01:03:00 4,096 ----a-r C:\WINDOWS\Installer\{91120414-6000-11D3-8CFE-0150048383C9}\opwicon.exe + 2008-04-17 22:05:34 4,096 ----a-r C:\WINDOWS\Installer\{91120414-6000-11D3-8CFE-0150048383C9}\opwicon.exe - 2008-03-21 01:03:00 794,624 ----a-r C:\WINDOWS\Installer\{91120414-6000-11D3-8CFE-0150048383C9}\outicon.exe + 2008-04-17 22:05:34 794,624 ----a-r C:\WINDOWS\Installer\{91120414-6000-11D3-8CFE-0150048383C9}\outicon.exe - 2008-03-21 01:03:00 249,856 ----a-r C:\WINDOWS\Installer\{91120414-6000-11D3-8CFE-0150048383C9}\pptico.exe + 2008-04-17 22:05:32 249,856 ----a-r C:\WINDOWS\Installer\{91120414-6000-11D3-8CFE-0150048383C9}\pptico.exe - 2008-03-21 01:03:00 23,040 ----a-r C:\WINDOWS\Installer\{91120414-6000-11D3-8CFE-0150048383C9}\unbndico.exe + 2008-04-17 22:05:34 23,040 ----a-r C:\WINDOWS\Installer\{91120414-6000-11D3-8CFE-0150048383C9}\unbndico.exe - 2008-03-21 01:03:00 286,720 ----a-r C:\WINDOWS\Installer\{91120414-6000-11D3-8CFE-0150048383C9}\wordicon.exe + 2008-04-17 22:05:32 286,720 ----a-r C:\WINDOWS\Installer\{91120414-6000-11D3-8CFE-0150048383C9}\wordicon.exe - 2008-03-21 01:03:00 409,600 ----a-r C:\WINDOWS\Installer\{91120414-6000-11D3-8CFE-0150048383C9}\xlicons.exe + 2008-04-17 22:05:32 409,600 ----a-r C:\WINDOWS\Installer\{91120414-6000-11D3-8CFE-0150048383C9}\xlicons.exe - 2007-12-07 01:21:46 124,928 ----a-w C:\WINDOWS\system32\advpack.dll + 2008-03-01 13:06:20 124,928 ----a-w C:\WINDOWS\system32\advpack.dll - 2007-12-07 01:21:46 124,928 ----a-w C:\WINDOWS\system32\dllcache\advpack.dll + 2008-03-01 13:06:20 124,928 ----a-w C:\WINDOWS\system32\dllcache\advpack.dll - 2007-12-19 22:01:06 347,136 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll + 2008-03-01 13:06:22 347,136 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll - 2007-12-07 01:21:46 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll + 2008-03-01 13:06:22 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll - 2007-12-07 01:21:46 133,120 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll + 2008-03-01 13:06:22 133,120 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll - 2007-12-07 01:21:46 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll + 2008-03-01 13:06:22 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll - 2007-12-07 01:21:46 153,088 ----a-w C:\WINDOWS\system32\dllcache\ieakeng.dll + 2008-03-01 13:06:22 153,088 ----a-w C:\WINDOWS\system32\dllcache\ieakeng.dll - 2007-12-07 01:21:46 230,400 ----a-w C:\WINDOWS\system32\dllcache\ieaksie.dll + 2008-03-01 13:06:22 230,400 ----a-w C:\WINDOWS\system32\dllcache\ieaksie.dll - 2007-12-07 01:21:46 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll + 2008-03-01 13:06:22 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll - 2007-12-07 01:21:46 384,512 ----a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll + 2008-03-01 13:06:22 384,512 ----a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll - 2007-12-07 01:21:46 6,066,176 ------w C:\WINDOWS\system32\dllcache\ieframe.dll + 2008-03-01 13:06:24 6,066,176 ------w C:\WINDOWS\system32\dllcache\ieframe.dll - 2007-12-07 01:21:46 44,544 ----a-w C:\WINDOWS\system32\dllcache\iernonce.dll + 2008-03-01 13:06:24 44,544 ----a-w C:\WINDOWS\system32\dllcache\iernonce.dll - 2007-12-07 01:21:46 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll + 2008-03-01 13:06:26 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll - 2007-12-07 01:21:48 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll + 2008-03-01 13:06:26 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll - 2007-12-07 01:21:48 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll + 2008-03-01 13:06:26 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll - 2007-12-07 01:21:48 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll + 2008-03-01 13:06:26 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll - 2007-12-07 01:21:48 478,208 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll + 2008-03-01 13:06:28 478,208 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll - 2007-12-07 01:21:48 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll + 2008-03-01 13:06:28 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll - 2007-12-07 01:21:48 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll + 2008-03-01 13:06:30 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll - 2007-12-07 01:21:48 102,912 ----a-w C:\WINDOWS\system32\dllcache\occache.dll + 2008-03-01 13:06:30 102,912 ----a-w C:\WINDOWS\system32\dllcache\occache.dll - 2008-01-11 04:53:32 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll + 2008-03-01 13:06:30 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll - 2007-12-07 01:21:48 105,984 ----a-w C:\WINDOWS\system32\dllcache\url.dll + 2008-03-01 13:06:30 105,984 ----a-w C:\WINDOWS\system32\dllcache\url.dll - 2007-12-07 01:21:48 1,159,680 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll + 2008-03-01 13:06:30 1,159,680 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll - 2007-12-07 01:21:48 233,472 ----a-w C:\WINDOWS\system32\dllcache\webcheck.dll + 2008-03-01 13:06:30 233,472 ----a-w C:\WINDOWS\system32\dllcache\webcheck.dll - 2007-12-07 01:21:48 824,832 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll + 2008-03-01 13:06:32 826,368 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll - 2006-06-26 17:37:10 148,480 ----a-w C:\WINDOWS\system32\dnsapi.dll + 2008-02-20 05:32:44 148,992 ----a-w C:\WINDOWS\system32\dnsapi.dll + 2008-03-29 17:26:52 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys - 2007-12-19 22:01:06 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll + 2008-03-01 13:06:22 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll - 2007-12-07 01:21:46 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll + 2008-03-01 13:06:22 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll - 2007-12-07 01:21:46 133,120 ----a-w C:\WINDOWS\system32\extmgr.dll + 2008-03-01 13:06:22 133,120 ----a-w C:\WINDOWS\system32\extmgr.dll - 2008-03-31 19:09:26 1,424,152 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT + 2008-04-18 09:22:42 1,424,152 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT - 2007-12-07 01:21:46 63,488 ----a-w C:\WINDOWS\system32\icardie.dll + 2008-03-01 13:06:22 63,488 ----a-w C:\WINDOWS\system32\icardie.dll - 2007-12-06 10:00:58 70,656 ----a-w C:\WINDOWS\system32\ie4uinit.exe + 2008-02-29 08:55:24 70,656 ----a-w C:\WINDOWS\system32\ie4uinit.exe - 2007-12-07 01:21:46 153,088 ----a-w C:\WINDOWS\system32\ieakeng.dll + 2008-03-01 13:06:22 153,088 ----a-w C:\WINDOWS\system32\ieakeng.dll - 2007-12-07 01:21:46 230,400 ----a-w C:\WINDOWS\system32\ieaksie.dll + 2008-03-01 13:06:22 230,400 ----a-w C:\WINDOWS\system32\ieaksie.dll - 2007-12-06 03:59:52 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll + 2008-02-15 05:44:26 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll - 2007-12-07 01:21:46 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll + 2008-03-01 13:06:22 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll - 2007-12-07 01:21:46 384,512 ----a-w C:\WINDOWS\system32\iedkcs32.dll + 2008-03-01 13:06:22 384,512 ----a-w C:\WINDOWS\system32\iedkcs32.dll - 2007-12-07 01:21:46 6,066,176 ----a-w C:\WINDOWS\system32\ieframe.dll + 2008-03-01 13:06:24 6,066,176 ----a-w C:\WINDOWS\system32\ieframe.dll - 2007-12-07 01:21:46 44,544 ----a-w C:\WINDOWS\system32\iernonce.dll + 2008-03-01 13:06:24 44,544 ----a-w C:\WINDOWS\system32\iernonce.dll - 2007-12-07 01:21:46 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll + 2008-03-01 13:06:26 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll - 2007-12-06 10:00:58 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe + 2008-02-22 10:00:52 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe - 2007-12-07 01:21:48 27,648 ----a-w C:\WINDOWS\system32\jsproxy.dll + 2008-03-01 13:06:26 27,648 ----a-w C:\WINDOWS\system32\jsproxy.dll + 2008-04-05 20:56:22 19,836,024 ----a-w C:\WINDOWS\system32\MRT.exe - 2007-12-07 01:21:48 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll + 2008-03-01 13:06:26 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll - 2007-12-07 01:21:48 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll + 2008-03-01 13:06:26 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll - 2007-12-08 04:21:48 3,592,192 ----a-w C:\WINDOWS\system32\mshtml.dll + 2008-03-01 16:36:30 3,591,680 ----a-w C:\WINDOWS\system32\mshtml.dll - 2007-12-07 01:21:48 478,208 ----a-w C:\WINDOWS\system32\mshtmled.dll + 2008-03-01 13:06:28 478,208 ----a-w C:\WINDOWS\system32\mshtmled.dll - 2007-12-07 01:21:48 193,024 ----a-w C:\WINDOWS\system32\msrating.dll + 2008-03-01 13:06:28 193,024 ----a-w C:\WINDOWS\system32\msrating.dll - 2007-12-07 01:21:48 671,232 ----a-w C:\WINDOWS\system32\mstime.dll + 2008-03-01 13:06:30 671,232 ----a-w C:\WINDOWS\system32\mstime.dll - 2007-12-07 01:21:48 102,912 ----a-w C:\WINDOWS\system32\occache.dll + 2008-03-01 13:06:30 102,912 ----a-w C:\WINDOWS\system32\occache.dll - 2008-01-11 04:53:32 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll + 2008-03-01 13:06:30 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll - 2007-12-07 01:21:48 105,984 ----a-w C:\WINDOWS\system32\url.dll + 2008-03-01 13:06:30 105,984 ----a-w C:\WINDOWS\system32\url.dll - 2007-12-07 01:21:48 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll + 2008-03-01 13:06:30 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll - 2007-12-07 01:21:48 233,472 ----a-w C:\WINDOWS\system32\webcheck.dll + 2008-03-01 13:06:30 233,472 ----a-w C:\WINDOWS\system32\webcheck.dll - 2007-12-07 01:21:48 824,832 ----a-w C:\WINDOWS\system32\wininet.dll + 2008-03-01 13:06:32 826,368 ----a-w C:\WINDOWS\system32\wininet.dll + 2008-04-18 09:48:16 16,384 ----a-w C:\WINDOWS\TEMP\Perflib_Perfdata_5f8.dat . -- Snapshot reset to current date -- . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2007-12-13 17:49 1185120] [HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}] [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1] [HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}] [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-12-13 17:49 1185120] [HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}] [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1] [HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}] [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00 15360] "PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 16:21 1449984] "way tool"="C:\DOCUME~1\PSYCHO~1\APPLIC~1\DRIVEB~1\FunkObjSeek.exe" [ ] "DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 11:39 486856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 12:00 110592 C:\WINDOWS\system32\bthprops.cpl] "Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2005-11-11 20:40 1236992] "RTHDCPL"="RTHDCPL.EXE" [2006-12-18 19:12 16062464 C:\WINDOWS\RTHDCPL.exe] "SkyTel"="SkyTel.EXE" [2006-05-16 02:04 2879488 C:\WINDOWS\SkyTel.exe] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 13:07 761946] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784] "Acer OrbiCam"="C:\WINDOWS\AcerOrbiCam.exe" [2006-11-22 18:03 401408] "Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-05-02 08:08 366400] "PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-06-15 12:36 229376] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24 286720] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648] "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152] "beep for long support"="C:\Documents and Settings\All Users.WINDOWS\Application Data\view name beep for\proc style.exe" [ ] "LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [2006-07-20 22:15 593920] "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 12:17 94208] "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 12:13 77824] "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 12:17 118784] "Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792] "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcabxv] efcabxv.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\WINDOWS\\System32\\USMT\\MIGWIZ.EXE"= "C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"= "C:\\Program Files\\DC++\\DCPlusPlus.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\Bonjour\\mDNSResponder.exe"= "C:\\WINDOWS\\System32\\SPOOLSV.EXE"= "C:\\Program Files\\Trillian\\trillian.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"= "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"= "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "C:\\WINDOWS\\PCHEALTH\\HELPCTR\\BINARIES\\HelpCtr.exe"= R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3c6bd009-6ef5-11dc-b14b-0011f6069176}] \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bcd97731-4b19-11dc-b12f-0011f6069176}] \Shell\AutoRun\command - G:\LaunchU3.exe -a . ************************************************************************** catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-04-19 11:43:31 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-04-19 11:43:59 ComboFix-quarantined-files.txt 2008-04-19 09:43:58 Pre-Run: 36,364,877,824 bytes free Post-Run: 36,424,056,832 bytes free . 2008-04-17 22:06:06 --- E O F --- Klikk for å se/fjerne innholdet nedenfor Lenke til kommentar
snippsat Skrevet 19. april 2008 Del Skrevet 19. april 2008 (endret) Nå har du bare kjørt combofix. Du må lese post 14 nøye. Du skal gjøre som på bildet,da vil combofix starte av seg selv. Et det uklart får du spørre. Endret 19. april 2008 av SNIPPSAT Lenke til kommentar
killerbanana Skrevet 19. april 2008 Forfatter Del Skrevet 19. april 2008 Og vi prøvde enda en gang Håper det er riktig nå da. Klikk for å se/fjerne innholdet nedenfor ComboFix 08-04-16.5 - Psychopath 2008-04-19 14:56:13.4 - FAT32x86Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.589 [GMT 2:00] Running from: C:\Documents and Settings\Psychopath\My Documents\ComboFix.exe Command switches used :: C:\Documents and Settings\Psychopath\Desktop\CFScript.txt.txt * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((( Files Created from 2008-03-19 to 2008-04-19 ))))))))))))))))))))))))))))))) . 2008-04-19 11:36 . 2008-04-19 11:36 <DIR> d--hs---- C:\FOUND.013 2008-04-18 12:08 . 2008-04-18 12:08 <DIR> d-------- C:\Program Files\TSBin 2008-04-18 12:08 . 2008-04-18 12:08 <DIR> d-------- C:\Program Files\CSBin 2008-04-18 12:08 . 2006-02-07 02:47 278,528 --a------ C:\Program Files\Sims2EP3_Uninst.exe 2008-04-18 12:07 . 2008-04-18 12:07 <DIR> d-------- C:\Program Files\TSData 2008-04-17 21:25 . 2008-04-17 21:25 <DIR> d--hs---- C:\FOUND.012 2008-04-17 20:21 . 2008-04-17 20:21 <DIR> d--hs---- C:\FOUND.011 2008-04-17 19:10 . 2008-04-17 19:10 <DIR> d-------- C:\Program Files\Alwil Software 2008-04-17 19:10 . 2008-03-29 19:45 1,146,232 --a------ C:\WINDOWS\system32\aswBoot.exe 2008-04-17 19:10 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx 2008-04-17 19:10 . 2008-03-29 19:23 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr 2008-04-17 19:10 . 2008-03-29 19:35 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys 2008-04-17 19:10 . 2008-01-17 17:34 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys 2008-04-17 19:10 . 2008-03-29 19:31 75,856 --a------ C:\WINDOWS\system32\drivers\aswSP.sys 2008-04-17 19:10 . 2008-03-29 19:27 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys 2008-04-17 19:10 . 2008-03-29 19:26 26,944 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys 2008-04-17 19:10 . 2008-03-29 19:29 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys 2008-04-17 19:10 . 2008-03-29 19:35 20,560 --a------ C:\WINDOWS\system32\drivers\aswFsBlk.sys 2008-04-17 18:12 . 2008-04-17 18:12 <DIR> d-------- C:\VundoFix Backups 2008-04-17 17:48 . 2008-04-17 17:48 <DIR> d-------- C:\Program Files\Trend Micro 2008-04-17 16:24 . 2008-04-17 16:24 <DIR> d--h----- C:\WINDOWS\PIF 2008-04-16 16:20 . 2008-04-16 16:20 <DIR> d--hs---- C:\FOUND.010 2008-04-16 15:02 . 2008-04-16 15:02 <DIR> d-------- C:\Program Files\DAEMON Tools Lite 2008-04-16 14:57 . 2008-04-16 14:57 <DIR> d-------- C:\Documents and Settings\Psychopath\Application Data\DAEMON Tools 2008-04-15 20:42 . 2008-04-17 14:36 714 ---hs---- C:\WINDOWS\system32\shdakxsq.ini 2008-04-14 20:51 . 2008-04-14 20:51 354 ---hs---- C:\WINDOWS\system32\jagaevxi.ini 2008-04-13 20:47 . 2008-04-14 20:47 294 ---hs---- C:\WINDOWS\system32\wjbjnqij.ini 2008-04-12 20:46 . 2008-04-12 20:47 1,770 ---hs---- C:\WINDOWS\system32\khqtgqfl.ini 2008-04-11 20:44 . 2008-04-12 20:45 1,710 ---hs---- C:\WINDOWS\system32\amnkxvro.ini 2008-04-10 19:26 . 2008-04-11 20:44 1,306 ---hs---- C:\WINDOWS\system32\cadxdmsn.ini 2008-04-09 19:31 . 2008-04-10 18:05 1,186 ---hs---- C:\WINDOWS\system32\rcevadll.ini 2008-04-08 19:27 . 2008-04-09 19:31 1,006 ---hs---- C:\WINDOWS\system32\chklojfa.ini 2008-04-08 18:06 . 2008-04-08 18:06 <DIR> d--hs---- C:\FOUND.009 2008-04-07 19:22 . 2008-04-08 18:15 886 ---hs---- C:\WINDOWS\system32\kjlsckbe.ini 2008-04-06 19:20 . 2008-04-07 19:04 818 ---hs---- C:\WINDOWS\system32\limdyjxh.ini 2008-04-05 19:19 . 2008-04-07 19:20 706 ---hs---- C:\WINDOWS\system32\yykbkinr.ini 2008-04-04 18:14 . 2008-04-05 19:15 354 ---hs---- C:\WINDOWS\system32\lxnmnuqf.ini 2008-04-03 21:22 . 2008-04-03 21:22 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-04-03 21:22 . 2008-04-03 21:22 1,409 --a------ C:\WINDOWS\QTFont.for 2008-04-03 18:13 . 2008-04-04 15:29 894 ---hs---- C:\WINDOWS\system32\ksbnganl.ini 2008-04-02 18:13 . 2008-04-03 16:43 714 ---hs---- C:\WINDOWS\system32\bhiuinkp.ini 2008-04-01 18:09 . 2008-04-02 14:08 594 ---hs---- C:\WINDOWS\system32\mmgvpkth.ini 2008-03-31 21:16 . 2008-04-01 02:00 594 ---hs---- C:\WINDOWS\system32\afnbseme.ini 2008-03-30 22:23 . 2008-03-31 21:10 534 ---hs---- C:\WINDOWS\system32\pddmknfy.ini 2008-03-29 21:17 . 2008-03-30 22:17 414 ---hs---- C:\WINDOWS\system32\xcmnynpg.ini 2008-03-29 20:07 . 2008-03-29 21:09 354 ---hs---- C:\WINDOWS\system32\ggahnfwk.ini 2008-03-28 20:01 . 2008-04-17 14:35 101,091 --a------ C:\WINDOWS\BM1e3c22e6.xml . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-04-19 09:41 2,752 ----a-w C:\WINDOWS\system32\PerfStringBackup.TMP 2008-04-16 12:57 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys 2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys 2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys 2008-03-14 05:50 --------- d-----w C:\Program Files\EA GAMES 2008-03-06 19:32 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf 2008-03-06 19:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys 2008-03-06 19:32 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat 2008-03-03 13:57 --------- d-sh--w C:\Program Files\Common Files\WindowsLiveInstaller 2008-03-03 13:56 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\WLInstaller 2008-03-01 16:36 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll 2008-02-29 08:55 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe 2008-02-29 08:55 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe 2008-02-22 10:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe 2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll 2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\dllcache\gdi32.dll 2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll 2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll 2008-02-20 05:32 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll 2008-02-19 12:48 --------- d-----w C:\Program Files\Den lengste reisen 2008-02-19 11:03 --------- d-----w C:\Program Files\directx 2008-02-15 05:44 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll 2007-03-31 08:02 44,541,440 ----a-w C:\Program Files\fsavcs_603_spion-og_virusvern_internetshield_webscan_emailscan_(komplett).msi 2007-03-16 12:49 19,994,184 ----a-w C:\Program Files\QuickTimeInstaller.exe 2007-03-15 17:50 727,138,334 ----a-w C:\Program Files\MyCDExtra.ncd 2007-03-12 17:59 552,448 ----a-w C:\Program Files\matpakke.pps 2007-03-10 16:18 6,718,976 ----a-w C:\Program Files\winamp533_full_emusic-7plus.exe 2007-03-05 18:06 4,003,432 ----a-w C:\Program Files\SweetImSetup.exe 2007-02-28 18:04 9,453,630 ----a-w C:\Program Files\vlc-0.8.6a-win32.exe 2007-02-28 14:08 4,222,516 ----a-w C:\Program Files\ABC-win32-v3.1.exe 2007-02-27 21:14 1,002,752 ----a-w C:\Program Files\JournalViewer1.5_KB886179_ENU.exe 2007-02-27 21:13 7,290,120 ----a-w C:\Program Files\setup.exe 2006-02-19 01:28 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll 2006-02-06 22:42 10,134 ----a-w C:\Program Files\Sims2EP3.ico . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2007-12-13 17:49 1185120] [HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}] [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1] [HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}] [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-12-13 17:49 1185120] [HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}] [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1] [HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}] [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00 15360] "PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 16:21 1449984] "way tool"="C:\DOCUME~1\PSYCHO~1\APPLIC~1\DRIVEB~1\FunkObjSeek.exe" [ ] "DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 11:39 486856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 12:00 110592 C:\WINDOWS\system32\bthprops.cpl] "Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2005-11-11 20:40 1236992] "RTHDCPL"="RTHDCPL.EXE" [2006-12-18 19:12 16062464 C:\WINDOWS\RTHDCPL.exe] "SkyTel"="SkyTel.EXE" [2006-05-16 02:04 2879488 C:\WINDOWS\SkyTel.exe] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 13:07 761946] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784] "Acer OrbiCam"="C:\WINDOWS\AcerOrbiCam.exe" [2006-11-22 18:03 401408] "Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-05-02 08:08 366400] "PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-06-15 12:36 229376] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24 286720] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648] "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152] "beep for long support"="C:\Documents and Settings\All Users.WINDOWS\Application Data\view name beep for\proc style.exe" [ ] "LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [2006-07-20 22:15 593920] "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 12:17 94208] "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 12:13 77824] "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 12:17 118784] "Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792] "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcabxv] efcabxv.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\WINDOWS\\System32\\USMT\\MIGWIZ.EXE"= "C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"= "C:\\Program Files\\DC++\\DCPlusPlus.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\Bonjour\\mDNSResponder.exe"= "C:\\WINDOWS\\System32\\SPOOLSV.EXE"= "C:\\Program Files\\Trillian\\trillian.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"= "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"= "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "C:\\WINDOWS\\PCHEALTH\\HELPCTR\\BINARIES\\HelpCtr.exe"= R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3c6bd009-6ef5-11dc-b14b-0011f6069176}] \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bcd97731-4b19-11dc-b12f-0011f6069176}] \Shell\AutoRun\command - G:\LaunchU3.exe -a . ************************************************************************** catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-04-19 14:57:06 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... C:\WINDOWS\Explorer.EXE [3388] 0x860D4590 scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-04-19 14:57:31 ComboFix-quarantined-files.txt 2008-04-19 12:57:30 ComboFix2.txt 2008-04-19 09:44:02 Pre-Run: 36,314,284,032 bytes free Post-Run: 36,310,482,944 bytes free . 2008-04-17 22:06:06 --- E O F --- Klikk for å se/fjerne innholdet nedenfor Lenke til kommentar
snippsat Skrevet 19. april 2008 Del Skrevet 19. april 2008 (endret) Nei det ikke som det skal. Hjelpe litt. Slett gamel logg c:\combofix.txt Legg denne filen på skrivebordet. Høyere klikk"lagre mål som"->velg skrivebordet. http://dump.no/files/9e799fdfdd1b/CFScript.txt Da skal du ha combofix og CFScript.txt på skrivebordet. Da skal du dra CFScript.txt over til combofix"som på bildet" Når du har gjort dette vil comobofix starte. Og du poster logg c:\combofix.txt Endret 19. april 2008 av SNIPPSAT Lenke til kommentar
Anbefalte innlegg
Opprett en konto eller logg inn for å kommentere
Du må være et medlem for å kunne skrive en kommentar
Opprett konto
Det er enkelt å melde seg inn for å starte en ny konto!
Start en kontoLogg inn
Har du allerede en konto? Logg inn her.
Logg inn nå