Jag har lite problem med min dator, den är lite seg och så df körde jag också
samma program (ComboFix) som du rekomenderade o här är logen:
Tack så jättemycket! kolla om det är något strull!
ComboFix 10-07-22.06 - bou 2010-07-23 21:22:10.1.1 - x86
Körs från: c:\documents and settings\bou\Skrivbord\ComboFix.exe
* Skapade en ny återställningspunkt
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\bou\Application Data\chrtmp
c:\documents and settings\bou\Start-meny\Program\Mach7.lnk
c:\program\Delade filer\m7
c:\program\Delade filer\m7\finish_install.exe
c:\program\Delade filer\m7\in.vbs
c:\program\Delade filer\m7\licence.txt
c:\program\Delade filer\m7\mach7.dat
c:\program\Delade filer\m7\mach7.exe
c:\program\Delade filer\m7\mach7ico.ico
c:\program\Delade filer\m7\startm7.bat
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000009_.tmp.dll
c:\windows\system32\fonts
c:\windows\system32\fonts\DataStudioSymbol.TTF
c:\windows\system32\mxpvct22.dat
c:\windows\system32\mxpvct25.dat
c:\windows\Temp\_ex-08.exe
----- BITS: Troligen infekterade webbplatser -----
hxxp://www.podtrac.com
hxxp://libsyn.com
.
((((((((((((((((((((((((((((((((((((((( Drivrutiner/Tjänster )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SSHNAS
(((((((((((((((((((((((( Filer Skapade från 2010-06-23 till 2010-07-23 ))))))))))))))))))))))))))))))
.
2010-07-23 19:34 . 2010-07-23 19:34 -------- dc----w- c:\temp\WPDNSE
2010-07-23 19:33 . 2010-07-23 19:33 53248 -c--a-w- c:\temp\catchme.dll
2010-07-23 19:32 . 2010-07-23 19:32 16384 -c--atw- c:\temp\Perflib_Perfdata_154.dat
2010-07-23 10:36 . 2010-07-23 19:26 -------- dc----w- c:\temp\div9.tmp
2010-07-21 10:05 . 2010-07-21 10:05 -------- dc----w- c:\temp\div3.tmp
2010-07-19 22:12 . 2010-07-22 19:11 -------- dc----w- c:\documents and settings\bou\Application Data\vlc
2010-07-19 22:09 . 2010-07-19 22:09 -------- dc----w- c:\documents and settings\bou\Lokala inst�llningar
2010-07-19 22:03 . 2010-07-19 22:03 -------- dc----w- c:\documents and settings\bou\Application Data\MozillaControl
2010-07-19 22:03 . 2010-07-23 19:26 -------- dc----w- c:\temp\{1D2C96C3-A3F3-49E7-B839-95279DED837F}
2010-07-19 22:01 . 2010-07-19 22:01 -------- dc----w- c:\program\Mozilla ActiveX Control v1.7.12
2010-07-19 21:57 . 2010-07-19 22:25 -------- dc----w- c:\program\Graboid
2010-07-19 20:12 . 2010-07-23 19:26 -------- dc----w- c:\temp\divBA.tmp
2010-07-14 15:11 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-14 15:08 . 2010-07-14 15:08 -------- dc----w- c:\temp\msohtml1
2010-07-14 15:08 . 2010-07-14 15:08 -------- dc----w- c:\temp\msohtml
2010-07-14 14:57 . 2010-07-14 14:57 -------- dc----w- c:\temp\VBE
2010-07-14 13:37 . 2010-07-23 19:26 -------- dc----w- c:\temp\iss1D.tmp
2010-07-14 13:19 . 2010-07-14 13:19 -------- dc----w- c:\temp\div16.tmp
2010-07-14 13:18 . 2010-07-23 19:26 -------- dc----w- c:\temp\is-TE48T.tmp
2010-07-14 12:58 . 2010-07-14 13:24 -------- dc----w- c:\temp\comtypes_cache
2010-07-14 11:51 . 2010-07-14 11:51 -------- dc----w- c:\windows\system32\wbem\Repository
2010-07-14 11:11 . 2010-07-14 11:54 766976 -c--a-w- c:\windows\system32\drivers\djscd.sys
2010-07-14 11:02 . 2010-07-20 22:00 -------- dc----w- c:\temp\hsperfdata_bou
2010-07-14 10:58 . 2010-07-14 10:58 -------- dc----w- c:\temp\div5.tmp
2010-07-13 21:02 . 2010-07-23 19:26 -------- dc----w- c:\temp\MessengerCache
2010-07-13 19:01 . 2010-07-13 19:01 -------- dc----w- c:\documents and settings\All Users\Application Data\wanted_demo
2010-07-13 18:48 . 2010-07-13 18:48 -------- dc----w- c:\program\WarnerBros
2010-07-13 14:52 . 2010-07-13 14:52 -------- dc----w- c:\program\AGEIA Technologies
2010-07-13 14:52 . 2010-07-13 14:52 -------- dc----w- c:\windows\system32\AGEIA
2010-07-13 14:46 . 2010-07-13 14:46 -------- dc----w- c:\program\Delade filer\Wise Installation Wizard
2010-07-13 09:47 . 2010-07-23 19:26 -------- dc----w- c:\temp\divA.tmp
2010-07-12 14:56 . 2010-07-12 14:56 -------- dc----w- c:\program\Thomas Wright Consulting
2010-07-11 11:08 . 2010-07-11 11:08 -------- dc----w- c:\windows\BBSTORE
2010-07-11 11:08 . 1997-05-12 14:53 314368 -c--a-w- c:\windows\IsUninst.exe
2010-07-11 10:51 . 2010-07-11 10:51 -------- dc----w- c:\program\Telia
2010-07-11 10:51 . 2010-07-11 10:51 -------- dc----w- c:\documents and settings\All Users\Application Data\Support.com
2010-07-10 19:16 . 2010-07-10 19:16 -------- dc----w- c:\windows\system32\winrm
2010-07-10 19:15 . 2010-07-10 19:16 -------- dc-h--w- c:\windows\$968930Uinstall_KB968930$
2010-07-10 14:17 . 2010-07-12 15:04 -------- dc----w- c:\program\MAGIX
2010-07-10 14:17 . 2010-07-12 15:04 -------- dc----w- c:\documents and settings\All Users\Application Data\MAGIX
2010-07-10 13:53 . 2010-07-10 14:56 -------- dc----w- c:\program\Ace Translator
2010-07-10 11:29 . 2010-07-10 11:29 -------- dc----w- c:\documents and settings\All Users\Application Data\Boss Media
2010-07-08 19:56 . 2010-07-08 19:58 -------- dc----w- c:\windows\uninstall
2010-07-08 17:14 . 2010-07-08 17:14 -------- dc----w- c:\documents and settings\bou\Application Data\Need for Speed World
2010-07-08 14:39 . 2010-07-08 14:39 -------- dc----w- c:\program\Ask.com
2010-07-08 14:39 . 2010-07-08 14:39 -------- dc----w- c:\program\Adobe PhotoShop CS3
2010-07-08 14:38 . 2010-07-08 14:38 -------- dc----w- c:\program\Vuze_Remote
2010-07-08 14:38 . 2010-07-08 14:38 -------- dc----w- c:\program\Windows Desktop Search
2010-07-08 14:38 . 2010-07-08 14:38 -------- dc----w- c:\program\PhotoFiltre
2010-07-08 14:38 . 2010-07-08 14:38 -------- dc----w- c:\program\Xara
2010-07-08 14:38 . 2010-07-14 13:37 -------- dc----w- c:\program\Uniblue
2010-07-08 14:38 . 2010-07-08 14:38 -------- dc----w- c:\program\UnHackMe
2010-07-08 14:38 . 2010-07-08 14:38 -------- dc----r- c:\program\Net Nanny
2010-07-08 14:36 . 2010-07-08 16:25 -------- dc----w- c:\program\Delade filer\Adobe AIR
2010-07-08 13:13 . 2010-07-08 13:13 -------- dc----w- c:\documents and settings\bou\Application Data\AdobeSupportAdvisor.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1
2010-07-08 13:13 . 2010-07-08 14:36 -------- dc----w- c:\program\AdobeSupportAdvisor
2010-07-08 13:13 . 2010-07-08 13:13 -------- dc----w- c:\program\Delade filer\Adobe AIR(3)
2010-07-07 10:29 . 2010-07-07 10:29 -------- dc----w- c:\program\Activision
2010-07-04 20:04 . 2010-07-04 20:05 -------- dc----w- c:\documents and settings\All Users\Application Data\PlatinumHideIP
2010-07-04 20:04 . 2010-07-04 20:04 -------- dc----w- c:\documents and settings\bou\Application Data\PlatinumHideIP
2010-07-04 18:41 . 2010-07-04 20:03 -------- dc----w- c:\documents and settings\bou\Application Data\DVD Flick
2010-07-04 18:40 . 2010-07-04 18:41 -------- dc----w- c:\program\DVD Flick
2010-07-03 23:20 . 2010-07-03 23:20 138056 -c--a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-07-03 23:20 . 2010-07-03 23:20 189248 -c--a-w- c:\windows\system32\PnkBstrB.exe
2010-07-03 23:20 . 2010-07-03 23:20 75064 -c--a-w- c:\windows\system32\PnkBstrA.exe
2010-07-03 23:20 . 2010-07-03 23:20 2434856 -c--a-w- c:\windows\system32\pbsvc_bc2.exe
2010-07-02 16:54 . 2010-07-02 16:54 -------- dcsh--w- c:\documents and settings\NetworkService\IETldCache
2010-07-01 19:53 . 2010-07-01 19:53 -------- dc----w- c:\documents and settings\bou\Application Data\CheeseSoft
2010-07-01 19:53 . 2010-07-01 19:54 -------- dc----w- c:\program\FinalUninstaller
2010-06-27 15:36 . 2010-07-14 12:00 -------- dc----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-06-27 15:36 . 2010-06-30 11:11 -------- dc----w- c:\program\Spybot - Search & Destroy
2010-06-26 19:39 . 2010-06-26 19:39 2 -cshatr- c:\windows\winstart.bat
2010-06-26 00:06 . 2010-06-26 00:06 -------- dc----w- c:\program\Conduit
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-23 19:32 . 2008-05-08 02:12 -------- dc----w- c:\program\NORMAN
2010-07-22 19:11 . 2010-07-19 22:12 -------- dc----w- c:\documents and settings\bou\Application Data\vlc
2010-07-19 22:49 . 2010-01-11 16:44 -------- dc----w- c:\documents and settings\bou\Application Data\uTorrent
2010-07-19 20:34 . 2010-02-03 17:56 -------- dc----w- c:\documents and settings\bou\Application Data\U3
2010-07-14 13:13 . 2010-05-07 17:01 -------- dc----w- c:\documents and settings\bou\Application Data\Uniblue
2010-07-13 18:48 . 2010-07-13 18:48 -------- dc----w- c:\program\WarnerBros
2010-07-13 18:48 . 2006-10-03 06:21 -------- dc-h--w- c:\program\InstallShield Installation Information
2010-07-11 10:58 . 2010-05-16 14:46 -------- dc----w- c:\program\MagicISO
2010-07-10 11:58 . 2010-06-14 16:59 57344 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-07-10 11:58 . 2010-05-07 21:03 -------- dc----w- c:\documents and settings\All Users\Application Data\DivX
2010-07-10 11:57 . 2010-07-10 11:57 56765 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-07-10 11:57 . 2010-05-07 21:05 -------- dc----w- c:\program\DivX
2010-07-10 11:57 . 2010-07-10 11:57 57715 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\Player\Uninstaller.exe
2010-07-10 11:57 . 2010-07-10 11:57 84054 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\TransferWizard\Uninstaller.exe
2010-07-10 11:56 . 2010-07-10 11:56 54153 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\DFXPlugin\Uninstaller.exe
2010-07-10 11:56 . 2010-06-16 17:39 1062184 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-07-10 11:54 . 2010-06-16 17:39 895256 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-07-08 16:24 . 2010-07-08 16:25 53632 -c--a-w- c:\documents and settings\bou\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-07-08 16:23 . 2010-07-08 16:23 12124624 -c--a-w- c:\documents and settings\bou\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airinstaller2x0\airinstaller2x0.exe
2010-07-08 15:42 . 2010-02-11 14:34 -------- dc----w- c:\program\Delade filer\Adobe
2010-07-08 14:38 . 2010-07-08 14:38 -------- dc----w- c:\program\Vuze_Remote
2010-07-04 18:46 . 2010-05-16 13:55 -------- dc----w- c:\documents and settings\bou\Application Data\ImgBurn
2010-07-04 18:45 . 2010-05-15 23:19 -------- dc----w- c:\program\ImgBurn
2010-07-03 23:20 . 2010-07-03 23:20 138056 -c--a-w- c:\documents and settings\bou\Application Data\PnkBstrK.sys
2010-07-03 23:20 . 2010-07-03 23:20 138056 -c--a-w- c:\documents and settings\bou\Application Data\PnkBstrK.sys
2010-07-01 22:16 . 2010-01-13 19:55 -------- dc----w- c:\documents and settings\bou\Application Data\HpUpdate
2010-07-01 21:26 . 2010-05-25 20:57 -------- dc----w- c:\program\Ubisoft
2010-07-01 20:11 . 2010-03-29 16:49 -------- dc----w- c:\documents and settings\bou\Application Data\Apple Computer
2010-07-01 15:30 . 2010-03-28 17:18 -------- dc--a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-01 14:20 . 2008-05-08 02:16 -------- dc----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-06-30 19:54 . 2006-05-02 12:05 -------- dc----w- c:\program\Google
2010-06-30 13:33 . 2010-05-25 21:21 -------- dc----w- c:\program\CCleaner
2010-06-28 12:17 . 2010-04-25 08:27 1324 -c--a-w- c:\windows\system32\d3d9caps.dat
2010-06-24 21:50 . 2008-05-30 08:03 -------- dc----w- c:\program\HP
2010-06-21 23:36 . 2010-03-24 20:19 -------- dc----w- c:\program\Free FLV Converter
2010-06-21 19:14 . 2010-06-21 19:14 0 -c-ha-w- c:\windows\system32\drivers\Msft_Kernel_SynTP_01009.Wdf
2010-06-21 19:14 . 2010-06-21 19:14 0 -c-ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2010-06-21 18:11 . 2010-05-29 10:14 -------- dc----w- c:\documents and settings\bou\Application Data\Dream Aquarium
2010-06-21 15:26 . 2010-06-21 15:24 -------- dc----w- c:\program\PcMedik
2010-06-19 19:54 . 2010-06-23 10:24 168448 -c--a-w- c:\windows\Wpicug.exe
2010-06-19 19:54 . 2010-06-22 12:01 168448 -c--a-w- c:\windows\Wpicuf.exe
2010-06-19 19:54 . 2010-06-21 23:49 168448 -c--a-w- c:\windows\Wpicue.exe
2010-06-19 19:54 . 2010-06-21 16:14 168448 -c--a-w- c:\windows\Wpicud.exe
2010-06-19 19:54 . 2010-06-21 09:02 168448 -c--a-w- c:\windows\Wpicuc.exe
2010-06-19 19:54 . 2010-06-20 10:47 168448 -c--a-w- c:\windows\Wpicub.exe
2010-06-19 19:53 . 2010-06-19 19:53 168448 -c--a-w- c:\windows\Wpicua.exe
2010-06-19 12:08 . 2010-06-19 12:08 -------- dc----w- c:\program\Saitek
2010-06-18 19:34 . 2010-02-27 14:29 -------- dc----w- c:\program\Windows Live Safety Center
2010-06-18 11:40 . 2004-08-04 12:00 84650 -c--a-w- c:\windows\system32\perfc01D.dat
2010-06-18 11:40 . 2004-08-04 12:00 446102 -c--a-w- c:\windows\system32\perfh01D.dat
2010-06-17 16:11 . 2010-01-17 17:51 -------- dc----w- c:\documents and settings\bou\Application Data\DivX
2010-06-17 10:44 . 2010-06-17 10:44 -------- dc----w- c:\program\SystemRequirementsLab
2010-06-17 10:16 . 2010-06-17 10:16 -------- dc----w- c:\program\Microsoft Games
2010-06-16 23:04 . 2010-02-11 20:41 -------- dc----w- c:\program\Windows Live
2010-06-16 23:03 . 2010-06-16 23:03 -------- dc----w- c:\program\Microsoft SQL Server Compact Edition
2010-06-16 17:39 . 2010-06-16 17:39 56997 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-06-16 17:39 . 2010-06-16 17:39 53600 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-06-16 17:38 . 2010-06-16 17:38 57054 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\DSDesktopComponents\Uninstaller.exe
2010-06-16 17:38 . 2010-06-16 17:38 54166 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\DSAVCDecoder\Uninstaller.exe
2010-06-16 17:38 . 2010-06-16 17:38 57532 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\DSASPDecoder\Uninstaller.exe
2010-06-16 17:38 . 2010-06-16 17:38 56458 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-06-16 17:38 . 2010-06-16 17:38 54174 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\DSAACDecoder\Uninstaller.exe
2010-06-16 17:38 . 2010-06-16 17:38 54128 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\Converter\Uninstaller.exe
2010-06-08 09:30 . 2010-03-24 20:19 311296 -c--a-w- c:\windows\system32\TubeFinder.exe
2010-06-08 09:00 . 2010-02-26 13:07 -------- dc----w- c:\documents and settings\bou\Application Data\Media Player Classic
2010-06-05 10:53 . 2010-06-05 10:53 -------- dc----w- c:\documents and settings\bou\Application Data\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2010-06-05 10:07 . 2010-05-22 14:55 -------- dc----w- c:\documents and settings\All Users\Application Data\regid.1986-12.com.adobe
2010-06-02 02:55 . 2010-06-23 12:23 74072 -c--a-w- c:\windows\system32\XAPOFX1_5.dll
2010-06-02 02:55 . 2010-06-23 12:23 527192 -c--a-w- c:\windows\system32\XAudio2_7.dll
2010-06-02 02:55 . 2010-06-23 12:23 239960 -c--a-w- c:\windows\system32\xactengine3_7.dll
2010-05-29 10:14 . 2010-05-29 10:07 -------- dc----w- c:\program\Dream Aquarium
2010-05-27 20:32 . 2007-12-19 09:45 245936 -c--a-w- c:\windows\system32\drivers\SynTP.sys
2010-05-27 20:31 . 2008-03-28 00:04 120104 -c--a-w- c:\windows\system32\SynTPCo4.dll
2010-05-27 20:31 . 2007-12-19 09:45 165160 ----a-w- c:\windows\system32\SynTPAPI.dll
2010-05-27 20:31 . 2007-12-19 09:45 210216 -c--a-w- c:\windows\system32\SynCtrl.dll
2010-05-27 20:31 . 2007-12-19 09:45 173352 ----a-w- c:\windows\system32\SynCOM.dll
2010-05-26 09:41 . 2010-06-23 12:23 248672 -c--a-w- c:\windows\system32\d3dx11_43.dll
2010-05-26 09:41 . 2010-06-23 12:23 2106216 -c--a-w- c:\windows\system32\D3DCompiler_43.dll
2010-05-26 09:41 . 2010-06-23 12:23 1868128 -c--a-w- c:\windows\system32\d3dcsx_43.dll
2010-05-26 09:41 . 2010-06-23 12:23 470880 -c--a-w- c:\windows\system32\d3dx10_43.dll
2010-05-26 09:41 . 2010-06-23 12:23 1998168 -c--a-w- c:\windows\system32\D3DX9_43.dll
2010-05-25 20:59 . 2010-05-01 15:48 -------- dc----w- c:\program\Easy-Hide-IP
2010-05-25 20:59 . 2010-05-25 20:59 -------- dc----w- c:\program\Common Files
2010-05-25 20:54 . 2010-05-09 14:41 -------- dc----w- c:\program\AllWebMenus3
2010-05-25 20:54 . 2010-05-09 16:40 -------- dc----w- c:\program\Gigaset QuickSync(2)
2010-05-25 20:38 . 2010-02-25 16:29 -------- dc----w- c:\program\Sony Ericsson
2010-05-25 20:29 . 2010-05-21 22:07 -------- dc----w- c:\documents and settings\bou\Application Data\GetRightToGo
2010-05-25 20:29 . 2010-05-21 22:11 -------- dc----w- c:\program\Driver Checker
2010-05-25 20:26 . 2010-05-22 13:39 -------- dc----w- c:\program\Delade filer\Adobe AIR(2)
2010-05-25 20:06 . 2010-02-25 16:34 -------- dc----w- c:\program\QuickTime
2010-05-25 20:05 . 2010-05-25 19:38 -------- dc----w- c:\documents and settings\All Users\Application Data\NOS
2010-05-17 19:00 . 2010-03-29 16:49 59052 -c-ha-w- c:\windows\system32\mlfcache.dat
2010-05-06 10:36 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 08:10 . 2004-08-04 12:00 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-28 05:44 . 2010-06-16 23:04 54760 -c--a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2010-04-25 10:55 . 2010-04-25 09:16 79488 -c--a-w- c:\documents and settings\bou\Application Data\Sun\Java\jre1.6.0_20\gtapi.dll
2010-04-25 10:55 . 2010-04-25 09:16 152576 -c--a-w- c:\documents and settings\bou\Application Data\Sun\Java\jre1.6.0_20\lzma.dll
2010-04-17 18:59 . 2010-04-17 18:08 80 -csh--r- c:\windows\system32\D59F6963CD.dll
.
(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Not* Tomma poster & legitima standardposter visas inte.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program\Synaptics\SynTP\SynTPEnh.exe" [2010-05-27 1721640]
"NDPS"="c:\windows\system32\dpmw32.exe" [2004-05-17 32859]
"ZENRC Tray Icon"="c:\windows\system32\zentray.exe" [2005-01-17 40960]
"NWTRAY"="NWTRAY.EXE" [2002-03-12 28672]
"HP Software Update"="c:\program\HP\HP Software Update\HPWuSchd2.exe" [2010-06-09 49208]
"Norman ZANDA"="c:\program\NORMAN\Npm\bin\ZLH.EXE" [2009-10-06 275840]
"StartCCC"="c:\program\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2008-04-14 143872]
"SoundMAXPnP"="c:\program\Analog Devices\Core\smax4pnp.exe" [2007-01-05 872448]
"NNTray"="c:\program\Net Nanny\nnstart.exe" [2002-09-24 61440]
"SunJavaUpdateSched"="c:\program\Delade filer\Java\Java Update\jusched.exe" [2010-02-18 248040]
"SwitchBoard"="c:\program\Delade filer\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program\Delade filer\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start-meny\Program\Autostart\
NalView.lnk - c:\program\Novell\ZENworks\NalView.exe [2005-9-8 35840]
PASPortal.lnk - c:\windows\Installer\{D4AB1A2A-72A8-4801-B238-0CB789C992FE}\NewShortcut1.exe [2008-5-8 40960]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"CompatibleRUPSecurity"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NetIdentity Notification]
2005-01-10 11:36 24576 -c--a-w- c:\windows\system32\Novell\xtnotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\TPSvc]
2007-05-02 02:21 364544 -c--a-r- c:\windows\system32\TPSvc.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwv1_0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start-meny^Program^Autostart^HP Photosmart Premier Snabbstart.lnk]
path=c:\documents and settings\All Users\Start-meny\Program\Autostart\HP Photosmart Premier Snabbstart.lnk
backup=c:\windows\pss\HP Photosmart Premier Snabbstart.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start-meny^Program^Autostart^Windows Search.lnk]
path=c:\documents and settings\All Users\Start-meny\Program\Autostart\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^bou^Start-meny^Program^Autostart^Telia Mobilt bredband.lnk]
path=c:\documents and settings\bou\Start-meny\Program\Autostart\Telia Mobilt bredband.lnk
backup=c:\windows\pss\Telia Mobilt bredband.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-18 07:58 40368 -c--a-w- c:\program\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeBridge]
2010-03-09 02:28 11989960 -c--a-w- c:\program\Adobe\Adobe Bridge CS5\Bridge.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
2010-02-22 02:57 406992 -c--a-w- c:\program\Delade filer\Adobe\CS5ServiceManager\CS5ServiceManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 16:05 15360 -c--a-w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-06-03 00:50 1144104 ----a-w- c:\program\DivX\DivX Update\DivXUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2010-04-16 20:12 3872080 -c--a-w- c:\program\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 14:07 2260480 -c----w- c:\program\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Synchronization Manager]
2008-04-14 16:05 143872 -c--a-w- c:\windows\system32\mobsync.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=2 (0x2)
"idsvc"=3 (0x3)
"gusvc"=3 (0x3)
"wlidsvc"=2 (0x2)
"ose"=3 (0x3)
"Bonjour Service"=2 (0x2)
"gupdate"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Novell\\GroupWise\\grpwise.exe"=
"c:\\Novell\\GroupWise\\notify.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\bou\\Skrivbord\\uTorrent.exe"=
"c:\\Program\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\dpmw32.exe"=
"c:\\Program\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program\\Ace Translator\\AceTrans.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2010-04-24 28552]
R1 NGS;Norman General Security Driver;c:\program\NORMAN\nvc\bin\ngs.sys [2010-01-11 25032]
R2 BlankScr;HBDevice;c:\windows\system32\drivers\blankscr.sys [2005-01-17 6899]
R2 Ndiskio;Ndiskio;c:\program\NORMAN\Nse\Bin\Ndiskio.sys [2010-01-11 24168]
R2 Remote Management Agent;Novell ZENworks Remote Management Agent;c:\program\Novell\ZENworks\RemoteManagement\RMAgent\ZenRem32.exe [2005-09-01 163840]
R2 USB Drive Letter Mananger;USBDLM;c:\program\USBDLM\USBDLM.exe [2006-05-24 64000]
R2 XTAgent;Novell XTier Agent Services;c:\windows\system32\Novell\xtagent.exe [2005-01-10 61440]
R3 Darpan;Darpan;c:\windows\system32\drivers\Darpan.sys [2005-01-10 2773]
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [2006-10-03 17149]
R3 nsesvc;Norman Scanner Engine Service;c:\program\NORMAN\Nse\Bin\Nsesvc.exe [2010-01-11 283976]
R3 NvcMFlt;NvcMFlt;c:\windows\system32\drivers\nvcw32mf.sys [2010-01-11 21832]
R3 nvcoas;Norman Virus Control on-access component;c:\program\NORMAN\nvc\bin\Nvcoas.exe [2010-01-11 185672]
R3 NVCScheduler;Norman Virus Control Scheduler;c:\program\NORMAN\nvc\bin\Nvcsched.exe [2010-01-11 148808]
S2 hgfs;hgfs;c:\windows\system32\DRIVERS\hgfs.sys --> c:\windows\system32\DRIVERS\hgfs.sys [?]
S3 ATHFMWDL;NETGEAR WG111T bootloader driver;c:\windows\system32\drivers\Athfmwdl.sys [2006-03-22 43392]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2010-02-25 13224]
S3 s3legacy;s3legacy;c:\windows\system32\drivers\s3legacy.sys [2007-07-05 65664]
S3 SwitchBoard;SwitchBoard;c:\program\Delade filer\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2004-08-04 14336]
S4 gupdate;Tjänsten Google Update (gupdate);c:\program\Google\Update\GoogleUpdate.exe [2010-03-02 135664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Innehållet i mappen 'Schemalagda aktiviteter':
2010-07-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-07-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program\Google\Update\GoogleUpdate.exe [2010-03-02 17:11]
2010-07-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program\Google\Update\GoogleUpdate.exe [2010-03-02 17:11]
2010-07-23 c:\windows\Tasks\User_Feed_Synchronization-{3D3AEC52-0069-4C6A-A4F2-9862916322C8}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
2010-07-23 c:\windows\Tasks\User_Feed_Synchronization-{695BC004-ABC9-4A06-ADF4-485202981975}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
.
.
------- Extra genomsökning -------
.
uStart Page = hxxp://www.google.se/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyServer = 127.0.0.1:8080
uInternet Settings,ProxyOverride = local
IE: E&xportera till Microsoft Excel - c:\program\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Sothink SWF Catcher - c:\program\Delade filer\SourceTec\SWF Catcher\InternetExplorer.htm
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} - hxxp://www.nattstad.se/ImageUploader6.cab
FF - ProfilePath - c:\documents and settings\bou\Application Data\Mozilla\Firefox\Profiles\9l2eva6x.default\
FF - prefs.js: browser.startup.homepage - hxxp://www2.firesearch.com/
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
.
------- Filassociationer -------
.
regfile\shell\edit\command=%SystemRoot%\system32\NOTEPAD.EXE %1
.
- - - - FÖRÄLDRALÖSA POSTER SOM TAGITS BORT - - - -
HKLM-Run-adsnwk - c:\windows\system32\adsnwk.exe
HKLM-Run-FU_JFM - c:\program\FinalUninstaller\JFM.exe
MSConfigStartUp-Adobe ARM - c:\program\Delade filer\Adobe\ARM\1.0\AdobeARM.exe
MSConfigStartUp-Adobe Photo Downloader - c:\program\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
MSConfigStartUp-AdobeCS4ServiceManager - c:\program\Delade filer\Adobe\CS4ServiceManager\CS4ServiceManager.exe
MSConfigStartUp-AGEIA PhysX SysTray - c:\program\AGEIA Technologies\TrayIcon.exe
MSConfigStartUp-IDMan - c:\temp\Rar$EX02.015\idm 5.18\IDMan.exe
MSConfigStartUp-m7 - c:\progra~1\common~1\m7\in.vbs
MSConfigStartUp-Sony Ericsson PC Suite - c:\program\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
MSConfigStartUp-swg - c:\program\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
AddRemove-Agere Systems Soft Modem - c:\windows\agrsmdel
AddRemove-Svenska Spels Poker - c:\casino\SVENSK~1\UNWISE.EXE
AddRemove-uTorrent - u:\\uTorrent.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-23 21:33
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
NNTray = c:\program\Net Nanny\nnstart.exe???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LÅSTA REGISTERNYCKLAR ---------------------
[HKEY_USERS\S-1-5-21-2814842062-1513136318-2222897245-1045\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder]
@Denied: (A C D 2 3 6) (Everyone)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•6~*]
"D140710900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
"D140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLer som "laddats" under processer som körs ---------------------
- - - - - - - > 'winlogon.exe'(872)
c:\program\Novell\ZENworks\ZENPOL32.DLL
c:\windows\system32\xmlparse.dll
c:\windows\system32\msi.dll
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'Explorer.exe'(3896)
c:\program\WINDOW~2\wmpband.dll
c:\windows\system32\msi.dll
c:\windows\system32\NLS\SVENSKA\NWSHLXNR.DLL
c:\windows\system32\NLS\SVENSKA\NOVNPNTR.DLL
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Andra processer som körs ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program\NORMAN\Npm\bin\ELOGSVC.EXE
c:\program\NORMAN\npm\bin\zanda.exe
c:\windows\system32\agrsmsvc.exe
c:\program\Java\jre6\bin\jqs.exe
c:\program\Delade filer\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program\Novell\ZENworks\nalntsrv.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program\Novell\ZENworks\wm.exe
c:\program\NORMAN\Npm\bin\NJEEVES.EXE
c:\program\Novell\ZENworks\WMRUNDLL.EXE
c:\windows\system32\NWTRAY.EXE
c:\program\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
c:\windows\system32\msiexec.exe
c:\program\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\program\NORMAN\Nvc\bin\cclaw.exe
c:\program\DataStudio\PASPortal.exe
.
**************************************************************************
.
Sluttid: 2010-07-23 21:42:14 - datorn startades om.
ComboFix-quarantined-files.txt 2010-07-23 19:42
Före genomsökningen: 64 613 941 248 byte ledigt
Efter genomsökningen: 65 233 313 792 byte ledigt
WindowsXP-KB310994-SP2-Home-BootDisk-SVE.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - AE3DC8D7F051866BF7362490207FBACA

Logga in
Bli medlem


Citera flera inlägg


