Just nu i M3-nätverket
Gå till innehåll

Virtumonde - Hur få bort?


Tangemo

Rekommendera Poster

Hej!

 

Jag tror jag drabbats av en trojansk häst som kallar sig Virtumonde. Den ser bland annat till att jag får ett felmeddelande med texten "Rundll32.exe kunde inte starta modulen ".

 

Varken Nod32 eller spybot får bort skräpet. Bifogar en Hijackthis-log och hoppas på hjälp!

 

[log]Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 21:54:29, on 2008-09-16

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Boot mode: Normal

 

Running processes:

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\System32\mobsync.exe

C:\hp\support\hpsysdrv.exe

C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe

C:\Windows\RtHDVCpl.exe

C:\Windows\system32\schtasks.exe

C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\MagicRotation\MagicPvt.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Windows\ehome\ehtray.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Program Files\DAEMON Tools Lite\daemon.exe

C:\Program Files\uTorrent\uTorrent.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Windows\ehome\ehmsas.exe

C:\Program Files\Personal\bin\Personal.exe

C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe

C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\Internet Explorer\ieuser.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\MagicTune Premium\MagicTune.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\hp\kbd\kbd.exe

C:\Windows\system32\Macromed\Flash\FlashUtil9c.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gp.se/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896'>http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=SV_SE&c=74&bd=Pavilion&pf=desktop

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

O2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe

O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE

O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode

O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateReg] "C:\Windows\system32\jureg.exe"

O4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [MagicRotation] C:\Program Files\MagicRotation\MagicPvt.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [MagicTuneEngine] C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [f81b46e9] rundll32.exe "C:\Users\Tangemo\AppData\Local\Temp\urwftogd.dll",b

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')

O4 - Startup: BUFFALO NAS Navigator.lnk = C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe

O4 - Startup: Skärmurklipp och start för OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Personal.lnk = C:\Program Files\Personal\bin\Personal.exe

O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

O9 - Extra button: Skicka till OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: Ski&cka till OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O13 - Gopher Prefix:

O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: Intel® Alert Service (AlertService) - Intel® Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Automatisches LiveUpdate - Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe

O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe

O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe

O23 - Service: HP Chasis Button Service (HPBtnSrv) - Unknown owner - c:\hp\HPEZBTN\HPBtnSrv.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Intel® Software Services Manager (ISSM) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)

O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

O23 - Service: Intel® Viiv Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe

O23 - Service: Intel® Application Tracker (MCLServiceATL) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

O23 - Service: Intel® Remoting Service (Remote UI Service) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe

O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe

 

--

End of file - 11156 bytes[/log]

 

Tacksam om någon kan och vill!

 

 

Länk till kommentar
Dela på andra webbplatser

Är det meningen att Symantec/Norton ska vara avinstallerad?

 

Ladda ner Malwarebytes Anti-Malware från en av dessa länkar:

http://www.malwaresupport.com/mbam/program/mbam-setup.exe

http://www.brothersoft.com/download-malwarebytes.-anti-malware-71406.html

Dubbelklicka på mbam-setup.exe för att installera programmet.

 

[log]Bocka för:

Update Malwarebytes' Anti-Malware

Launch Malwarebytes' Anti-Malware

Tryck på Finish

Om det finns någon uppdatering så kommer den att laddas ner och installeras.

 

När programmet startar så välj Perform Quick Scan och tryck på Scan.

Skanningen tar ett tag.

När den är klar så tryck på OK och sedan Show Results.

Bocka för allt och tryck sedan Remove Selected.

När borttagningen är klar så öppnar Anteckningar med en logg.

 

Eventuellt så kommer det upp en begäran om att starta om datorn (Restart). I så fall gör det.

Om programmet inte kommer igång efter omstarten så starta det.

 

Om loggen inte kommer upp själv i Anteckningar så hittar du loggen på Logs-fliken i MBAM.

Kopiera loggen och klistra in den i ditt svar tillsammans med en ny HijackThis-logg.[/log]

 

Länk till kommentar
Dela på andra webbplatser

Jag ser i Hijack-loggen att du har en väldigt gammal java-version med

säkerhetshål i datorn.Jag rekommenderar att du laddar hem och

installerar uppdaterad version http://www.java.com/sv/ Avinstallera

sedan den gamla i Kontrollpanelen Lägg till eller ta bort program

(inga webläsare igång)

 

Länk till kommentar
Dela på andra webbplatser

Hej!

 

Tack för infon, har installerat ny java och avinstallerat den gamla. Lustigt, köpte datorn för bara en månad sen, men det har väl stått i butiken ett tag antar jag... Postar loggar med mera i svar till "Cecilia"...

 

Länk till kommentar
Dela på andra webbplatser

Hej!

 

Först och främst: Tack för hjälpen. Det är meningen att ha norton avinstallerad. Kör med ESET Nod32 istället. Hoppas jag kommit en bit på vägen nu iaf tack vare dina tipss

 

Ladda ner och körde MBAF -> Log 1

 

[log]Malwarebytes' Anti-Malware 1.28

Database version: 1164

Windows 6.0.6001 Service Pack 1

 

2008-09-17 18:56:29

mbam-log-2008-09-17 (18-56-29).txt

 

Scan type: Quick Scan

Objects scanned: 49750

Time elapsed: 2 minute(s), 42 second(s)

 

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 1

Registry Data Items Infected: 1

Folders Infected: 0

Files Infected: 0

 

Memory Processes Infected:

(No malicious items detected)

 

Memory Modules Infected:

(No malicious items detected)

 

Registry Keys Infected:

(No malicious items detected)

 

Registry Values Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\f81b46e9 (Trojan.Vundo) -> Quarantined and deleted successfully.

 

Registry Data Items Infected:

HKEY_CLASSES_ROOT\scrfile\shell\open\command\ (Broken.OpenCommand) -> Bad: ("%1" %*) Good: ("%1" /S) -> Quarantined and deleted successfully.

 

Folders Infected:

(No malicious items detected)

 

Files Infected:

(No malicious items detected)[/log]

 

Omstart enligt MBAMs önskan. Scan igen -> Log 2

 

[log]Malwarebytes' Anti-Malware 1.28

Database version: 1164

Windows 6.0.6001 Service Pack 1

 

2008-09-17 19:09:41

mbam-log-2008-09-17 (19-09-41).txt

 

Scan type: Quick Scan

Objects scanned: 49588

Time elapsed: 2 minute(s), 10 second(s)

 

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 1

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

 

Memory Processes Infected:

(No malicious items detected)

 

Memory Modules Infected:

(No malicious items detected)

 

Registry Keys Infected:

(No malicious items detected)

 

Registry Values Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\f81b46e9 (Trojan.Vundo) -> Quarantined and deleted successfully.

 

Registry Data Items Infected:

(No malicious items detected)

 

Folders Infected:

(No malicious items detected)

 

Files Infected:

(No malicious items detected)

[/log]

 

Och därefter Hijackthis - > Hijacklog

 

[log]Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 19:10:33, on 2008-09-17

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Boot mode: Normal

 

Running processes:

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\hp\support\hpsysdrv.exe

C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe

C:\Windows\RtHDVCpl.exe

C:\Windows\System32\jureg.exe

C:\Windows\system32\schtasks.exe

C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\MagicRotation\MagicPvt.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Windows\ehome\ehtray.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Windows\ehome\ehmsas.exe

C:\Program Files\DAEMON Tools Lite\daemon.exe

C:\Program Files\uTorrent\uTorrent.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\Personal\bin\Personal.exe

C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe

C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Windows\System32\mobsync.exe

C:\Program Files\MagicTune Premium\MagicTune.exe

C:\hp\kbd\kbd.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gp.se/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896'>http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=SV_SE&c=74&bd=Pavilion&pf=desktop

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe

O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE

O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode

O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateReg] "C:\Windows\system32\jureg.exe"

O4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [MagicRotation] C:\Program Files\MagicRotation\MagicPvt.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [MagicTuneEngine] C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [f81b46e9] rundll32.exe "C:\Users\Tangemo\AppData\Local\Temp\urwftogd.dll",b

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')

O4 - Startup: BUFFALO NAS Navigator.lnk = C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe

O4 - Startup: Skärmurklipp och start för OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Personal.lnk = C:\Program Files\Personal\bin\Personal.exe

O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll

O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll

O9 - Extra button: Skicka till OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: Ski&cka till OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O13 - Gopher Prefix:

O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: Intel® Alert Service (AlertService) - Intel® Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Automatisches LiveUpdate - Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe

O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe

O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe

O23 - Service: HP Chasis Button Service (HPBtnSrv) - Unknown owner - c:\hp\HPEZBTN\HPBtnSrv.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Intel® Software Services Manager (ISSM) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)

O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

O23 - Service: Intel® Viiv Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe

O23 - Service: Intel® Application Tracker (MCLServiceATL) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

O23 - Service: Intel® Remoting Service (Remote UI Service) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe

O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe

 

 

End of file - 11162 bytes[/log]

 

Tror ni att jag är fri från virusen nu?

 

Lagt till LOG-taggar

När du har klistrat in en logg så var vänlig och markera loggen och tryck sedan på LOG-knappen som finns på samma rad som :thumbsdown::thumbsup: i inläggsfönstret.

Cecilia - Moderator för Virus, skadliga program & botemedel

 

[inlägget ändrat 2008-09-17 19:21:05 av Cecilia]

Länk till kommentar
Dela på andra webbplatser

Se om du hittar något mer med Symantec eller Norton i Kontrollpanelen - Lägg till eller ta bort program (t ex LiveUpdate). Kör sedan deras städprogram för att ta bort rester:

http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039

 

Kör MBAM igen men välj inte Quick Scan utan en komplett skanning av C:, för den verkar inte hitta filen som finns i Temp-mappen.

 

Lustigt, köpte datorn för bara en månad sen, men det har väl stått i butiken ett tag antar jag...
Tillverkaren gör ofta en "installationsskiva" i samband med att datorn blir klar och den uppdaterar de sedan inte även om det kommer ut nya versioner av program.

 

Länk till kommentar
Dela på andra webbplatser

Hej!

 

Installerade bort ett par rester av norton via kontrollpanelen (liveupdate + en komponent till). Körde sedan Norton removal tool och startade om datorn. Därefter en komplett scan av c med MBAM:

 

[log]Malwarebytes' Anti-Malware 1.28

Database version: 1164

Windows 6.0.6001 Service Pack 1

 

2008-09-17 22:00:59

mbam-log-2008-09-17 (22-00-59).txt

 

Scan type: Full Scan (C:\|)

Objects scanned: 173940

Time elapsed: 1 hour(s), 49 minute(s), 45 second(s)

 

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 1

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

 

Memory Processes Infected:

(No malicious items detected)

 

Memory Modules Infected:

(No malicious items detected)

 

Registry Keys Infected:

(No malicious items detected)

 

Registry Values Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\f81b46e9 (Trojan.Vundo) -> Quarantined and deleted successfully.

 

Registry Data Items Infected:

(No malicious items detected)

 

Folders Infected:

(No malicious items detected)

 

Files Infected:

(No malicious items detected)

[/log]

 

..och en Hijackthis:

 

[log]Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 22:01:38, on 2008-09-17

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Boot mode: Normal

 

Running processes:

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\hp\support\hpsysdrv.exe

C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe

C:\Windows\RtHDVCpl.exe

C:\Windows\System32\jureg.exe

C:\Windows\system32\schtasks.exe

C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\MagicRotation\MagicPvt.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Windows\ehome\ehtray.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Program Files\DAEMON Tools Lite\daemon.exe

C:\Program Files\uTorrent\uTorrent.exe

C:\Windows\ehome\ehmsas.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\Personal\bin\Personal.exe

C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe

C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\MagicTune Premium\MagicTune.exe

C:\hp\kbd\kbd.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\system32\NOTEPAD.EXE

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gp.se/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896'>http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=SV_SE&c=74&bd=Pavilion&pf=desktop

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe

O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE

O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode

O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateReg] "C:\Windows\system32\jureg.exe"

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [MagicRotation] C:\Program Files\MagicRotation\MagicPvt.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [MagicTuneEngine] C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [f81b46e9] rundll32.exe "C:\Users\Tangemo\AppData\Local\Temp\urwftogd.dll",b

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')

O4 - Startup: BUFFALO NAS Navigator.lnk = C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe

O4 - Startup: Skärmurklipp och start för OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Personal.lnk = C:\Program Files\Personal\bin\Personal.exe

O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll

O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll

O9 - Extra button: Skicka till OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: Ski&cka till OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O13 - Gopher Prefix:

O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: Intel® Alert Service (AlertService) - Intel® Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe

O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe

O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe

O23 - Service: HP Chasis Button Service (HPBtnSrv) - Unknown owner - c:\hp\HPEZBTN\HPBtnSrv.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Intel® Software Services Manager (ISSM) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe

O23 - Service: Intel® Viiv Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe

O23 - Service: Intel® Application Tracker (MCLServiceATL) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

O23 - Service: Intel® Remoting Service (Remote UI Service) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe

O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe

 

--

End of file - 10249 bytes

[/log]

 

Next step?

 

Länk till kommentar
Dela på andra webbplatser

Det hjälpte inte då får vi ta till ComboFix:

Ladda ner ComboFix till Skrivbordet:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

 

[log]Dra ur internetanslutningen och stäng av alla program du ser inklusive antivirusprogram, antispionprogram och brandvägg, alternativt starta om datorn i felsäkert läge.

Kör ComboFix och följ anvisningarna som visas.

 

VIKTIGT! Klicka inte på ComboFix-fönstret med musen när den körs annars kan den hänga upp sig.

 

När den är färdig så ska en logg komma upp, bifoga den till ditt svar. Kontrollera att antivirusprogram och brandvägg är igång innan du ansluter till internet.

 

Om du får problem med att komma ut på internet:

Kontrollpanelen - Nätverksanslutningar

högerklicka på din internetanslutning och välj Reparera och/eller starta om datorn.

[/log]

Varning! ComboFix förhindrar automatisk körning av CD, disketter och USB-enheter för att göra det lättare att rensa datorn och skydda datorn mot infektioner i framtiden. Det kan bli problem t ex om datorn har internet via ett USB-modem eller USB-nätverkskort. Säg då till i stället för att köra ComboFix.

 

Länk till kommentar
Dela på andra webbplatser

Hej!

 

Det verkar inte ha hjälpt det heller.... Testade först i felsäkert läge, men då strulade combofix med adminrättigheter. Startade då normalt och avaktiverade allt vad säkerhet heter och då gick det fint. Fick denna combofix-log

[log]

ComboFix 08-09-16.05 - Tangemo 2008-09-17 22:46:09.4 - NTFSx86

Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1031.18.2033 [GMT 2:00]

ausgeführt von:: C:\Users\Tangemo\Desktop\ComboFix.exe

* Neuer Wiederherstellungspunkt wurde erstellt

.

 

(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))

.

.

---- Previous Run -------

.

C:\Windows\system32\jusched.exe

 

.

((((((((((((((((((((((( Dateien erstellt von 2008-08-17 bis 2008-09-17 ))))))))))))))))))))))))))))))

.

 

2008-09-17 19:47 . 2008-09-17 19:47 <DIR> d-------- C:\Users\All Users\NortonInstaller

2008-09-17 19:47 . 2008-09-17 19:47 <DIR> d-------- C:\ProgramData\NortonInstaller

2008-09-17 18:52 . 2008-09-17 18:52 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware

2008-09-17 18:52 . 2008-09-10 00:04 38,528 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys

2008-09-17 18:52 . 2008-09-10 00:03 17,200 --a------ C:\Windows\System32\drivers\mbam.sys

2008-09-13 12:33 . 2008-09-13 12:33 <DIR> d-------- C:\Users\All Users\Office Genuine Advantage

2008-09-13 12:33 . 2008-09-13 12:33 <DIR> d-------- C:\ProgramData\Office Genuine Advantage

2008-09-13 11:20 . 2008-09-13 11:20 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\Sync App Settings

2008-09-13 11:19 . 2008-09-13 11:19 <DIR> d-------- C:\Users\All Users\Sync App Settings

2008-09-13 11:19 . 2008-09-13 11:19 <DIR> d-------- C:\ProgramData\Sync App Settings

2008-09-13 11:19 . 2008-09-13 11:19 <DIR> d-------- C:\Program Files\Allway Sync

2008-09-12 21:28 . 2008-09-12 21:28 <DIR> d-------- C:\Program Files\Apple Software Update

2008-09-12 21:25 . 2008-09-12 21:25 <DIR> d----c--- C:\Windows\System32\DRVSTORE

2008-09-12 21:25 . 2008-04-17 13:12 107,368 --a------ C:\Windows\System32\GEARAspi.dll

2008-09-12 21:25 . 2008-04-17 13:12 15,464 --a------ C:\Windows\System32\drivers\GEARAspiWDM.sys

2008-09-12 21:24 . 2008-09-12 21:25 <DIR> d-------- C:\Users\All Users\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

2008-09-12 21:24 . 2008-09-12 21:25 <DIR> d-------- C:\ProgramData\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

2008-09-12 21:24 . 2008-09-12 21:25 <DIR> d-------- C:\Program Files\iTunes

2008-09-12 21:24 . 2008-09-12 21:24 <DIR> d-------- C:\Program Files\iPod

2008-09-12 21:23 . 2008-09-12 21:23 <DIR> d-------- C:\Program Files\Bonjour

2008-09-12 21:22 . 2008-09-12 21:23 <DIR> d-------- C:\Program Files\QuickTime

2008-09-12 19:51 . 2008-09-12 19:51 <DIR> d-------- C:\Program Files\Safari

2008-09-10 22:55 . 2008-09-10 22:55 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\vlc

2008-09-10 22:52 . 2008-09-10 22:52 <DIR> d-------- C:\Program Files\VideoLAN

2008-09-10 18:21 . 2008-07-31 03:13 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll

2008-09-10 18:21 . 2008-07-31 05:32 28,160 --a------ C:\Windows\System32\Apphlpdm.dll

2008-09-10 18:20 . 2008-08-02 03:01 625,152 --a------ C:\Windows\System32\drivers\dxgkrnl.sys

2008-09-10 18:20 . 2008-06-26 05:29 565,248 --a------ C:\Windows\System32\emdmgmt.dll

2008-09-10 18:20 . 2008-06-26 05:29 303,616 --a------ C:\Windows\System32\wmpeffects.dll

2008-09-10 18:20 . 2008-05-08 21:21 211,968 --a------ C:\Windows\System32\drivers\mrxsmb10.sys

2008-09-10 18:20 . 2008-05-20 04:07 148,480 --a------ C:\Windows\System32\drivers\nwifi.sys

2008-09-10 18:20 . 2008-06-26 05:29 45,056 --a------ C:\Windows\System32\dataclen.dll

2008-09-10 18:20 . 2008-08-02 05:26 36,864 --a------ C:\Windows\System32\cdd.dll

2008-09-08 18:36 . 2008-09-08 18:36 <DIR> d-------- C:\Program Files\Rockstar Games

2008-09-08 18:32 . 2008-09-08 18:32 <DIR> d-------- C:\Program Files\DAEMON Tools Lite

2008-09-08 18:28 . 2008-09-08 18:28 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\DAEMON Tools

2008-09-08 18:28 . 2008-09-08 18:28 717,296 --a------ C:\Windows\System32\drivers\sptd.sys

2008-09-08 18:09 . 2008-09-10 22:48 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\Roxio

2008-09-08 00:35 . 2008-09-08 00:35 <DIR> d-------- C:\Program Files\MagicRotation

2008-09-08 00:35 . 2007-05-25 10:57 79,360 --a------ C:\Windows\System32\magicpvt.dll

2008-09-08 00:35 . 2006-12-05 04:08 77,824 --a------ C:\Windows\System32\mpvthook.dll

2008-09-08 00:35 . 2006-12-04 00:34 77,824 --a------ C:\Windows\System32\MagicPvtUser.exe

2008-09-08 00:35 . 2006-12-04 00:36 26,240 --a------ C:\Windows\System32\drivers\magicpvt.sys

2008-09-08 00:35 . 2006-12-04 00:35 16 --a------ C:\Windows\System32\magicpvt.dat

2008-09-08 00:35 . 2006-12-04 00:34 0 --a------ C:\Windows\System32\driver.dat

2008-09-08 00:26 . 2008-09-08 00:26 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\InstallShield

2008-09-08 00:26 . 2008-09-08 00:26 <DIR> d-------- C:\Program Files\MagicTune Premium

2008-09-08 00:26 . 2008-07-04 10:19 13,056 --a------ C:\Windows\System32\drivers\MTiCtwl.sys

2008-09-08 00:26 . 2006-11-02 14:56 3,294 --a------ C:\Windows\System32\drivers\TMM

2008-09-07 23:53 . 2008-09-07 23:53 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\Malwarebytes

2008-09-07 23:53 . 2008-09-07 23:53 <DIR> d-------- C:\Users\All Users\Malwarebytes

2008-09-07 23:53 . 2008-09-07 23:53 <DIR> d-------- C:\ProgramData\Malwarebytes

2008-09-07 23:45 . 2008-09-17 22:30 236,938,548 --a------ C:\Windows\MEMORY.DMP

2008-09-07 20:19 . 2008-09-11 18:49 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\skypePM

2008-09-07 20:19 . 2008-09-07 20:19 56 --ah----- C:\Users\All Users\ezsidmv.dat

2008-09-07 20:19 . 2008-09-07 20:19 56 --ah----- C:\ProgramData\ezsidmv.dat

2008-09-07 20:17 . 2008-09-07 20:17 <DIR> d-------- C:\Program Files\Common Files\Skype

2008-09-07 19:18 . 2008-09-11 22:38 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\Skype

2008-09-07 19:17 . 2008-09-07 20:17 <DIR> d-------- C:\Users\All Users\Skype

2008-09-07 19:17 . 2008-09-07 20:17 <DIR> d-------- C:\ProgramData\Skype

2008-09-07 19:17 . 2008-09-07 20:17 <DIR> dr------- C:\Program Files\Skype

2008-09-07 17:15 . 2008-09-07 17:15 <DIR> d--hs---- C:\found.000

2008-09-07 12:31 . 2008-09-07 12:31 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf

2008-09-07 12:27 . 2008-09-07 12:27 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\Backup MyPC

2008-09-07 12:22 . 2008-09-07 12:22 <DIR> d-------- C:\HP Personal Media Drive

2008-09-07 12:15 . 2008-09-07 12:34 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\ICAClient

2008-09-07 12:14 . 2008-09-07 12:14 <DIR> d-------- C:\Program Files\Citrix

2008-09-06 23:06 . 2008-09-06 23:06 378 --a------ C:\Windows\wininit.ini

2008-09-06 22:32 . 2008-09-06 23:47 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy

2008-09-06 22:32 . 2008-09-06 23:47 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy

2008-09-06 22:32 . 2008-09-06 22:35 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy

2008-09-06 16:59 . 2008-03-03 14:25 5,702 --ah----- C:\Windows\nod32restoretemdono.reg

2008-09-06 16:59 . 2008-03-03 18:21 568 --ah----- C:\Windows\nod32fixtemdono.reg

2008-09-06 16:56 . 2008-09-06 16:56 <DIR> d-------- C:\Users\All Users\ESET

2008-09-06 16:56 . 2008-09-06 16:56 <DIR> d-------- C:\ProgramData\ESET

2008-09-06 16:56 . 2008-09-06 16:56 <DIR> d-------- C:\Program Files\ESET

2008-09-06 16:36 . 2008-09-06 16:36 <DIR> d-------- C:\Program Files\7-Zip

2008-09-06 15:09 . 2008-09-06 15:09 90,112 --a------ C:\Windows\System32\QuickTimeVR.qtx

2008-09-06 15:09 . 2008-09-06 15:09 57,344 --a------ C:\Windows\System32\QuickTime.qts

2008-09-06 14:23 . 2006-12-04 10:25 22,723 --a------ C:\Windows\System32\sugs1l3.dll

2008-09-06 13:44 . 2008-09-06 13:44 <DIR> d-------- C:\Program Files\Trend Micro

2008-09-06 13:40 . 2008-09-06 13:40 <DIR> d-------- C:\VundoFix Backups

2008-09-06 03:10 . 2008-09-06 03:10 <DIR> d-------- C:\PerfLogs

2008-09-06 02:01 . 2008-09-06 02:21 <DIR> d-------- C:\Windows\nvidia icons

2008-09-06 00:54 . 2008-09-06 00:56 <DIR> d-------- C:\Users\All Users\Lavasoft

2008-09-06 00:54 . 2008-09-06 00:56 <DIR> d-------- C:\ProgramData\Lavasoft

2008-09-05 23:15 . 2008-09-05 23:15 <DIR> d-------- C:\Windows\System32\AGEIA

2008-09-05 23:15 . 2008-09-06 23:00 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard

2008-09-05 23:15 . 2008-09-05 23:16 <DIR> d-------- C:\Program Files\AGEIA Technologies

2008-09-05 22:06 . 2008-05-03 05:46 313,888 --a------ C:\Windows\System32\nvexpbar.dll

2008-09-05 20:33 . 2008-08-15 23:22 1,108,512 --a------ C:\Windows\System32\nvcpluir.dll

2008-09-05 20:33 . 2008-08-15 23:22 797,216 --a------ C:\Windows\System32\nvcplui.exe

2008-09-05 20:33 . 2008-08-15 23:22 420,384 --a------ C:\Windows\System32\nvcpl.cpl

2008-09-05 20:11 . 2008-09-05 20:11 <DIR> d-------- C:\Program Files\NVIDIA

2008-09-04 20:51 . 2008-09-12 21:39 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\Apple Computer

2008-09-04 20:48 . 2008-09-04 20:50 <DIR> d-------- C:\Users\All Users\Apple Computer

2008-09-04 20:48 . 2008-09-04 20:50 <DIR> d-------- C:\ProgramData\Apple Computer

2008-09-04 20:46 . 2008-09-04 20:46 <DIR> d-------- C:\Users\All Users\Apple

2008-09-04 20:46 . 2008-09-04 20:46 <DIR> d-------- C:\ProgramData\Apple

2008-09-04 20:46 . 2008-09-12 21:22 <DIR> d-------- C:\Program Files\Common Files\Apple

2008-09-04 20:30 . 2008-09-04 21:22 <DIR> d-------- C:\Program Files\The GodFather

2008-09-04 19:32 . 2008-09-04 19:32 <DIR> d-------- C:\Windows\System32\wTR15

2008-09-04 19:32 . 2008-09-04 19:32 <DIR> d-------- C:\Temp\dax41

2008-09-04 19:32 . 2008-09-07 13:21 <DIR> d-------- C:\Temp

2008-09-04 19:31 . 2008-09-04 19:51 <DIR> d-------- C:\Users\All Users\RoboForm

2008-09-04 19:31 . 2008-09-04 19:51 <DIR> d-------- C:\ProgramData\RoboForm

2008-09-03 23:41 . 2008-07-19 07:09 1,811,656 --a------ C:\Windows\System32\wuaueng.dll

2008-09-03 23:41 . 2008-07-19 05:44 1,524,736 --a------ C:\Windows\System32\wucltux.dll

2008-09-03 23:41 . 2008-07-19 07:09 563,912 --a------ C:\Windows\System32\wuapi.dll

2008-09-03 23:41 . 2008-07-18 22:08 163,904 --a------ C:\Windows\System32\wuwebv.dll

2008-09-03 23:41 . 2008-07-19 05:44 83,456 --a------ C:\Windows\System32\wudriver.dll

2008-09-03 23:41 . 2008-07-19 07:10 53,448 --a------ C:\Windows\System32\wuauclt.exe

2008-09-03 23:41 . 2008-07-19 07:10 45,768 --a------ C:\Windows\System32\wups2.dll

2008-09-03 23:41 . 2008-07-19 07:10 36,552 --a------ C:\Windows\System32\wups.dll

2008-09-03 23:41 . 2008-07-18 20:44 31,232 --a------ C:\Windows\System32\wuapp.exe

2008-09-03 23:23 . 2006-10-26 19:56 32,592 --a------ C:\Windows\System32\msonpmon.dll

2008-09-03 23:21 . 2008-09-03 23:21 <DIR> d-------- C:\Program Files\Microsoft.NET

2008-09-03 23:18 . 2008-09-03 23:18 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8

2008-09-03 23:16 . 2008-09-03 23:16 <DIR> d-------- C:\Program Files\uTorrent

2008-09-03 23:03 . 2008-09-17 22:43 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\uTorrent

2008-09-03 23:01 . 2008-09-11 18:54 <DIR> d-------- C:\Users\All Users\Microsoft Help

2008-09-03 23:01 . 2008-09-11 18:54 <DIR> d-------- C:\ProgramData\Microsoft Help

2008-09-03 23:01 . 2008-09-03 23:01 <DIR> dr-h----- C:\MSOCache

2008-09-03 00:06 . 2008-09-03 00:06 <DIR> d-------- C:\Program Files\Microsoft SQL Server Compact Edition

2008-09-03 00:06 . 2006-11-29 13:06 3,426,072 --a------ C:\Windows\System32\d3dx9_32.dll

 

.

(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-09-17 17:43 --------- d-----w C:\Program Files\Common Files\Symantec Shared

2008-09-17 16:57 --------- d-----w C:\Program Files\Java

2008-09-11 16:52 --------- d-----w C:\Program Files\Microsoft Works

2008-09-10 20:55 --------- d-----w C:\Users\Tangemo\AppData\Roaming\vlc

2008-09-08 16:36 --------- d--h--w C:\Program Files\InstallShield Installation Information

2008-09-08 16:09 --------- d-----w C:\ProgramData\Sonic

2008-09-07 15:39 --------- d-----w C:\ProgramData\NVIDIA

2008-09-07 10:22 --------- d-----w C:\Program Files\Roxio

2008-09-06 12:22 65,536 ----a-w C:\Windows\System32\sugs1ci.dll

2008-09-06 12:22 151,552 ----a-w C:\Windows\System32\sugs1ci.exe

2008-09-06 01:22 174 --sha-w C:\Program Files\desktop.ini

2008-09-06 01:12 --------- d-----w C:\Program Files\Windows Sidebar

2008-09-06 01:12 --------- d-----w C:\Program Files\Windows Photo Gallery

2008-09-06 01:12 --------- d-----w C:\Program Files\Windows Mail

2008-09-06 01:12 --------- d-----w C:\Program Files\Windows Journal

2008-09-06 01:12 --------- d-----w C:\Program Files\Windows Defender

2008-09-06 01:12 --------- d-----w C:\Program Files\Windows Collaboration

2008-09-06 01:12 --------- d-----w C:\Program Files\Windows Calendar

2008-09-06 00:45 82,432 ----a-w C:\Windows\System32\axaltocm.dll

2008-09-06 00:45 101,888 ----a-w C:\Windows\System32\ifxcardm.dll

2008-09-03 21:22 --------- d-----w C:\Program Files\MSBuild

2008-09-02 19:29 --------- d-----w C:\Program Files\Common Files\PX Storage Engine

2008-09-01 17:48 --------- d-----w C:\Program Files\HP

2008-08-24 09:00 --------- d-----w C:\Program Files\Google

2008-08-24 08:38 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll

2008-08-24 07:43 --------- d-sh--w C:\ProgramData\Vorlagen

2008-08-24 07:43 --------- d-sh--w C:\ProgramData\Startmenü

2008-08-24 07:43 --------- d-sh--w C:\ProgramData\Favoriten

2008-08-24 07:43 --------- d-sh--w C:\ProgramData\Dokumente

2008-08-24 07:43 --------- d-sh--w C:\ProgramData\Anwendungsdaten

2008-08-24 07:43 --------- d-sh--w C:\Program Files\Gemeinsame Dateien

2008-08-01 09:05 70,936 ----a-w C:\Windows\System32\PhysXLoader.dll

2008-07-31 03:32 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll

2008-07-31 03:32 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll

2008-07-31 03:32 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll

2008-07-22 18:32 32,000 ----a-w C:\Windows\system32\drivers\usbaapl.sys

2008-07-18 18:39 586,752 ----a-w C:\Windows\WLXPGSS.SCR

2008-07-09 03:05 129,520 ------w C:\Windows\System32\PxAFS.DLL

2008-07-09 03:05 120,568 ------w C:\Windows\System32\pxcpyi64.exe

2008-07-09 03:05 118,256 ------w C:\Windows\System32\pxinsi64.exe

2008-02-07 19:46 13,624 ----a-w C:\Program Files\mozilla firefox\plugins\cgpcfg.dll

2008-02-07 19:46 87,360 ----a-w C:\Program Files\mozilla firefox\plugins\CgpCore.dll

2008-02-07 19:46 91,448 ----a-w C:\Program Files\mozilla firefox\plugins\confmgr.dll

2008-02-07 19:46 21,824 ----a-w C:\Program Files\mozilla firefox\plugins\ctxlogging.dll

2008-02-07 19:46 206,136 ----a-w C:\Program Files\mozilla firefox\plugins\ctxmui.dll

2008-02-07 19:46 31,544 ----a-w C:\Program Files\mozilla firefox\plugins\icafile.dll

2008-02-07 19:46 40,248 ----a-w C:\Program Files\mozilla firefox\plugins\icalogon.dll

2007-03-16 15:27 479,232 ----a-w C:\Program Files\mozilla firefox\plugins\msvcm80.dll

2007-03-16 15:27 548,864 ----a-w C:\Program Files\mozilla firefox\plugins\msvcp80.dll

2007-03-16 15:27 626,688 ----a-w C:\Program Files\mozilla firefox\plugins\msvcr80.dll

2007-07-20 10:47 981,170 ----a-w C:\Program Files\mozilla firefox\plugins\sslsdk_b.dll

2008-02-07 19:46 24,384 ----a-w C:\Program Files\mozilla firefox\plugins\TcpPServ.dll

.

 

((((((((((((((((((((((((((((( snapshot@2008-09-07_23.42.58.17 )))))))))))))))))))))))))))))))))))))))))

.

- 2008-08-24 08:38:04 540,672 ----a-w C:\Windows\AppPatch\AcLayers.dll

+ 2008-06-12 05:28:53 541,696 ----a-w C:\Windows\AppPatch\AcLayers.dll

+ 2007-09-14 19:45:58 16,901,168 ----a-r C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSO.DLL

+ 2007-08-28 22:19:24 1,654,648 ----a-r C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OGL.DLL

+ 2007-08-28 22:49:28 606,120 ----a-r C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ONBTTNIE.DLL

+ 2007-08-28 21:43:30 1,022,840 ----a-r C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ONENOTE.EXE

+ 2007-08-24 02:45:42 101,784 ----a-r C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ONENOTEM.EXE

+ 2007-08-24 02:45:42 75,144 ----a-r C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ONFILTER.DLL

+ 2007-08-24 02:45:46 1,167,744 ----a-r C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ONLIBS.DLL

+ 2007-10-12 19:08:52 6,588,968 ----a-r C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ONMAIN.DLL

+ 2008-09-12 19:25:30 102,400 ----a-r C:\Windows\Installer\{41B9E2CF-0B3F-442A-B5B3-592A4A355634}\iTunesIco.exe

- 2007-10-08 13:06:03 65,536 ----a-r C:\Windows\Installer\{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}\_2B60A6E578BF_42F0_A92E_A65DB05D5315.exe

+ 2008-09-11 16:52:07 65,536 ----a-r C:\Windows\Installer\{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}\_2B60A6E578BF_42F0_A92E_A65DB05D5315.exe

- 2007-10-08 13:06:03 184,320 ----a-r C:\Windows\Installer\{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}\_798E252A59A3_40C7_9D6D_A9F69BC0F2A0.exe

+ 2008-09-11 16:52:07 184,320 ----a-r C:\Windows\Installer\{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}\_798E252A59A3_40C7_9D6D_A9F69BC0F2A0.exe

- 2007-10-08 13:06:03 65,536 ----a-r C:\Windows\Installer\{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}\_96B0B63FE326_4C27_85A4_E89EE8F993E3.exe

+ 2008-09-11 16:52:07 65,536 ----a-r C:\Windows\Installer\{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}\_96B0B63FE326_4C27_85A4_E89EE8F993E3.exe

- 2007-10-08 13:06:03 65,536 ----a-r C:\Windows\Installer\{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}\_A1754BD8395F_428B_846C_E2F97DCB709B.exe

+ 2008-09-11 16:52:07 65,536 ----a-r C:\Windows\Installer\{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}\_A1754BD8395F_428B_846C_E2F97DCB709B.exe

- 2007-10-08 13:06:03 17,534 ----a-r C:\Windows\Installer\{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}\gtngstrtd.exe

+ 2008-09-11 16:52:07 17,534 ----a-r C:\Windows\Installer\{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}\gtngstrtd.exe

- 2007-10-08 13:06:03 4,710 ----a-r C:\Windows\Installer\{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}\Win2Kico.exe

+ 2008-09-11 16:52:07 4,710 ----a-r C:\Windows\Installer\{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}\Win2Kico.exe

- 2007-10-08 13:06:03 4,710 ----a-r C:\Windows\Installer\{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}\WSBico.exe

+ 2008-09-11 16:52:07 4,710 ----a-r C:\Windows\Installer\{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}\WSBico.exe

+ 2008-09-12 19:28:24 27,136 ----a-r C:\Windows\Installer\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}\AppleSoftwareUpdateIco.exe

+ 2008-09-12 19:23:27 86,016 ----a-r C:\Windows\Installer\{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}\PrntWzrdIco.exe

- 2008-09-05 01:11:19 1,165,584 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe

+ 2008-09-11 16:54:30 1,165,584 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe

- 2008-09-05 01:11:19 20,240 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe

+ 2008-09-11 16:54:30 20,240 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe

- 2008-09-05 01:11:19 159,504 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe

+ 2008-09-11 16:54:30 159,504 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe

- 2008-09-05 01:11:19 184,080 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe

+ 2008-09-11 16:54:30 184,080 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe

- 2008-09-05 01:11:19 217,864 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe

+ 2008-09-11 16:54:30 217,864 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe

- 2008-09-05 01:11:19 18,704 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe

+ 2008-09-11 16:54:30 18,704 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe

- 2008-09-05 01:11:19 35,088 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe

+ 2008-09-11 16:54:30 35,088 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe

- 2008-09-05 01:11:19 845,584 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe

+ 2008-09-11 16:54:30 845,584 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe

- 2008-09-05 01:11:19 922,384 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe

+ 2008-09-11 16:54:30 922,384 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe

- 2008-09-05 01:11:19 272,648 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe

+ 2008-09-11 16:54:30 272,648 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe

- 2008-09-05 01:11:19 888,080 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe

+ 2008-09-11 16:54:30 888,080 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe

- 2008-09-05 01:11:19 1,172,240 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe

+ 2008-09-11 16:54:30 1,172,240 ----a-r C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe

+ 2008-09-12 17:51:14 307,200 ----a-r C:\Windows\Installer\{C9D96682-5A4D-45FA-BA3E-DDCB2B0CB868}\SafariIco.exe

+ 2008-09-17 20:38:29 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2008-09-17 20:38:29 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

- 2008-09-07 21:37:23 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT

+ 2008-09-17 20:39:14 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT

+ 2008-09-17 20:39:14 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1

- 2008-09-06 01:23:17 2,639,093 -c--a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing\tokens.dat

+ 2008-09-09 05:50:58 2,639,093 -c--a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing\tokens.dat

- 2008-09-07 21:37:20 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT

+ 2008-09-17 20:39:53 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT

+ 2008-09-17 20:39:53 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1

- 2008-01-19 07:34:37 1,671,168 ----a-w C:\Windows\System32\chsbrkr.dll

+ 2008-05-27 05:17:13 1,671,680 ----a-w C:\Windows\System32\chsbrkr.dll

- 2008-01-19 07:34:40 6,103,040 ----a-w C:\Windows\System32\chtbrkr.dll

+ 2008-05-27 05:17:16 6,103,040 ----a-w C:\Windows\System32\chtbrkr.dll

- 2008-09-07 20:57:58 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2008-09-17 17:08:31 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2008-09-07 20:57:58 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2008-09-17 17:08:31 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2008-09-07 20:57:58 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2008-09-17 17:08:31 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2008-09-07 21:30:43 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat

+ 2008-09-17 20:46:05 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat

- 2007-07-24 13:17:08 81,920 ----a-w C:\Windows\System32\dns-sd.exe

+ 2008-08-29 08:18:58 87,336 ----a-w C:\Windows\System32\dns-sd.exe

- 2007-07-24 13:17:08 61,440 ----a-w C:\Windows\System32\dnssd.dll

+ 2008-08-29 07:53:50 61,440 ----a-w C:\Windows\System32\dnssd.dll

+ 2008-04-17 11:12:54 107,368 -c--a-w C:\Windows\System32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspi.dll

+ 2008-04-17 11:12:54 15,464 -c--a-w C:\Windows\System32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspiWDM.sys

- 2007-04-06 22:15:26 135,168 ----a-w C:\Windows\System32\java.exe

+ 2008-06-09 23:21:01 135,168 ----a-w C:\Windows\System32\java.exe

- 2007-04-06 22:15:28 135,168 ----a-w C:\Windows\System32\javaw.exe

+ 2008-06-09 23:21:04 135,168 ----a-w C:\Windows\System32\javaw.exe

- 2007-04-06 23:16:26 139,264 ----a-w C:\Windows\System32\javaws.exe

+ 2008-06-10 00:32:34 139,264 ----a-w C:\Windows\System32\javaws.exe

- 2007-04-07 00:56:45 272,024 ----a-w C:\Windows\System32\jucheck.exe

+ 2008-06-10 02:27:03 329,104 ----a-w C:\Windows\System32\jucheck.exe

- 2007-04-07 00:56:47 54,936 ----a-w C:\Windows\System32\jureg.exe

+ 2008-06-10 02:27:04 54,672 ----a-w C:\Windows\System32\jureg.exe

- 2008-01-19 07:34:42 42,496 ----a-w C:\Windows\System32\korwbrkr.dll

+ 2008-05-27 05:17:16 143,872 ----a-w C:\Windows\System32\korwbrkr.dll

- 2008-01-19 07:34:49 35,328 ----a-w C:\Windows\System32\mimefilt.dll

+ 2008-05-27 05:18:32 40,448 ----a-w C:\Windows\System32\mimefilt.dll

- 2008-08-05 09:11:02 15,888,504 ----a-w C:\Windows\System32\mrt.exe

+ 2008-08-26 20:28:12 16,208,504 ----a-w C:\Windows\System32\mrt.exe

- 2008-01-19 07:35:12 23,552 ----a-w C:\Windows\System32\msscb.dll

+ 2008-05-27 05:17:42 34,816 ----a-w C:\Windows\System32\msscb.dll

- 2008-01-19 07:35:12 51,200 ----a-w C:\Windows\System32\msscntrs.dll

+ 2008-05-27 05:17:25 60,416 ----a-w C:\Windows\System32\msscntrs.dll

+ 2008-05-27 05:17:36 11,776 ----a-w C:\Windows\System32\msshooks.dll

- 2008-01-19 07:35:13 248,832 ----a-w C:\Windows\System32\msshsq.dll

+ 2008-05-27 05:18:32 231,936 ----a-w C:\Windows\System32\msshsq.dll

- 2008-01-19 07:35:13 98,304 ----a-w C:\Windows\System32\mssitlb.dll

+ 2008-05-27 05:17:25 87,552 ----a-w C:\Windows\System32\mssitlb.dll

- 2008-01-19 07:35:13 333,824 ----a-w C:\Windows\System32\mssph.dll

+ 2008-05-27 05:18:25 350,208 ----a-w C:\Windows\System32\mssph.dll

- 2008-01-19 07:35:13 167,936 ----a-w C:\Windows\System32\mssphtb.dll

+ 2008-05-27 05:18:55 203,776 ----a-w C:\Windows\System32\mssphtb.dll

- 2008-01-19 07:35:13 32,256 ----a-w C:\Windows\System32\mssprxy.dll

+ 2008-05-27 05:17:26 32,768 ----a-w C:\Windows\System32\mssprxy.dll

- 2008-01-19 07:36:08 1,400,832 ----a-w C:\Windows\System32\mssrch.dll

+ 2008-05-27 05:21:24 1,418,240 ----a-w C:\Windows\System32\mssrch.dll

- 2008-01-19 07:35:13 52,224 ----a-w C:\Windows\System32\msstrc.dll

+ 2008-05-27 05:18:40 44,032 ----a-w C:\Windows\System32\msstrc.dll

- 2008-01-19 07:35:13 1,696,768 ----a-w C:\Windows\System32\mssvp.dll

+ 2008-05-27 05:18:56 670,208 ----a-w C:\Windows\System32\mssvp.dll

- 2008-01-19 07:35:38 122,368 ----a-w C:\Windows\System32\nlhtml.dll

+ 2008-05-27 05:18:30 136,704 ----a-w C:\Windows\System32\nlhtml.dll

- 2008-01-19 07:36:00 194,560 ----a-w C:\Windows\System32\offfilt.dll

+ 2008-05-27 05:17:23 194,560 ----a-w C:\Windows\System32\offfilt.dll

- 2008-09-07 20:58:59 122,018 ----a-w C:\Windows\System32\perfc007.dat

+ 2008-09-12 17:51:31 122,018 ----a-w C:\Windows\System32\perfc007.dat

- 2008-09-07 20:58:59 101,052 ----a-w C:\Windows\System32\perfc009.dat

+ 2008-09-12 17:51:31 101,052 ----a-w C:\Windows\System32\perfc009.dat

- 2008-09-07 20:58:59 607,532 ----a-w C:\Windows\System32\perfh007.dat

+ 2008-09-12 17:51:31 607,544 ----a-w C:\Windows\System32\perfh007.dat

- 2008-09-07 20:58:59 586,980 ----a-w C:\Windows\System32\perfh009.dat

+ 2008-09-12 17:51:31 586,980 ----a-w C:\Windows\System32\perfh009.dat

- 2008-01-19 07:36:11 65,536 ----a-w C:\Windows\System32\propdefs.dll

+ 2008-05-27 05:18:06 71,680 ----a-w C:\Windows\System32\propdefs.dll

- 2008-01-19 07:36:11 750,080 ----a-w C:\Windows\System32\propsys.dll

+ 2008-05-27 05:17:46 754,176 ----a-w C:\Windows\System32\propsys.dll

- 2008-01-19 07:36:17 26,624 ----a-w C:\Windows\System32\rtffilt.dll

+ 2008-05-27 05:18:30 38,400 ----a-w C:\Windows\System32\rtffilt.dll

- 2008-01-19 07:33:28 76,800 ----a-w C:\Windows\System32\SearchFilterHost.exe

+ 2008-05-27 05:17:55 87,552 ----a-w C:\Windows\System32\SearchFilterHost.exe

- 2008-01-19 07:33:28 302,080 ----a-w C:\Windows\System32\SearchIndexer.exe

+ 2008-05-27 05:18:43 439,808 ----a-w C:\Windows\System32\SearchIndexer.exe

- 2008-01-19 07:33:28 179,200 ----a-w C:\Windows\System32\SearchProtocolHost.exe

+ 2008-05-27 05:18:16 184,832 ----a-w C:\Windows\System32\SearchProtocolHost.exe

- 2008-09-07 09:53:33 6,291,456 ----a-w C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT

+ 2008-09-11 20:43:15 6,291,456 ----a-w C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT

- 2008-01-19 07:36:35 258,048 ----a-w C:\Windows\System32\srchadmin.dll

+ 2008-05-27 05:17:28 301,568 ----a-w C:\Windows\System32\srchadmin.dll

- 2008-01-19 03:17:42 100,043 ----a-w C:\Windows\System32\StructuredQuerySchema.bin

+ 2008-05-27 04:59:39 106,605 ----a-w C:\Windows\System32\StructuredQuerySchema.bin

- 2006-11-02 06:29:53 18,271 ----a-w C:\Windows\System32\StructuredQuerySchemaTrivial.bin

+ 2008-05-27 04:59:40 18,904 ----a-w C:\Windows\System32\StructuredQuerySchemaTrivial.bin

- 2006-11-02 09:46:13 313,344 ----a-w C:\Windows\System32\thawbrkr.dll

+ 2008-05-27 05:17:16 313,344 ----a-w C:\Windows\System32\thawbrkr.dll

- 2008-01-19 07:36:42 1,505,792 ----a-w C:\Windows\System32\tquery.dll

+ 2008-05-27 05:21:07 1,582,592 ----a-w C:\Windows\System32\tquery.dll

- 2008-09-07 21:38:54 6,946 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1997900430-2287122297-485223492-1001_UserData.bin

+ 2008-09-17 20:40:14 7,830 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1997900430-2287122297-485223492-1001_UserData.bin

- 2008-09-07 21:38:54 60,022 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin

+ 2008-09-17 20:40:14 64,002 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin

- 2008-09-07 21:38:50 44,006 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2008-09-17 20:40:10 46,072 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin

- 2008-09-07 14:35:44 287,284 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin

+ 2008-09-12 21:28:07 299,434 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin

- 2008-01-19 07:37:11 27,136 ----a-w C:\Windows\System32\wsepno.dll

+ 2008-05-27 05:18:35 29,184 ----a-w C:\Windows\System32\wsepno.dll

- 2008-01-19 07:37:12 110,592 ----a-w C:\Windows\System32\xmlfilter.dll

+ 2008-05-27 05:18:32 56,320 ----a-w C:\Windows\System32\xmlfilter.dll

- 2008-09-06 10:42:27 126,180,477 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin

+ 2008-09-11 17:01:14 127,803,035 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin

+ 2008-05-27 05:17:28 301,568 ----a-w C:\Windows\winsxs\x86_desktop_shell-search-srchadmin_31bf3856ad364e35_7.0.6001.16503_none_13fcab3737a334c2\srchadmin.dll

+ 2008-07-31 03:34:58 28,160 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6000.16721_none_8006fd7863ac1387\Apphlpdm.dll

+ 2008-07-30 03:11:12 28,160 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6000.20885_none_8053bbe37cf6c053\Apphlpdm.dll

+ 2008-07-31 03:32:38 28,160 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6001.18112_none_81f90c5460c9a1de\Apphlpdm.dll

+ 2008-07-31 03:23:27 28,160 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6001.22233_none_826e099179f692e1\Apphlpdm.dll

+ 2008-07-30 23:32:41 2,560 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6000.16721_none_0a275bdbf535293c\AcRes.dll

+ 2008-07-29 23:16:45 2,560 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6000.20885_none_0a741a470e7fd608\AcRes.dll

+ 2008-08-24 08:38:06 2,560 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6001.18112_none_0c196ab7f252b793\AcRes.dll

+ 2008-07-31 01:03:24 2,560 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6001.22233_none_0c8e67f50b7fa896\AcRes.dll

+ 2008-07-31 03:34:58 2,144,256 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.0.6000.16721_none_0a295c6ff5335bea\AcGenral.dll

+ 2008-07-30 03:11:10 2,144,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.0.6000.20885_none_0a761adb0e7e08b6\AcGenral.dll

+ 2008-07-31 03:32:38 2,154,496 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.0.6001.18112_none_0c1b6b4bf250ea41\AcGenral.dll

+ 2008-07-31 03:23:20 2,153,984 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.0.6001.22233_none_0c9068890b7ddb44\AcGenral.dll

+ 2008-07-31 03:34:58 449,536 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6000.16721_none_0a2a5cb9f5327541\AcSpecfc.dll

+ 2008-07-30 03:11:10 450,560 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6000.20885_none_0a771b250e7d220d\AcSpecfc.dll

+ 2008-07-31 03:32:38 460,288 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6001.18112_none_0c1c6b95f2500398\AcSpecfc.dll

+ 2008-07-31 03:23:21 459,776 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6001.22233_none_0c9168d30b7cf49b\AcSpecfc.dll

+ 2008-07-31 03:34:58 537,600 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6000.16721_none_0a2b5d03f5318e98\AcLayers.dll

+ 2008-07-31 03:34:58 173,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6000.16721_none_0a2b5d03f5318e98\AcXtrnal.dll

+ 2008-07-30 03:11:10 537,600 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6000.20885_none_0a781b6f0e7c3b64\AcLayers.dll

+ 2008-07-30 03:11:10 173,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6000.20885_none_0a781b6f0e7c3b64\AcXtrnal.dll

+ 2008-06-12 05:28:53 541,696 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6001.18112_none_0c1d6bdff24f1cef\AcLayers.dll

+ 2008-07-31 03:32:38 173,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6001.18112_none_0c1d6bdff24f1cef\AcXtrnal.dll

+ 2008-07-31 03:23:21 541,696 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6001.22233_none_0c92691d0b7c0df2\AcLayers.dll

+ 2008-07-31 03:23:22 173,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6001.22233_none_0c92691d0b7c0df2\AcXtrnal.dll

+ 2008-05-27 05:18:30 136,704 ----a-w C:\Windows\winsxs\x86_microsoft-windows-content-filter-html_31bf3856ad364e35_7.0.6001.16503_none_13ff1de93d266b97\nlhtml.dll

+ 2008-05-27 05:18:32 56,320 ----a-w C:\Windows\winsxs\x86_microsoft-windows-content-filter-html_31bf3856ad364e35_7.0.6001.16503_none_13ff1de93d266b97\xmlfilter.dll

+ 2008-05-27 05:18:32 40,448 ----a-w C:\Windows\winsxs\x86_microsoft-windows-content-filter-mime_31bf3856ad364e35_7.0.6001.16503_none_10a358dd3f57c0de\mimefilt.dll

+ 2008-05-27 05:17:23 194,560 ----a-w C:\Windows\winsxs\x86_microsoft-windows-content-filter-office_31bf3856ad364e35_7.0.6001.16503_none_fab3f42bbfadf408\offfilt.dll

+ 2008-05-27 05:18:30 38,400 ----a-w C:\Windows\winsxs\x86_microsoft-windows-content-filter-rtf_31bf3856ad364e35_7.0.6001.16503_none_485964bf76e0570a\rtffilt.dll

+ 2008-06-26 03:29:02 45,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-dataclen_31bf3856ad364e35_6.0.6001.18098_none_f64ce87593b7801f\dataclen.dll

+ 2008-06-26 03:15:06 45,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-dataclen_31bf3856ad364e35_6.0.6001.22211_none_f7260480ac9a8c27\dataclen.dll

+ 2008-06-26 03:29:02 565,248 ----a-w C:\Windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6001.18098_none_9e329f52f6fc276d\emdmgmt.dll

+ 2008-06-26 03:15:30 565,248 ----a-w C:\Windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6001.22211_none_9f0bbb5e0fdf3375\emdmgmt.dll

+ 2008-07-31 03:34:59 1,686,528 ----a-w C:\Windows\winsxs\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6000.16721_none_400572c0c425beea\gameux.dll

+ 2008-07-30 23:47:04 4,247,552 ----a-w C:\Windows\winsxs\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6000.16721_none_400572c0c425beea\GameUXLegacyGDFs.dll

+ 2008-07-30 03:11:51 1,686,528 ----a-w C:\Windows\winsxs\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6000.20885_none_4052312bdd706bb6\gameux.dll

+ 2008-07-29 23:31:23 4,247,552 ----a-w C:\Windows\winsxs\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6000.20885_none_4052312bdd706bb6\GameUXLegacyGDFs.dll

+ 2008-08-24 08:38:04 1,695,744 ----a-w C:\Windows\winsxs\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.18112_none_41f7819cc1434d41\gameux.dll

+ 2008-07-31 01:13:15 4,240,384 ----a-w C:\Windows\winsxs\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.18112_none_41f7819cc1434d41\GameUXLegacyGDFs.dll

+ 2008-07-31 03:25:45 1,695,744 ----a-w C:\Windows\winsxs\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.22233_none_426c7ed9da703e44\gameux.dll

+ 2008-07-31 01:15:32 4,240,384 ----a-w C:\Windows\winsxs\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.22233_none_426c7ed9da703e44\GameUXLegacyGDFs.dll

+ 2008-08-02 03:26:00 36,864 ----a-w C:\Windows\winsxs\x86_microsoft-windows-lddmcore_31bf3856ad364e35_6.0.6001.18114_none_abc1cbc0e39143f0\cdd.dll

+ 2008-08-02 01:01:23 625,152 ----a-w C:\Windows\winsxs\x86_microsoft-windows-lddmcore_31bf3856ad364e35_6.0.6001.18114_none_abc1cbc0e39143f0\dxgkrnl.sys

+ 2008-08-02 03:20:51 36,864 ----a-w C:\Windows\winsxs\x86_microsoft-windows-lddmcore_31bf3856ad364e35_6.0.6001.22235_none_ac36c8fdfcbe34f3\cdd.dll

+ 2008-08-02 00:59:11 625,152 ----a-w C:\Windows\winsxs\x86_microsoft-windows-lddmcore_31bf3856ad364e35_6.0.6001.22235_none_ac36c8fdfcbe34f3\dxgkrnl.sys

+ 2008-06-26 03:22:35 303,616 ----a-w C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-wmpeffects_31bf3856ad364e35_6.0.6000.16710_none_f75cda9b92533b4f\wmpeffects.dll

+ 2008-06-26 03:20:37 303,616 ----a-w C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-wmpeffects_31bf3856ad364e35_6.0.6000.20867_none_f7b769d0ab93182f\wmpeffects.dll

+ 2008-06-26 03:29:09 303,616 ----a-w C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-wmpeffects_31bf3856ad364e35_6.0.6001.18098_none_f8f49a4b8fb37959\wmpeffects.dll

+ 2008-06-26 03:21:15 303,616 ----a-w C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-wmpeffects_31bf3856ad364e35_6.0.6001.22211_none_f9cdb656a8968561\wmpeffects.dll

+ 2008-05-20 02:07:31 148,480 ----a-w C:\Windows\winsxs\x86_microsoft-windows-native-80211_31bf3856ad364e35_6.0.6001.18075_none_4ec1fb0e8f26c88a\nwifi.sys

+ 2008-05-20 02:00:06 148,480 ----a-w C:\Windows\winsxs\x86_microsoft-windows-native-80211_31bf3856ad364e35_6.0.6001.22183_none_4f3ec759a84e5197\nwifi.sys

+ 2008-08-24 08:41:49 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16730_none_f0816da06e6c1330\OESpamFilter.dat

+ 2008-08-24 08:41:49 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.20895_none_f0cf2c5587b5d953\OESpamFilter.dat

+ 2008-08-24 08:41:49 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18121_none_f2737c7c6b89a187\OESpamFilter.dat

+ 2008-08-24 08:41:49 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22243_none_f2e97a0384b5abe1\OESpamFilter.dat

+ 2008-05-27 05:17:46 754,176 ----a-w C:\Windows\winsxs\x86_microsoft-windows-propsys_31bf3856ad364e35_7.0.6001.16503_none_f3d11aeeb9526bbb\propsys.dll

+ 2008-05-27 05:18:35 29,184 ----a-w C:\Windows\winsxs\x86_microsoft-windows-search-profilenotify_31bf3856ad364e35_7.0.6001.16503_none_d86cd72c8d3c237e\wsepno.dll

+ 2008-05-08 19:21:56 211,968 ----a-w C:\Windows\winsxs\x86_microsoft-windows-smb10-minirdr_31bf3856ad364e35_6.0.6001.18068_none_886bae514b981fe3\mrxsmb10.sys

+ 2008-05-08 02:47:34 211,968 ----a-w C:\Windows\winsxs\x86_microsoft-windows-smb10-minirdr_31bf3856ad364e35_6.0.6001.22175_none_88e77a5264c08f99\mrxsmb10.sys

+ 2008-05-27 05:17:16 6,103,040 ----a-w C:\Windows\winsxs\x86_microsoft-windows-w..-chinesetraditional_31bf3856ad364e35_7.0.6001.16503_none_df2000cce0d8c017\chtbrkr.dll

+ 2008-05-27 05:17:16 313,344 ----a-w C:\Windows\winsxs\x86_microsoft-windows-w..breakerstemmer-thai_31bf3856ad364e35_7.0.6001.16503_none_d40428cfc6b6fdf9\thawbrkr.dll

+ 2008-05-27 05:17:16 143,872 ----a-w C:\Windows\winsxs\x86_microsoft-windows-w..eakerstemmer-korean_31bf3856ad364e35_7.0.6001.16503_none_14072d09797cf93d\korwbrkr.dll

+ 2008-05-27 05:17:13 1,671,680 ----a-w C:\Windows\winsxs\x86_microsoft-windows-w..r-chinesesimplified_31bf3856ad364e35_7.0.6001.16503_none_4cbdb704b61543d2\chsbrkr.dll

+ 2008-04-30 05:24:09 1,744,896 ----a-w C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08ac96e2537\GdiPlus.dll

+ 2008-05-01 03:16:12 1,744,896 ----a-w C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.20826_none_87cd0392e31b3a67\GdiPlus.dll

+ 2008-04-30 05:27:35 1,748,992 ----a-w C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\GdiPlus.dll

+ 2008-05-01 03:22:16 1,748,992 ----a-w C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.22170_none_87ae89a0e3672b5a\GdiPlus.dll

+ 2008-04-30 05:24:10 1,823,232 ----a-w C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.6000.16683_none_8df25f6f6273fede\GdiPlus.dll

+ 2008-05-01 03:16:13 1,823,232 ----a-w C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.6000.20826_none_771e72777c21140e\GdiPlus.dll

+ 2008-04-30 05:27:40 1,823,232 ----a-w C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.6001.18065_none_8dcc2d1362c70bc9\GdiPlus.dll

+ 2008-05-01 03:22:16 1,823,232 ----a-w C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.6001.22170_none_76fff8857c6d0501\GdiPlus.dll

+ 2008-05-27 05:18:43 13,824 ----a-w C:\Windows\winsxs\x86_windowssearch-wtrservicingsupport_31bf3856ad364e35_7.0.6001.16503_none_163fe74a2171e12e\WSWTRSvc.exe

+ 2008-05-27 05:18:32 231,936 ----a-w C:\Windows\winsxs\x86_windowssearchengine-structuredquery_31bf3856ad364e35_7.0.6001.16503_none_98586419f9103903\msshsq.dll

+ 2008-05-27 04:59:39 106,605 ----a-w C:\Windows\winsxs\x86_windowssearchengine..uredqueryschema.bin_31bf3856ad364e35_7.0.6001.16503_none_88f88929e3c77aa3\StructuredQuerySchema.bin

+ 2008-05-27 04:59:40 18,904 ----a-w C:\Windows\winsxs\x86_windowssearchengine..uredqueryschema.bin_31bf3856ad364e35_7.0.6001.16503_none_88f88929e3c77aa3\StructuredQuerySchemaTrivial.bin

+ 2008-05-27 05:17:42 34,816 ----a-w C:\Windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3dd\msscb.dll

+ 2008-05-27 05:17:25 60,416 ----a-w C:\Windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3dd\msscntrs.dll

+ 2008-05-27 05:17:36 11,776 ----a-w C:\Windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3dd\msshooks.dll

+ 2008-05-27 05:17:25 87,552 ----a-w C:\Windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3dd\mssitlb.dll

+ 2008-05-27 05:18:25 350,208 ----a-w C:\Windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3dd\mssph.dll

+ 2008-05-27 05:18:55 203,776 ----a-w C:\Windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3dd\mssphtb.dll

+ 2008-05-27 05:17:26 32,768 ----a-w C:\Windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3dd\mssprxy.dll

+ 2008-05-27 05:21:24 1,418,240 ----a-w C:\Windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3dd\mssrch.dll

+ 2008-05-27 05:18:40 44,032 ----a-w C:\Windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3dd\msstrc.dll

+ 2008-05-27 05:18:56 670,208 ----a-w C:\Windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3dd\mssvp.dll

+ 2008-05-27 05:18:06 71,680 ----a-w C:\Windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3dd\propdefs.dll

+ 2008-05-27 05:17:55 87,552 ----a-w C:\Windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3dd\SearchFilterHost.exe

+ 2008-05-27 05:18:43 439,808 ----a-w C:\Windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3dd\SearchIndexer.exe

+ 2008-05-27 05:18:16 184,832 ----a-w C:\Windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3dd\SearchProtocolHost.exe

+ 2008-05-27 05:21:07 1,582,592 ----a-w C:\Windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3dd\tquery.dll

.

.

(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))

.

.

*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]

"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 125952]

"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]

"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [2008-09-03 267056]

"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CCUTRAYICON"="FactoryMode" [X]

"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]

"KBD"="C:\HP\KBD\KbdStub.EXE" [2006-12-08 65536]

"OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]

"HP Health Check Scheduler"="c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-05-24 71176]

"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]

"SunJavaUpdateReg"="C:\Windows\system32\jureg.exe" [2008-06-10 54672]

"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]

"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]

"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-06-10 1447168]

"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-08-15 13576736]

"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-08-15 92704]

"MagicRotation"="C:\Program Files\MagicRotation\MagicPvt.exe" [2007-08-01 2572410]

"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]

"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]

"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-10 289576]

"MagicTuneEngine"="C:\Program Files\MagicTune Premium\MagicTuneEngine.exe" [2008-08-05 69632]

"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]

"RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 C:\Windows\RtHDVCpl.exe]

 

C:\Users\Tangemo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartupBUFFALO NAS Navigator.lnk - C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe [2007-05-11 1070648]

Sk„rmurklipp och start f”r OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]

 

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartupPersonal.lnk - C:\Program Files\Personal\bin\Personal.exe [2008-08-29 910864]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableUIADesktopToggle"= 0 (0x0)

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{39B15A4A-8C87-43B7-9859-E98F429DDEBB}"= "C:\Windows\system32\opnoMdAs.dll" [bU]

 

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GammaTray.lnk]

path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GammaTray.lnk

backup=C:\Windows\pss\GammaTray.lnk.CommonStartup

backupExtension=.CommonStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MagicTuneEngine]

--a------ 2008-08-05 03:42 69632 C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"UacDisableNotify"=dword:00000001

"InternetSettingsDisableNotify"=dword:00000001

"AutoUpdateDisableNotify"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{1CA32AD2-4EEB-4DA7-A9DF-E3E61BA3A5F4}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM

"{63C6B2CA-BA49-471D-945A-8674446304B8}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM

"{C69AD56D-94B9-473E-9FD2-25C57F5D91EF}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv Media Server

"{2B53614B-68D7-4679-AB96-7D068765ED7B}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv Media Server

"{E89BC0FB-7491-4272-B575-6B0F18FC60B0}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service

"{808F38D9-0B42-480A-A3B3-104C491FFC4E}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service

"{D9C14108-24FB-4F3A-A4C2-C25EA317FAFE}"= TCP:9442:127.0.0.1:Intel® Viiv Media Server Discovery

"{60D7B77D-8F66-418D-86A6-B3CAE8C7B4DB}"= TCP:1900:LocalSubnet:LocalSubnet:Intel® Viiv Media Server UPnP Discovery

"{34456AA8-885F-4402-8FDC-8EEAD919BA36}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

"{AFE2C24B-F377-4222-8395-201B77B37026}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (TCP-In)

"{21553A70-2072-4A7A-B49D-0FBDF57822B7}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (UDP-In)

"{104157BD-6511-440F-969B-DADCBD7DD19F}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook

"{0310470A-21F5-4F63-98D3-8B403A83B13E}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove

"{AEC4103E-4B3D-47AC-9916-FB80A964CC24}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove

"{33F701C6-CD2E-4CC0-930B-9FBCCA3AF0BC}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote

"{9FD332A1-E2D7-4739-8E27-2F1001621A24}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote

"TCP Query User{46C4FFEC-6DF3-4C3D-9ADB-DCEB68179216}C:\\program files\\skype\\phone\\skype.exe"= UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath

"UDP Query User{78ACFFB9-F195-4346-A8D6-8DB1C0B54566}C:\\program files\\skype\\phone\\skype.exe"= TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath

"{A9189C8B-A74D-42BA-86D4-C789312B0CF2}"= C:\Program Files\Skype\Phone\Skype.exe:Skype

"TCP Query User{E83AD50C-FE18-435C-9E58-7D4DB2E018CD}C:\\program files\\magictune premium\\magictune.exe"= UDP:C:\program files\magictune premium\magictune.exe:MagicTune

"UDP Query User{16D3F237-9EBD-4D38-9522-88D70A37E7F9}C:\\program files\\magictune premium\\magictune.exe"= TCP:C:\program files\magictune premium\magictune.exe:MagicTune

"{1501D97F-4171-4D6D-AF58-589234502B6A}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour

"{3B531429-BCB1-4A57-96C4-2A965673133B}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour

"{AA23DB46-B3DE-48A7-90B1-CF4F9DB2C805}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes

"{9A6C4C4D-BE3E-45FF-BB2A-44064D19E417}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes

"TCP Query User{B5F2187C-3744-4B5C-A154-43ADB67B857E}C:\\program files\\totalcmd\\totalcmd.exe"= UDP:C:\program files\totalcmd\totalcmd.exe:Total Commander 32 bit international version, file manager replacement for Windows

"UDP Query User{3C19E335-400D-4BA9-9411-3BBE350D6940}C:\\program files\\totalcmd\\totalcmd.exe"= TCP:C:\program files\totalcmd\totalcmd.exe:Total Commander 32 bit international version, file manager replacement for Windows

"TCP Query User{B79E5A7A-1970-40AD-B0DC-2ABBAF7892CB}C:\\program files\\allway sync\\bin\\syncappw.exe"= UDP:C:\program files\allway sync\bin\syncappw.exe:syncappw

"UDP Query User{58BF8E92-704A-4D49-BF98-49195EA3C017}C:\\program files\\allway sync\\bin\\syncappw.exe"= TCP:C:\program files\allway sync\bin\syncappw.exe:syncappw

"{81860274-0DB0-45B1-9C1B-A2AED1EAE96C}"= UDP:C:\Users\Tangemo\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool

"{DC2A8279-EDB6-49B2-98CF-EE4412DA95DE}"= TCP:C:\Users\Tangemo\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]

"EnableFirewall"= 0 (0x0)

 

R1 epfwtdir;epfwtdir;C:\Windows\system32\DRIVERS\epfwtdir.sys [2008-06-10 34312]

R1 magicpvt;magicpvt;C:\Windows\system32\drivers\magicpvt.sys [2006-12-04 26240]

R2 DQLWinService;DQLWinService;C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2006-09-03 208896]

R2 HPBtnSrv;HP Chasis Button Service;c:\hp\HPEZBTN\HPBtnSrv.exe [2007-05-29 198240]

R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;C:\Windows\system32\drivers\HCW85BDA.sys [2007-06-11 968064]

R3 PID_0920;Logitech QuickCam Express(PID_0920);C:\Windows\system32\DRIVERS\LV532AV.SYS [2005-01-31 163328]

S2 IntelDHSvcConf;Intel DH Service;C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe [2006-05-10 29696]

S2 NOD32FiXTemDono;Eset Nod32 Boot;C:\Windows\system32\regedt32.exe [2006-11-02 9216]

S3 netr73;USB Wireless 802.11 b/g Adaptor Driver for Vista;C:\Windows\system32\DRIVERS\netr73.sys [2007-04-20 265216]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]

\shell\AutoRun\command - E:\monsetup.exe

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{581079a0-7dc3-11dd-8fe3-001d60e0fc4f}]

\shell\AutoRun\command - F:\Install.exe

.

Inhalt des "geplante Tasks" Ordners

.

.

------- Zusätzlicher Suchlauf -------

.

FireFox -: Profile - C:\Users\Tangemo\AppData\Roaming\Mozilla\Firefox\Profiles\60vz7hqr.defaultFireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.gp.se/

FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll

FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npicaN.dll

FF -: plugin - C:\Program Files\Personal\bin\np_prsnl.dll

FF -: plugin - C:\Program Files\Picasa2\npPicasa2.dll

.

 

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-09-17 22:48:35

Windows 6.0.6001 Service Pack 1 NTFS

 

Scanne versteckte Prozesse...

 

Scanne versteckte Autostarteinträge...

 

Scanne versteckte Dateien...

 

Scan erfolgreich abgeschlossen

versteckte Dateien: 0

 

**************************************************************************

.

Zeit der Fertigstellung: 2008-09-17 22:52:30

ComboFix-quarantined-files.txt 2008-09-17 20:51:32

ComboFix2.txt 2008-09-08 21:52:10

ComboFix3.txt 2008-09-07 22:03:47

 

Vor Suchlauf: 9 Verzeichnis(se), 121,136,316,416 Bytes frei

Nach Suchlauf: 19 Verzeichnis(se), 121,089,363,968 Bytes frei

 

591 --- E O F --- 2008-09-11 16:55:57[/log]

 

Hijackthis-log

[log]Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 22:57:21, on 2008-09-17

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Boot mode: Normal

 

Running processes:

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\hp\support\hpsysdrv.exe

C:\hp\KBD\KbdStub.exe

C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe

C:\Windows\RtHDVCpl.exe

C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

C:\Windows\System32\jureg.exe

C:\Windows\system32\schtasks.exe

C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\MagicRotation\MagicPvt.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Windows\ehome\ehtray.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Program Files\DAEMON Tools Lite\daemon.exe

C:\Program Files\uTorrent\uTorrent.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\Personal\bin\Personal.exe

C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe

C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Windows\ehome\ehmsas.exe

C:\Program Files\MagicTune Premium\MagicTune.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

C:\Windows\system32\SearchFilterHost.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gp.se/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896'>http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=SV_SE&c=74&bd=Pavilion&pf=desktop

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe

O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE

O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode

O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateReg] "C:\Windows\system32\jureg.exe"

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [MagicRotation] C:\Program Files\MagicRotation\MagicPvt.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [MagicTuneEngine] C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [f81b46e9] rundll32.exe "C:\Users\Tangemo\AppData\Local\Temp\urwftogd.dll",b

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')

O4 - Startup: BUFFALO NAS Navigator.lnk = C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe

O4 - Startup: Skärmurklipp och start för OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Personal.lnk = C:\Program Files\Personal\bin\Personal.exe

O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll

O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll

O9 - Extra button: Skicka till OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: Ski&cka till OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O13 - Gopher Prefix:

O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: Intel® Alert Service (AlertService) - Intel® Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe

O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe

O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe

O23 - Service: HP Chasis Button Service (HPBtnSrv) - Unknown owner - c:\hp\HPEZBTN\HPBtnSrv.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Intel® Software Services Manager (ISSM) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe

O23 - Service: Intel® Viiv Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe

O23 - Service: Intel® Application Tracker (MCLServiceATL) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

O23 - Service: Intel® Remoting Service (Remote UI Service) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe

O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe

 

--

End of file - 10345 bytes[/log]

 

...?

 

Länk till kommentar
Dela på andra webbplatser

Vad finns i dessa mappar?

C:\Windows\System32\wTR15

C:\Temp\dax41

 

Ta bort mappen C:\Program Files\Common Files\Symantec Shared

 

Surfa till http://www.virustotal.com klistra in ett av följande filnamn i rutan, tryck på Skicka Fil och vänta tills resultatet är klart (Närvarande status blir genomförd). Klistra in resultatet från de olika antivirusprogrammen (inte Övrig information) här. Upprepa med nästa filnamn.

C:\Windows\System32\sugs1ci.dll

C:\Windows\System32\sugs1ci.exe

C:\Windows\Installer\{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}\

gtngstrtd.exe

C:\Windows\system32\opnoMdAs.dll

 

 

Länk till kommentar
Dela på andra webbplatser

Hej!

 

Vad finns i dessa mappar?

C:\Windows\System32\wTR15

C:\Temp\dax41

 

Båda tomma. Ta bort?

 

Ta bort mappen C:\Program Files\Common Files\Symantec Shared

 

Borttagen

 

Surfa till http://www.virustotal.com klistra in ett av följande filnamn i rutan, tryck på Skicka Fil och vänta tills resultatet är klart (Närvarande status blir genomförd). Klistra in resultatet från de olika antivirusprogrammen (inte Övrig information) här. Upprepa med nästa filnamn.

 

[log]C:\Windows\System32\sugs1ci.dll

 

ntivirus Version Senaste Uppdatering Resultat

AhnLab-V3 2008.9.13.0 2008.09.18 -

AntiVir 7.8.1.34 2008.09.18 -

Authentium 5.1.0.4 2008.09.18 -

Avast 4.8.1195.0 2008.09.18 -

AVG 8.0.0.161 2008.09.18 -

BitDefender 7.2 2008.09.18 -

CAT-QuickHeal 9.50 2008.09.17 -

ClamAV 0.93.1 2008.09.18 -

DrWeb 4.44.0.09170 2008.09.18 -

eSafe 7.0.17.0 2008.09.18 -

eTrust-Vet 31.6.6091 2008.09.16 -

Ewido 4.0 2008.09.18 -

F-Prot 4.4.4.56 2008.09.18 -

F-Secure 8.0.14332.0 2008.09.18 -

Fortinet 3.113.0.0 2008.09.18 -

GData 19 2008.09.18 -

Ikarus T3.1.1.34.0 2008.09.18 -

K7AntiVirus 7.10.461 2008.09.18 -

Kaspersky 7.0.0.125 2008.09.18 -

McAfee 5386 2008.09.17 -

Microsoft 1.3903 2008.09.18 -

NOD32v2 3452 2008.09.18 -

Norman 5.80.02 2008.09.18 -

Panda 9.0.0.4 2008.09.18 -

PCTools 4.4.2.0 2008.09.18 -

Prevx1 V2 2008.09.18 -

Rising 20.62.32.00 2008.09.18 -

Sophos 4.33.0 2008.09.18 -

Sunbelt 3.1.1647.1 2008.09.18 -

Symantec 10 2008.09.18 -

TheHacker 6.3.0.9.086 2008.09.18 -

TrendMicro 8.700.0.1004 2008.09.18 -

VBA32 3.12.8.5 2008.09.18 -

ViRobot 2008.9.18.1381 2008.09.18 -

VirusBuster 4.5.11.0 2008.09.18 -

Webwasher-Gateway 6.6.2 2008.09.18 -[/log]

 

[log]C:\Windows\System32\sugs1ci.exe

 

Antivirus Version Senaste Uppdatering Resultat

AhnLab-V3 2008.9.19.0 2008.09.18 -

AntiVir 7.8.1.34 2008.09.18 -

Authentium 5.1.0.4 2008.09.18 -

Avast 4.8.1195.0 2008.09.18 -

AVG 8.0.0.161 2008.09.18 -

BitDefender 7.2 2008.09.18 -

CAT-QuickHeal 9.50 2008.09.17 -

ClamAV 0.93.1 2008.09.18 -

DrWeb 4.44.0.09170 2008.09.18 -

eSafe 7.0.17.0 2008.09.18 -

eTrust-Vet 31.6.6091 2008.09.16 -

Ewido 4.0 2008.09.18 -

F-Prot 4.4.4.56 2008.09.18 -

F-Secure 8.0.14332.0 2008.09.18 -

Fortinet 3.113.0.0 2008.09.18 -

GData 19 2008.09.18 -

Ikarus T3.1.1.34.0 2008.09.18 -

K7AntiVirus 7.10.461 2008.09.18 -

Kaspersky 7.0.0.125 2008.09.18 -

McAfee 5386 2008.09.17 -

Microsoft 1.3903 2008.09.18 -

NOD32v2 3452 2008.09.18 -

Norman 5.80.02 2008.09.18 -

Panda 9.0.0.4 2008.09.18 -

PCTools 4.4.2.0 2008.09.18 -

Prevx1 V2 2008.09.18 -

Rising 20.62.32.00 2008.09.18 -

Sophos 4.33.0 2008.09.18 -

Sunbelt 3.1.1647.1 2008.09.18 -

Symantec 10 2008.09.18 -

TheHacker 6.3.0.9.086 2008.09.18 -

TrendMicro 8.700.0.1004 2008.09.18 -

VBA32 3.12.8.5 2008.09.18 -

ViRobot 2008.9.18.1381 2008.09.18 -

VirusBuster 4.5.11.0 2008.09.18 -

Webwasher-Gateway 6.6.2 2008.09.18 -[/log]

 

[log]C:\Windows\Installer\{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}gtngstrtd.exe

 

Antivirus Version Senaste Uppdatering Resultat

AhnLab-V3 2008.9.19.0 2008.09.18 -

AntiVir 7.8.1.34 2008.09.18 -

Authentium 5.1.0.4 2008.09.18 -

Avast 4.8.1195.0 2008.09.18 -

AVG 8.0.0.161 2008.09.18 -

BitDefender 7.2 2008.09.18 -

CAT-QuickHeal 9.50 2008.09.17 -

ClamAV 0.93.1 2008.09.18 -

DrWeb 4.44.0.09170 2008.09.18 -

eSafe 7.0.17.0 2008.09.18 -

eTrust-Vet 31.6.6091 2008.09.16 -

Ewido 4.0 2008.09.18 -

F-Prot 4.4.4.56 2008.09.18 -

Fortinet 3.113.0.0 2008.09.18 -

GData 19 2008.09.18 -

Ikarus T3.1.1.34.0 2008.09.18 -

K7AntiVirus 7.10.461 2008.09.18 -

Kaspersky 7.0.0.125 2008.09.18 -

McAfee 5386 2008.09.17 -

Microsoft 1.3903 2008.09.18 -

NOD32v2 3452 2008.09.18 -

Norman 5.80.02 2008.09.18 -

Panda 9.0.0.4 2008.09.18 -

PCTools 4.4.2.0 2008.09.18 -

Prevx1 V2 2008.09.18 -

Rising 20.62.32.00 2008.09.18 -

Sophos 4.33.0 2008.09.18 -

Sunbelt 3.1.1647.1 2008.09.18 -

Symantec 10 2008.09.18 -

TheHacker 6.3.0.9.086 2008.09.18 -

TrendMicro 8.700.0.1004 2008.09.18 -

VBA32 3.12.8.5 2008.09.18 -

ViRobot 2008.9.18.1381 2008.09.18 -

VirusBuster 4.5.11.0 2008.09.18 -

Webwasher-Gateway 6.6.2 2008.09.18 -[/log]

 

C:\Windows\system32\opnoMdAs.dll

 

Finns inte mer på hårddisken! Kan därför inte köra scannen... De övriga filerna verkar heller inte så farliga enligt virustotal....

 

 

Länk till kommentar
Dela på andra webbplatser

Båda tomma. Ta bort?
Japp

 

Stäng av Spybot S&Ds TeaTimer för ett tag så att den inte stoppar de behövliga förändringarna i registret. Man gör det inifrån Spybot-programmet (Tools - Resident på engelska).

 

Kopiera alla rader i rutan (använd markera kod)

File::
C:\Users\Tangemo\AppData\Local\Temp\urwftogd.dll
C:\Windows\system32\opnoMdAs.dll
Registry::
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
{39B15A4A-8C87-43B7-9859-E98F429DDEBB}"=-

och klistra in i Anteckningar.

Spara filen på Skrivbordet med namnet CFScript.

 

Förbered datorn på samma sätt som tidigare för ComboFix.

 

Dra CFScript med musen och släpp den ovanpå ComboFix-ikonen på Skrivbordet så startar programmet på ett särskilt sätt.

Klistra in loggen som kommer ut och en ny HijackThis-logg.

 

Länk till kommentar
Dela på andra webbplatser

Hej...

[log]

ComboFix 08-09-16.05 - Tangemo 2008-09-18 19:51:13.5 - NTFSx86

Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1031.18.1946 [GMT 2:00]

ausgeführt von:: C:\Users\Tangemo\Desktop\ComboFix.exe

Benutzte Befehlsschalter :: C:\Users\Tangemo\Desktop\CFScript.txt

* Neuer Wiederherstellungspunkt wurde erstellt

.

 

((((((((((((((((((((((( Dateien erstellt von 2008-08-18 bis 2008-09-18 ))))))))))))))))))))))))))))))

.

 

2008-09-18 19:50 . 2008-09-18 19:50 <DIR> d-------- C:\32788R22FWJFW

2008-09-17 19:47 . 2008-09-17 19:47 <DIR> d-------- C:\Users\All Users\NortonInstaller

2008-09-17 19:47 . 2008-09-17 19:47 <DIR> d-------- C:\ProgramData\NortonInstaller

2008-09-17 18:52 . 2008-09-17 18:52 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware

2008-09-17 18:52 . 2008-09-10 00:04 38,528 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys

2008-09-17 18:52 . 2008-09-10 00:03 17,200 --a------ C:\Windows\System32\drivers\mbam.sys

2008-09-13 12:33 . 2008-09-13 12:33 <DIR> d-------- C:\Users\All Users\Office Genuine Advantage

2008-09-13 12:33 . 2008-09-13 12:33 <DIR> d-------- C:\ProgramData\Office Genuine Advantage

2008-09-13 11:20 . 2008-09-13 11:20 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\Sync App Settings

2008-09-13 11:19 . 2008-09-13 11:19 <DIR> d-------- C:\Users\All Users\Sync App Settings

2008-09-13 11:19 . 2008-09-13 11:19 <DIR> d-------- C:\ProgramData\Sync App Settings

2008-09-13 11:19 . 2008-09-13 11:19 <DIR> d-------- C:\Program Files\Allway Sync

2008-09-12 21:28 . 2008-09-12 21:28 <DIR> d-------- C:\Program Files\Apple Software Update

2008-09-12 21:25 . 2008-09-12 21:25 <DIR> d----c--- C:\Windows\System32\DRVSTORE

2008-09-12 21:25 . 2008-04-17 13:12 107,368 --a------ C:\Windows\System32\GEARAspi.dll

2008-09-12 21:25 . 2008-04-17 13:12 15,464 --a------ C:\Windows\System32\drivers\GEARAspiWDM.sys

2008-09-12 21:24 . 2008-09-12 21:25 <DIR> d-------- C:\Users\All Users\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

2008-09-12 21:24 . 2008-09-12 21:25 <DIR> d-------- C:\ProgramData\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

2008-09-12 21:24 . 2008-09-12 21:25 <DIR> d-------- C:\Program Files\iTunes

2008-09-12 21:24 . 2008-09-12 21:24 <DIR> d-------- C:\Program Files\iPod

2008-09-12 21:23 . 2008-09-12 21:23 <DIR> d-------- C:\Program Files\Bonjour

2008-09-12 21:22 . 2008-09-12 21:23 <DIR> d-------- C:\Program Files\QuickTime

2008-09-12 19:51 . 2008-09-12 19:51 <DIR> d-------- C:\Program Files\Safari

2008-09-10 22:55 . 2008-09-10 22:55 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\vlc

2008-09-10 22:52 . 2008-09-10 22:52 <DIR> d-------- C:\Program Files\VideoLAN

2008-09-10 18:21 . 2008-07-31 03:13 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll

2008-09-10 18:21 . 2008-07-31 05:32 28,160 --a------ C:\Windows\System32\Apphlpdm.dll

2008-09-10 18:20 . 2008-08-02 03:01 625,152 --a------ C:\Windows\System32\drivers\dxgkrnl.sys

2008-09-10 18:20 . 2008-06-26 05:29 565,248 --a------ C:\Windows\System32\emdmgmt.dll

2008-09-10 18:20 . 2008-06-26 05:29 303,616 --a------ C:\Windows\System32\wmpeffects.dll

2008-09-10 18:20 . 2008-05-08 21:21 211,968 --a------ C:\Windows\System32\drivers\mrxsmb10.sys

2008-09-10 18:20 . 2008-05-20 04:07 148,480 --a------ C:\Windows\System32\drivers\nwifi.sys

2008-09-10 18:20 . 2008-06-26 05:29 45,056 --a------ C:\Windows\System32\dataclen.dll

2008-09-10 18:20 . 2008-08-02 05:26 36,864 --a------ C:\Windows\System32\cdd.dll

2008-09-08 18:36 . 2008-09-08 18:36 <DIR> d-------- C:\Program Files\Rockstar Games

2008-09-08 18:32 . 2008-09-08 18:32 <DIR> d-------- C:\Program Files\DAEMON Tools Lite

2008-09-08 18:28 . 2008-09-08 18:28 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\DAEMON Tools

2008-09-08 18:28 . 2008-09-08 18:28 717,296 --a------ C:\Windows\System32\drivers\sptd.sys

2008-09-08 18:09 . 2008-09-10 22:48 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\Roxio

2008-09-08 00:35 . 2008-09-08 00:35 <DIR> d-------- C:\Program Files\MagicRotation

2008-09-08 00:35 . 2007-05-25 10:57 79,360 --a------ C:\Windows\System32\magicpvt.dll

2008-09-08 00:35 . 2006-12-05 04:08 77,824 --a------ C:\Windows\System32\mpvthook.dll

2008-09-08 00:35 . 2006-12-04 00:34 77,824 --a------ C:\Windows\System32\MagicPvtUser.exe

2008-09-08 00:35 . 2006-12-04 00:36 26,240 --a------ C:\Windows\System32\drivers\magicpvt.sys

2008-09-08 00:35 . 2006-12-04 00:35 16 --a------ C:\Windows\System32\magicpvt.dat

2008-09-08 00:35 . 2006-12-04 00:34 0 --a------ C:\Windows\System32\driver.dat

2008-09-08 00:26 . 2008-09-08 00:26 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\InstallShield

2008-09-08 00:26 . 2008-09-08 00:26 <DIR> d-------- C:\Program Files\MagicTune Premium

2008-09-08 00:26 . 2008-07-04 10:19 13,056 --a------ C:\Windows\System32\drivers\MTiCtwl.sys

2008-09-08 00:26 . 2006-11-02 14:56 3,294 --a------ C:\Windows\System32\drivers\TMM

2008-09-07 23:53 . 2008-09-07 23:53 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\Malwarebytes

2008-09-07 23:53 . 2008-09-07 23:53 <DIR> d-------- C:\Users\All Users\Malwarebytes

2008-09-07 23:53 . 2008-09-07 23:53 <DIR> d-------- C:\ProgramData\Malwarebytes

2008-09-07 23:45 . 2008-09-17 22:30 236,938,548 --a------ C:\Windows\MEMORY.DMP

2008-09-07 20:19 . 2008-09-11 18:49 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\skypePM

2008-09-07 20:19 . 2008-09-07 20:19 56 --ah----- C:\Users\All Users\ezsidmv.dat

2008-09-07 20:19 . 2008-09-07 20:19 56 --ah----- C:\ProgramData\ezsidmv.dat

2008-09-07 20:17 . 2008-09-07 20:17 <DIR> d-------- C:\Program Files\Common Files\Skype

2008-09-07 19:18 . 2008-09-11 22:38 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\Skype

2008-09-07 19:17 . 2008-09-07 20:17 <DIR> d-------- C:\Users\All Users\Skype

2008-09-07 19:17 . 2008-09-07 20:17 <DIR> d-------- C:\ProgramData\Skype

2008-09-07 19:17 . 2008-09-07 20:17 <DIR> dr------- C:\Program Files\Skype

2008-09-07 17:15 . 2008-09-07 17:15 <DIR> d--hs---- C:\found.000

2008-09-07 12:31 . 2008-09-07 12:31 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf

2008-09-07 12:27 . 2008-09-07 12:27 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\Backup MyPC

2008-09-07 12:22 . 2008-09-07 12:22 <DIR> d-------- C:\HP Personal Media Drive

2008-09-07 12:15 . 2008-09-07 12:34 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\ICAClient

2008-09-07 12:14 . 2008-09-07 12:14 <DIR> d-------- C:\Program Files\Citrix

2008-09-06 23:06 . 2008-09-06 23:06 378 --a------ C:\Windows\wininit.ini

2008-09-06 22:32 . 2008-09-06 23:47 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy

2008-09-06 22:32 . 2008-09-06 23:47 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy

2008-09-06 22:32 . 2008-09-06 22:35 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy

2008-09-06 16:59 . 2008-03-03 14:25 5,702 --ah----- C:\Windows\nod32restoretemdono.reg

2008-09-06 16:59 . 2008-03-03 18:21 568 --ah----- C:\Windows\nod32fixtemdono.reg

2008-09-06 16:56 . 2008-09-06 16:56 <DIR> d-------- C:\Users\All Users\ESET

2008-09-06 16:56 . 2008-09-06 16:56 <DIR> d-------- C:\ProgramData\ESET

2008-09-06 16:56 . 2008-09-06 16:56 <DIR> d-------- C:\Program Files\ESET

2008-09-06 16:36 . 2008-09-06 16:36 <DIR> d-------- C:\Program Files\7-Zip

2008-09-06 15:09 . 2008-09-06 15:09 90,112 --a------ C:\Windows\System32\QuickTimeVR.qtx

2008-09-06 15:09 . 2008-09-06 15:09 57,344 --a------ C:\Windows\System32\QuickTime.qts

2008-09-06 14:23 . 2006-12-04 10:25 22,723 --a------ C:\Windows\System32\sugs1l3.dll

2008-09-06 13:44 . 2008-09-06 13:44 <DIR> d-------- C:\Program Files\Trend Micro

2008-09-06 13:40 . 2008-09-06 13:40 <DIR> d-------- C:\VundoFix Backups

2008-09-06 03:10 . 2008-09-06 03:10 <DIR> d-------- C:\PerfLogs

2008-09-06 02:01 . 2008-09-06 02:21 <DIR> d-------- C:\Windows\nvidia icons

2008-09-06 00:54 . 2008-09-06 00:56 <DIR> d-------- C:\Users\All Users\Lavasoft

2008-09-06 00:54 . 2008-09-06 00:56 <DIR> d-------- C:\ProgramData\Lavasoft

2008-09-05 23:15 . 2008-09-05 23:15 <DIR> d-------- C:\Windows\System32\AGEIA

2008-09-05 23:15 . 2008-09-06 23:00 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard

2008-09-05 23:15 . 2008-09-05 23:16 <DIR> d-------- C:\Program Files\AGEIA Technologies

2008-09-05 22:06 . 2008-05-03 05:46 313,888 --a------ C:\Windows\System32\nvexpbar.dll

2008-09-05 20:33 . 2008-08-15 23:22 1,108,512 --a------ C:\Windows\System32\nvcpluir.dll

2008-09-05 20:33 . 2008-08-15 23:22 797,216 --a------ C:\Windows\System32\nvcplui.exe

2008-09-05 20:33 . 2008-08-15 23:22 420,384 --a------ C:\Windows\System32\nvcpl.cpl

2008-09-05 20:11 . 2008-09-05 20:11 <DIR> d-------- C:\Program Files\NVIDIA

2008-09-04 20:51 . 2008-09-12 21:39 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\Apple Computer

2008-09-04 20:48 . 2008-09-04 20:50 <DIR> d-------- C:\Users\All Users\Apple Computer

2008-09-04 20:48 . 2008-09-04 20:50 <DIR> d-------- C:\ProgramData\Apple Computer

2008-09-04 20:46 . 2008-09-04 20:46 <DIR> d-------- C:\Users\All Users\Apple

2008-09-04 20:46 . 2008-09-04 20:46 <DIR> d-------- C:\ProgramData\Apple

2008-09-04 20:46 . 2008-09-12 21:22 <DIR> d-------- C:\Program Files\Common Files\Apple

2008-09-04 20:30 . 2008-09-04 21:22 <DIR> d-------- C:\Program Files\The GodFather

2008-09-04 19:32 . 2008-09-07 13:21 <DIR> d-------- C:\Temp

2008-09-04 19:31 . 2008-09-04 19:51 <DIR> d-------- C:\Users\All Users\RoboForm

2008-09-04 19:31 . 2008-09-04 19:51 <DIR> d-------- C:\ProgramData\RoboForm

2008-09-03 23:41 . 2008-07-19 07:09 1,811,656 --a------ C:\Windows\System32\wuaueng.dll

2008-09-03 23:41 . 2008-07-19 05:44 1,524,736 --a------ C:\Windows\System32\wucltux.dll

2008-09-03 23:41 . 2008-07-19 07:09 563,912 --a------ C:\Windows\System32\wuapi.dll

2008-09-03 23:41 . 2008-07-18 22:08 163,904 --a------ C:\Windows\System32\wuwebv.dll

2008-09-03 23:41 . 2008-07-19 05:44 83,456 --a------ C:\Windows\System32\wudriver.dll

2008-09-03 23:41 . 2008-07-19 07:10 53,448 --a------ C:\Windows\System32\wuauclt.exe

2008-09-03 23:41 . 2008-07-19 07:10 45,768 --a------ C:\Windows\System32\wups2.dll

2008-09-03 23:41 . 2008-07-19 07:10 36,552 --a------ C:\Windows\System32\wups.dll

2008-09-03 23:41 . 2008-07-18 20:44 31,232 --a------ C:\Windows\System32\wuapp.exe

2008-09-03 23:23 . 2006-10-26 19:56 32,592 --a------ C:\Windows\System32\msonpmon.dll

2008-09-03 23:21 . 2008-09-03 23:21 <DIR> d-------- C:\Program Files\Microsoft.NET

2008-09-03 23:18 . 2008-09-03 23:18 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8

2008-09-03 23:16 . 2008-09-03 23:16 <DIR> d-------- C:\Program Files\uTorrent

2008-09-03 23:03 . 2008-09-18 19:49 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\uTorrent

2008-09-03 23:01 . 2008-09-11 18:54 <DIR> d-------- C:\Users\All Users\Microsoft Help

2008-09-03 23:01 . 2008-09-11 18:54 <DIR> d-------- C:\ProgramData\Microsoft Help

2008-09-03 23:01 . 2008-09-03 23:01 <DIR> dr-h----- C:\MSOCache

2008-09-03 00:06 . 2008-09-03 00:06 <DIR> d-------- C:\Program Files\Microsoft SQL Server Compact Edition

 

.

(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-09-17 16:57 --------- d-----w C:\Program Files\Java

2008-09-11 16:52 --------- d-----w C:\Program Files\Microsoft Works

2008-09-10 20:55 --------- d-----w C:\Users\Tangemo\AppData\Roaming\vlc

2008-09-08 16:36 --------- d--h--w C:\Program Files\InstallShield Installation Information

2008-09-08 16:09 --------- d-----w C:\ProgramData\Sonic

2008-09-07 15:39 --------- d-----w C:\ProgramData\NVIDIA

2008-09-07 10:22 --------- d-----w C:\Program Files\Roxio

2008-09-06 12:22 65,536 ----a-w C:\Windows\System32\sugs1ci.dll

2008-09-06 12:22 151,552 ----a-w C:\Windows\System32\sugs1ci.exe

2008-09-06 01:22 174 --sha-w C:\Program Files\desktop.ini

2008-09-06 01:12 --------- d-----w C:\Program Files\Windows Sidebar

2008-09-06 01:12 --------- d-----w C:\Program Files\Windows Photo Gallery

2008-09-06 01:12 --------- d-----w C:\Program Files\Windows Mail

2008-09-06 01:12 --------- d-----w C:\Program Files\Windows Journal

2008-09-06 01:12 --------- d-----w C:\Program Files\Windows Defender

2008-09-06 01:12 --------- d-----w C:\Program Files\Windows Collaboration

2008-09-06 01:12 --------- d-----w C:\Program Files\Windows Calendar

2008-09-06 00:45 82,432 ----a-w C:\Windows\System32\axaltocm.dll

2008-09-06 00:45 101,888 ----a-w C:\Windows\System32\ifxcardm.dll

2008-09-03 21:22 --------- d-----w C:\Program Files\MSBuild

2008-09-02 19:29 --------- d-----w C:\Program Files\Common Files\PX Storage Engine

2008-09-01 17:48 --------- d-----w C:\Program Files\HP

2008-08-24 09:00 --------- d-----w C:\Program Files\Google

2008-08-24 08:38 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll

2008-08-24 07:43 --------- d-sh--w C:\ProgramData\Vorlagen

2008-08-24 07:43 --------- d-sh--w C:\ProgramData\Startmenü

2008-08-24 07:43 --------- d-sh--w C:\ProgramData\Favoriten

2008-08-24 07:43 --------- d-sh--w C:\ProgramData\Dokumente

2008-08-24 07:43 --------- d-sh--w C:\ProgramData\Anwendungsdaten

2008-08-24 07:43 --------- d-sh--w C:\Program Files\Gemeinsame Dateien

2008-08-01 09:05 70,936 ----a-w C:\Windows\System32\PhysXLoader.dll

2008-07-31 03:32 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll

2008-07-31 03:32 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll

2008-07-31 03:32 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll

2008-07-22 18:32 32,000 ----a-w C:\Windows\system32\drivers\usbaapl.sys

2008-07-18 18:39 586,752 ----a-w C:\Windows\WLXPGSS.SCR

2008-07-09 03:05 129,520 ------w C:\Windows\System32\PxAFS.DLL

2008-07-09 03:05 120,568 ------w C:\Windows\System32\pxcpyi64.exe

2008-07-09 03:05 118,256 ------w C:\Windows\System32\pxinsi64.exe

2008-02-07 19:46 13,624 ----a-w C:\Program Files\mozilla firefox\plugins\cgpcfg.dll

2008-02-07 19:46 87,360 ----a-w C:\Program Files\mozilla firefox\plugins\CgpCore.dll

2008-02-07 19:46 91,448 ----a-w C:\Program Files\mozilla firefox\plugins\confmgr.dll

2008-02-07 19:46 21,824 ----a-w C:\Program Files\mozilla firefox\plugins\ctxlogging.dll

2008-02-07 19:46 206,136 ----a-w C:\Program Files\mozilla firefox\plugins\ctxmui.dll

2008-02-07 19:46 31,544 ----a-w C:\Program Files\mozilla firefox\plugins\icafile.dll

2008-02-07 19:46 40,248 ----a-w C:\Program Files\mozilla firefox\plugins\icalogon.dll

2007-03-16 15:27 479,232 ----a-w C:\Program Files\mozilla firefox\plugins\msvcm80.dll

2007-03-16 15:27 548,864 ----a-w C:\Program Files\mozilla firefox\plugins\msvcp80.dll

2007-03-16 15:27 626,688 ----a-w C:\Program Files\mozilla firefox\plugins\msvcr80.dll

2007-07-20 10:47 981,170 ----a-w C:\Program Files\mozilla firefox\plugins\sslsdk_b.dll

2008-02-07 19:46 24,384 ----a-w C:\Program Files\mozilla firefox\plugins\TcpPServ.dll

.

 

((((((((((((((((((((((((((((( snapshot_2008-09-17_22.51.17.61 )))))))))))))))))))))))))))))))))))))))))

.

- 2008-09-17 20:38:29 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2008-09-18 16:48:46 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2008-09-17 20:38:29 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2008-09-18 16:48:46 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

- 2008-09-17 20:39:14 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT

+ 2008-09-18 16:50:12 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT

+ 2008-09-18 16:50:12 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1

- 2008-09-17 20:39:53 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT

+ 2008-09-18 17:00:09 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT

+ 2008-09-18 17:00:09 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1

- 2008-09-17 20:40:14 7,830 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1997900430-2287122297-485223492-1001_UserData.bin

+ 2008-09-18 16:51:00 7,838 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1997900430-2287122297-485223492-1001_UserData.bin

- 2008-09-17 20:40:14 64,002 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin

+ 2008-09-18 16:51:00 64,118 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin

- 2008-09-17 20:40:10 46,072 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2008-09-18 16:50:59 46,152 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin

.

(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))

.

.

*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]

"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 125952]

"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]

"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [2008-09-03 267056]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CCUTRAYICON"="FactoryMode" [X]

"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]

"KBD"="C:\HP\KBD\KbdStub.EXE" [2006-12-08 65536]

"OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]

"HP Health Check Scheduler"="c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-05-24 71176]

"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]

"SunJavaUpdateReg"="C:\Windows\system32\jureg.exe" [2008-06-10 54672]

"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]

"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]

"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-06-10 1447168]

"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-08-15 13576736]

"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-08-15 92704]

"MagicRotation"="C:\Program Files\MagicRotation\MagicPvt.exe" [2007-08-01 2572410]

"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]

"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]

"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-10 289576]

"MagicTuneEngine"="C:\Program Files\MagicTune Premium\MagicTuneEngine.exe" [2008-08-05 69632]

"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]

"RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 C:\Windows\RtHDVCpl.exe]

 

C:\Users\Tangemo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartupBUFFALO NAS Navigator.lnk - C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe [2007-05-11 1070648]

Sk„rmurklipp och start f”r OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]

 

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartupPersonal.lnk - C:\Program Files\Personal\bin\Personal.exe [2008-08-29 910864]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableUIADesktopToggle"= 0 (0x0)

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{39B15A4A-8C87-43B7-9859-E98F429DDEBB}"= "C:\Windows\system32\opnoMdAs.dll" [bU]

 

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GammaTray.lnk]

path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GammaTray.lnk

backup=C:\Windows\pss\GammaTray.lnk.CommonStartup

backupExtension=.CommonStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MagicTuneEngine]

--a------ 2008-08-05 03:42 69632 C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"UacDisableNotify"=dword:00000001

"InternetSettingsDisableNotify"=dword:00000001

"AutoUpdateDisableNotify"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{1CA32AD2-4EEB-4DA7-A9DF-E3E61BA3A5F4}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM

"{63C6B2CA-BA49-471D-945A-8674446304B8}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM

"{C69AD56D-94B9-473E-9FD2-25C57F5D91EF}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv Media Server

"{2B53614B-68D7-4679-AB96-7D068765ED7B}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv Media Server

"{E89BC0FB-7491-4272-B575-6B0F18FC60B0}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service

"{808F38D9-0B42-480A-A3B3-104C491FFC4E}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service

"{D9C14108-24FB-4F3A-A4C2-C25EA317FAFE}"= TCP:9442:127.0.0.1:Intel® Viiv Media Server Discovery

"{60D7B77D-8F66-418D-86A6-B3CAE8C7B4DB}"= TCP:1900:LocalSubnet:LocalSubnet:Intel® Viiv Media Server UPnP Discovery

"{34456AA8-885F-4402-8FDC-8EEAD919BA36}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

"{AFE2C24B-F377-4222-8395-201B77B37026}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (TCP-In)

"{21553A70-2072-4A7A-B49D-0FBDF57822B7}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (UDP-In)

"{104157BD-6511-440F-969B-DADCBD7DD19F}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook

"{0310470A-21F5-4F63-98D3-8B403A83B13E}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove

"{AEC4103E-4B3D-47AC-9916-FB80A964CC24}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove

"{33F701C6-CD2E-4CC0-930B-9FBCCA3AF0BC}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote

"{9FD332A1-E2D7-4739-8E27-2F1001621A24}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote

"TCP Query User{46C4FFEC-6DF3-4C3D-9ADB-DCEB68179216}C:\\program files\\skype\\phone\\skype.exe"= UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath

"UDP Query User{78ACFFB9-F195-4346-A8D6-8DB1C0B54566}C:\\program files\\skype\\phone\\skype.exe"= TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath

"{A9189C8B-A74D-42BA-86D4-C789312B0CF2}"= C:\Program Files\Skype\Phone\Skype.exe:Skype

"TCP Query User{E83AD50C-FE18-435C-9E58-7D4DB2E018CD}C:\\program files\\magictune premium\\magictune.exe"= UDP:C:\program files\magictune premium\magictune.exe:MagicTune

"UDP Query User{16D3F237-9EBD-4D38-9522-88D70A37E7F9}C:\\program files\\magictune premium\\magictune.exe"= TCP:C:\program files\magictune premium\magictune.exe:MagicTune

"{1501D97F-4171-4D6D-AF58-589234502B6A}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour

"{3B531429-BCB1-4A57-96C4-2A965673133B}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour

"{AA23DB46-B3DE-48A7-90B1-CF4F9DB2C805}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes

"{9A6C4C4D-BE3E-45FF-BB2A-44064D19E417}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes

"TCP Query User{B5F2187C-3744-4B5C-A154-43ADB67B857E}C:\\program files\\totalcmd\\totalcmd.exe"= UDP:C:\program files\totalcmd\totalcmd.exe:Total Commander 32 bit international version, file manager replacement for Windows

"UDP Query User{3C19E335-400D-4BA9-9411-3BBE350D6940}C:\\program files\\totalcmd\\totalcmd.exe"= TCP:C:\program files\totalcmd\totalcmd.exe:Total Commander 32 bit international version, file manager replacement for Windows

"TCP Query User{B79E5A7A-1970-40AD-B0DC-2ABBAF7892CB}C:\\program files\\allway sync\\bin\\syncappw.exe"= UDP:C:\program files\allway sync\bin\syncappw.exe:syncappw

"UDP Query User{58BF8E92-704A-4D49-BF98-49195EA3C017}C:\\program files\\allway sync\\bin\\syncappw.exe"= TCP:C:\program files\allway sync\bin\syncappw.exe:syncappw

"{81860274-0DB0-45B1-9C1B-A2AED1EAE96C}"= UDP:C:\Users\Tangemo\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool

"{DC2A8279-EDB6-49B2-98CF-EE4412DA95DE}"= TCP:C:\Users\Tangemo\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]

"EnableFirewall"= 0 (0x0)

 

R1 epfwtdir;epfwtdir;C:\Windows\system32\DRIVERS\epfwtdir.sys [2008-06-10 34312]

R1 magicpvt;magicpvt;C:\Windows\system32\drivers\magicpvt.sys [2006-12-04 26240]

R2 DQLWinService;DQLWinService;C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2006-09-03 208896]

R2 HPBtnSrv;HP Chasis Button Service;c:\hp\HPEZBTN\HPBtnSrv.exe [2007-05-29 198240]

R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;C:\Windows\system32\drivers\HCW85BDA.sys [2007-06-11 968064]

R3 PID_0920;Logitech QuickCam Express(PID_0920);C:\Windows\system32\DRIVERS\LV532AV.SYS [2005-01-31 163328]

S2 IntelDHSvcConf;Intel DH Service;C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe [2006-05-10 29696]

S2 NOD32FiXTemDono;Eset Nod32 Boot;C:\Windows\system32\regedt32.exe [2006-11-02 9216]

S3 netr73;USB Wireless 802.11 b/g Adaptor Driver for Vista;C:\Windows\system32\DRIVERS\netr73.sys [2007-04-20 265216]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]

\shell\AutoRun\command - E:\monsetup.exe

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{581079a0-7dc3-11dd-8fe3-001d60e0fc4f}]

\shell\AutoRun\command - F:\Install.exe

 

*Newly Created Service* - MBAMSWISSARMY

.

Inhalt des "geplante Tasks" Ordners

.

 

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-09-18 19:54:20

Windows 6.0.6001 Service Pack 1 NTFS

 

Scanne versteckte Prozesse...

 

Scanne versteckte Autostarteinträge...

 

Scanne versteckte Dateien...

 

Scan erfolgreich abgeschlossen

versteckte Dateien: 0

 

**************************************************************************

.

Zeit der Fertigstellung: 2008-09-18 19:56:37

ComboFix-quarantined-files.txt 2008-09-18 17:56:32

ComboFix2.txt 2008-09-17 20:52:31

ComboFix3.txt 2008-09-08 21:52:10

ComboFix4.txt 2008-09-07 22:03:47

 

Vor Suchlauf: 10 Verzeichnis(se), 122,945,269,760 Bytes frei

Nach Suchlauf: 20 Verzeichnis(se), 122,898,366,464 Bytes frei

 

332 --- E O F --- 2008-09-18 16:55:02[/log]

 

[log]Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 20:03:48, on 2008-09-18

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Boot mode: Normal

 

Running processes:

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\hp\support\hpsysdrv.exe

C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe

C:\Windows\RtHDVCpl.exe

C:\Windows\System32\jureg.exe

C:\Windows\system32\schtasks.exe

C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\MagicRotation\MagicPvt.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Windows\ehome\ehtray.exe

C:\Program Files\DAEMON Tools Lite\daemon.exe

C:\Windows\ehome\ehmsas.exe

C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe

C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

C:\Program Files\Windows Sidebar\sidebar.exe

C:\hp\kbd\kbd.exe

C:\Windows\system32\conime.exe

C:\Windows\Explorer.exe

C:\Windows\system32\NOTEPAD.EXE

C:\Windows\system32\rundll32.exe

C:\Windows\system32\FirewallControlPanel.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gp.se/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896'>http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=SV_SE&c=74&bd=Pavilion&pf=desktop

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe

O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE

O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode

O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateReg] "C:\Windows\system32\jureg.exe"

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [MagicRotation] C:\Program Files\MagicRotation\MagicPvt.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [MagicTuneEngine] C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')

O4 - Startup: BUFFALO NAS Navigator.lnk = C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe

O4 - Startup: Skärmurklipp och start för OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Personal.lnk = C:\Program Files\Personal\bin\Personal.exe

O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll

O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll

O9 - Extra button: Skicka till OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: Ski&cka till OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O13 - Gopher Prefix:

O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: Intel® Alert Service (AlertService) - Intel® Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe

O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe

O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe

O23 - Service: HP Chasis Button Service (HPBtnSrv) - Unknown owner - c:\hp\HPEZBTN\HPBtnSrv.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Intel® Software Services Manager (ISSM) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe

O23 - Service: Intel® Viiv Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe

O23 - Service: Intel® Application Tracker (MCLServiceATL) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

O23 - Service: Intel® Remoting Service (Remote UI Service) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe

O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe

 

--

End of file - 9884 bytes

[/log]

 

Länk till kommentar
Dela på andra webbplatser

[log]Har du använt registereditorn regedit förut?[/log]

 

Ja, har bland annat försökt att mota bort nyckeln f81b46e9 som vill köra rundll32.exe med dll-filen urwfogd.dll eller nåt liknande som ej existerar. Jag måste kanske prova att göra det i felsäkert läge eller nåt, för den kommer alltid igen som det är nu, fast jag tar bort den...

 

[log]Är brandväggen igång i datorn?[/log]

 

Ja, windows-brandväggen är på när jag inte kör combofix...

 

[log]Hur fungerar datorn?[/log]

 

Ganska fint. Var värre innan då jag hade mer trojaner på den. Då öppnade sig en massa nya websidor och dylikt. Nu är det bara en popup när jag startar datorn med meddelandet Rundll32.exe kunde inte starta modulen urwfogd.dll (eller något liknande). Sen kan det ju vara annat suspekt som händer i bakgrunden....

 

 

 

Länk till kommentar
Dela på andra webbplatser

Nu är det bara en popup när jag startar datorn med meddelandet Rundll32.exe kunde inte starta modulen urwfogd.dll (eller något liknande)
Det betyder att filen är borta men inte referensen i registret. Men får du det felmeddelandet fortfarande? För jag ser inte längre till referensen.

 

I registret:

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

Ta bort raden

"{39B15A4A-8C87-43B7-9859-E98F429DDEBB}"= "C:\Windows\system32\opnoMdAs.dll"

till höger.

 

Länk till kommentar
Dela på andra webbplatser

Hej.

 

Nu är meddelandet borta...

 

Hijackthislog:

 

[log]Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 21:21:16, on 2008-09-18

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Boot mode: Normal

 

Running processes:

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\hp\support\hpsysdrv.exe

C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe

C:\Windows\RtHDVCpl.exe

C:\Windows\System32\jureg.exe

C:\Windows\system32\schtasks.exe

C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\MagicRotation\MagicPvt.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Windows\ehome\ehtray.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Program Files\DAEMON Tools Lite\daemon.exe

C:\Program Files\uTorrent\uTorrent.exe

C:\Windows\ehome\ehmsas.exe

C:\Program Files\Personal\bin\Personal.exe

C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe

C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\iTunes\iTunes.exe

C:\Program Files\MagicTune Premium\MagicTune.exe

C:\hp\kbd\kbd.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gp.se/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896'>http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=SV_SE&c=74&bd=Pavilion&pf=desktop

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe

O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE

O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode

O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateReg] "C:\Windows\system32\jureg.exe"

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [MagicRotation] C:\Program Files\MagicRotation\MagicPvt.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [MagicTuneEngine] C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')

O4 - Startup: BUFFALO NAS Navigator.lnk = C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe

O4 - Startup: Skärmurklipp och start för OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Personal.lnk = C:\Program Files\Personal\bin\Personal.exe

O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll

O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll

O9 - Extra button: Skicka till OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: Ski&cka till OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O13 - Gopher Prefix:

O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: Intel® Alert Service (AlertService) - Intel® Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe

O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe

O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe

O23 - Service: HP Chasis Button Service (HPBtnSrv) - Unknown owner - c:\hp\HPEZBTN\HPBtnSrv.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Intel® Software Services Manager (ISSM) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe

O23 - Service: Intel® Viiv Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe

O23 - Service: Intel® Application Tracker (MCLServiceATL) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

O23 - Service: Intel® Remoting Service (Remote UI Service) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe

O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe

 

--

End of file - 10008 bytes[/log]

 

 

Virusfri?

 

Länk till kommentar
Dela på andra webbplatser

Hej.

 

...det dök dock upp ett nytt problem efter omstart. När jag väljer extra stora ikoner i vista, vilket jag har som standard på skrivbordet och för bilder, syns ej ikonerna alls. Hade antagligen med nyckeln jag tog bort att göra. Normalstora ikoner syns dock...

 

 

 

Länk till kommentar
Dela på andra webbplatser

Det var ju konstigt för du sa att filen inte fanns i datorn. Men du ser ju i mitt inlägg 21:05 hur det såg ut i registret förut så du kan skapa den på nytt.

 

Jag ser inget skadligt i loggarna.

 

Länk till kommentar
Dela på andra webbplatser

Hej,

 

ja, lite skumt är det. Men jag "får nog leva med" halvstora ikoner ;)

 

Känns skönt att det verkar vara borta. Även MBAB sa att datorn är ren.

 

Många turer var det, men tusen tack för hjälpen!!!

 

Länk till kommentar
Dela på andra webbplatser

Ikonerna på skrivbordet kan man ändra storlek på enligt en inlägg för några dagar sedan på ett smart sätt, jag tror det var genom att klicka på Skrivbordet, hålla nere Ctrl och så skrolla på mushjulet.

 

Länk till kommentar
Dela på andra webbplatser

Hej!

 

Tack för tipset....

 

Man ska ju inte ropa hej förrän man är över bron, och jag hade inte kommit över bron igår visade det sig. Det irriterade meddelandet som mitt inlägg här på eforum började med, kommer fortfarande när jag startar upp datorn. Var visst bara en gång, som jag slapp det, och då trodde jag att jag var fri....

 

Meddelandet som kommer upp är (fritt översatt från tyska)

Fel vid laddning av

C:\Users\Tangemo\AppData\Local\Temp\urwftogd.dll

Den angivna modulen hittades inte.

 

Det styrs antagligen av den envetna nyckeln i registret som pånyttföds varje gång jag startar om datorn:

 

HKEY_USERS\S-1-5-21-1997900430-2287122297-485223492-1001\Software\Microsoft\Windows\CurrentVersion\Run

Name: f81b46e9

Type: REG_SZ

Value:rundll32.exe "C:\Users\Tangemo\AppData\Local\Temp\urwftogd.dll",b

 

Den filen finns som sagt inte. Men i samma mapp hittade jag en lurig dll-fil

C:\Users\Tangemo\AppData\Local\Temp\catchme.dll

 

Körde den i Virustotal...

 

[log] Virustotal-log

 

Antivirus Version Senaste Uppdatering Resultat

AhnLab-V3 2008.9.19.2 2008.09.19 -

AntiVir 7.8.1.34 2008.09.19 -

Authentium 5.1.0.4 2008.09.19 W32/Heuristic-KPP!Eldorado

Avast 4.8.1195.0 2008.09.19 -

AVG 8.0.0.161 2008.09.19 -

BitDefender 7.2 2008.09.19 -

CAT-QuickHeal 9.50 2008.09.19 -

ClamAV 0.93.1 2008.09.19 -

DrWeb 4.44.0.09170 2008.09.19 -

eSafe 7.0.17.0 2008.09.18 -

eTrust-Vet 31.6.6091 2008.09.16 -

Ewido 4.0 2008.09.19 -

F-Prot 4.4.4.56 2008.09.19 W32/Heuristic-KPP!Eldorado

F-Secure 8.0.14332.0 2008.09.19 -

Fortinet 3.113.0.0 2008.09.19 -

GData 19 2008.09.19 -

Ikarus T3.1.1.34.0 2008.09.19 -

K7AntiVirus 7.10.464 2008.09.19 -

Kaspersky 7.0.0.125 2008.09.19 -

McAfee 5387 2008.09.18 -

Microsoft 1.3903 2008.09.19 -

NOD32v2 3456 2008.09.19 -

Norman 5.80.02 2008.09.19 -

Panda 9.0.0.4 2008.09.19 -

PCTools 4.4.2.0 2008.09.19 -

Prevx1 V2 2008.09.19 -

Rising 20.62.42.00 2008.09.19 -

Sophos 4.33.0 2008.09.19 -

Sunbelt 3.1.1651.1 2008.09.19 -

Symantec 10 2008.09.19 -

TheHacker 6.3.0.9.087 2008.09.18 -

TrendMicro 8.700.0.1004 2008.09.19 -

VBA32 3.12.8.5 2008.09.18 -

ViRobot 2008.9.19.1383 2008.09.19 -

VirusBuster 4.5.11.0 2008.09.19 -

Webwasher-Gateway 6.6.2 2008.09.19 -[/log]

 

Hijackthis log:

 

[log]Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 18:21:34, on 2008-09-19

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Boot mode: Normal

 

Running processes:

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\hp\support\hpsysdrv.exe

C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe

C:\Windows\RtHDVCpl.exe

C:\Windows\System32\jureg.exe

C:\Windows\system32\schtasks.exe

C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\MagicRotation\MagicPvt.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Windows\ehome\ehtray.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Program Files\DAEMON Tools Lite\daemon.exe

C:\Windows\ehome\ehmsas.exe

C:\Program Files\uTorrent\uTorrent.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\Logitech\SetPoint\SetPoint.exe

C:\Program Files\Personal\bin\Personal.exe

C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe

C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE

C:\Program Files\MagicTune Premium\MagicTune.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\hp\kbd\kbd.exe

C:\Windows\system32\NOTEPAD.EXE

C:\Windows\system32\NOTEPAD.EXE

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

C:\Program Files\Windows Media Player\wmplayer.exe

C:\Program Files\Windows Media Player\WMPNSCFG.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gp.se/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896'>http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=SV_SE&c=74&bd=Pavilion&pf=desktop

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe

O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE

O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode

O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateReg] "C:\Windows\system32\jureg.exe"

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [MagicRotation] C:\Program Files\MagicRotation\MagicPvt.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [MagicTuneEngine] C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [f81b46e9] rundll32.exe "C:\Users\Tangemo\AppData\Local\Temp\urwftogd.dll",b

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')

O4 - Startup: BUFFALO NAS Navigator.lnk = C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe

O4 - Startup: Skärmurklipp och start för OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe

O4 - Global Startup: Personal.lnk = C:\Program Files\Personal\bin\Personal.exe

O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll

O9 - Extra button: Skicka till OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: Ski&cka till OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O13 - Gopher Prefix:

O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: Intel® Alert Service (AlertService) - Intel® Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe

O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe

O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe

O23 - Service: HP Chasis Button Service (HPBtnSrv) - Unknown owner - c:\hp\HPEZBTN\HPBtnSrv.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Intel® Software Services Manager (ISSM) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe

O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe

O23 - Service: Intel® Viiv Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe

O23 - Service: Intel® Application Tracker (MCLServiceATL) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

O23 - Service: Intel® Remoting Service (Remote UI Service) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe

O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe

 

--

End of file - 10805 bytes

[/log]

 

Hur gå vidare?

 

Länk till kommentar
Dela på andra webbplatser

Hej!

 

"Senare" - Finns det begreppet hos dig? Verkar som du gör allt direkt... ;)

 

[log]ComboFix 08-09-16.05 - Tangemo 2008-09-19 18:50:13.6 - NTFSx86

Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1031.18.2037 [GMT 2:00]

ausgeführt von:: C:\Users\Tangemo\Desktop\ComboFix.exe

.

 

((((((((((((((((((((((( Dateien erstellt von 2008-08-19 bis 2008-09-19 ))))))))))))))))))))))))))))))

.

 

2008-09-18 22:30 . 2008-09-18 22:30 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\Logitech

2008-09-18 22:30 . 2008-09-18 22:30 <DIR> d-------- C:\Users\All Users\LogiShrd

2008-09-18 22:30 . 2008-09-18 22:30 <DIR> d-------- C:\ProgramData\LogiShrd

2008-09-18 22:29 . 2008-09-18 22:29 0 --ah----- C:\Windows\System32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf

2008-09-18 22:29 . 2008-09-18 22:29 0 --ah----- C:\Windows\System32\drivers\Msft_Kernel_LMouFilt_01005.Wdf

2008-09-18 22:27 . 2008-09-18 22:27 <DIR> d-------- C:\Users\All Users\Logitech

2008-09-18 22:27 . 2008-09-18 22:27 <DIR> d-------- C:\ProgramData\Logitech

2008-09-18 22:27 . 2008-09-18 22:27 <DIR> d-------- C:\Program Files\Logitech

2008-09-18 22:27 . 2008-09-18 22:27 <DIR> d-------- C:\Program Files\Common Files\Logishrd

2008-09-18 22:27 . 2008-05-02 02:38 301,656 --a------ C:\Windows\System32\BtCoreIf.dll

2008-09-18 22:27 . 2008-05-02 02:39 170,512 --a------ C:\Windows\System32\kemutb.dll

2008-09-18 22:27 . 2008-05-02 02:39 145,936 --a------ C:\Windows\System32\KemUtil.dll

2008-09-18 22:27 . 2008-05-02 02:40 117,264 --a------ C:\Windows\System32\KemWnd.dll

2008-09-18 22:27 . 2008-05-02 02:40 84,496 --a------ C:\Windows\System32\KemXML.dll

2008-09-17 19:47 . 2008-09-17 19:47 <DIR> d-------- C:\Users\All Users\NortonInstaller

2008-09-17 19:47 . 2008-09-17 19:47 <DIR> d-------- C:\ProgramData\NortonInstaller

2008-09-17 18:52 . 2008-09-17 18:52 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware

2008-09-17 18:52 . 2008-09-10 00:04 38,528 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys

2008-09-17 18:52 . 2008-09-10 00:03 17,200 --a------ C:\Windows\System32\drivers\mbam.sys

2008-09-13 12:33 . 2008-09-13 12:33 <DIR> d-------- C:\Users\All Users\Office Genuine Advantage

2008-09-13 12:33 . 2008-09-13 12:33 <DIR> d-------- C:\ProgramData\Office Genuine Advantage

2008-09-13 11:20 . 2008-09-13 11:20 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\Sync App Settings

2008-09-13 11:19 . 2008-09-13 11:19 <DIR> d-------- C:\Users\All Users\Sync App Settings

2008-09-13 11:19 . 2008-09-13 11:19 <DIR> d-------- C:\ProgramData\Sync App Settings

2008-09-13 11:19 . 2008-09-13 11:19 <DIR> d-------- C:\Program Files\Allway Sync

2008-09-12 21:28 . 2008-09-12 21:28 <DIR> d-------- C:\Program Files\Apple Software Update

2008-09-12 21:25 . 2008-09-12 21:25 <DIR> d----c--- C:\Windows\System32\DRVSTORE

2008-09-12 21:25 . 2008-04-17 13:12 107,368 --a------ C:\Windows\System32\GEARAspi.dll

2008-09-12 21:25 . 2008-04-17 13:12 15,464 --a------ C:\Windows\System32\drivers\GEARAspiWDM.sys

2008-09-12 21:24 . 2008-09-12 21:25 <DIR> d-------- C:\Users\All Users\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

2008-09-12 21:24 . 2008-09-12 21:25 <DIR> d-------- C:\ProgramData\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

2008-09-12 21:24 . 2008-09-12 21:25 <DIR> d-------- C:\Program Files\iTunes

2008-09-12 21:24 . 2008-09-12 21:24 <DIR> d-------- C:\Program Files\iPod

2008-09-12 21:23 . 2008-09-12 21:23 <DIR> d-------- C:\Program Files\Bonjour

2008-09-12 21:22 . 2008-09-12 21:23 <DIR> d-------- C:\Program Files\QuickTime

2008-09-12 19:51 . 2008-09-12 19:51 <DIR> d-------- C:\Program Files\Safari

2008-09-10 22:55 . 2008-09-10 22:55 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\vlc

2008-09-10 22:52 . 2008-09-10 22:52 <DIR> d-------- C:\Program Files\VideoLAN

2008-09-10 18:21 . 2008-07-31 03:13 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll

2008-09-10 18:21 . 2008-07-31 05:32 28,160 --a------ C:\Windows\System32\Apphlpdm.dll

2008-09-10 18:20 . 2008-08-02 03:01 625,152 --a------ C:\Windows\System32\drivers\dxgkrnl.sys

2008-09-10 18:20 . 2008-06-26 05:29 565,248 --a------ C:\Windows\System32\emdmgmt.dll

2008-09-10 18:20 . 2008-06-26 05:29 303,616 --a------ C:\Windows\System32\wmpeffects.dll

2008-09-10 18:20 . 2008-05-08 21:21 211,968 --a------ C:\Windows\System32\drivers\mrxsmb10.sys

2008-09-10 18:20 . 2008-05-20 04:07 148,480 --a------ C:\Windows\System32\drivers\nwifi.sys

2008-09-10 18:20 . 2008-06-26 05:29 45,056 --a------ C:\Windows\System32\dataclen.dll

2008-09-10 18:20 . 2008-08-02 05:26 36,864 --a------ C:\Windows\System32\cdd.dll

2008-09-08 18:36 . 2008-09-08 18:36 <DIR> d-------- C:\Program Files\Rockstar Games

2008-09-08 18:32 . 2008-09-08 18:32 <DIR> d-------- C:\Program Files\DAEMON Tools Lite

2008-09-08 18:28 . 2008-09-08 18:28 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\DAEMON Tools

2008-09-08 18:28 . 2008-09-08 18:28 717,296 --a------ C:\Windows\System32\drivers\sptd.sys

2008-09-08 18:09 . 2008-09-10 22:48 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\Roxio

2008-09-08 00:35 . 2008-09-08 00:35 <DIR> d-------- C:\Program Files\MagicRotation

2008-09-08 00:35 . 2007-05-25 10:57 79,360 --a------ C:\Windows\System32\magicpvt.dll

2008-09-08 00:35 . 2006-12-05 04:08 77,824 --a------ C:\Windows\System32\mpvthook.dll

2008-09-08 00:35 . 2006-12-04 00:34 77,824 --a------ C:\Windows\System32\MagicPvtUser.exe

2008-09-08 00:35 . 2006-12-04 00:36 26,240 --a------ C:\Windows\System32\drivers\magicpvt.sys

2008-09-08 00:35 . 2006-12-04 00:35 16 --a------ C:\Windows\System32\magicpvt.dat

2008-09-08 00:35 . 2006-12-04 00:34 0 --a------ C:\Windows\System32\driver.dat

2008-09-08 00:26 . 2008-09-08 00:26 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\InstallShield

2008-09-08 00:26 . 2008-09-08 00:26 <DIR> d-------- C:\Program Files\MagicTune Premium

2008-09-08 00:26 . 2008-07-04 10:19 13,056 --a------ C:\Windows\System32\drivers\MTiCtwl.sys

2008-09-08 00:26 . 2006-11-02 14:56 3,294 --a------ C:\Windows\System32\drivers\TMM

2008-09-07 23:53 . 2008-09-07 23:53 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\Malwarebytes

2008-09-07 23:53 . 2008-09-07 23:53 <DIR> d-------- C:\Users\All Users\Malwarebytes

2008-09-07 23:53 . 2008-09-07 23:53 <DIR> d-------- C:\ProgramData\Malwarebytes

2008-09-07 23:45 . 2008-09-17 22:30 236,938,548 --a------ C:\Windows\MEMORY.DMP

2008-09-07 20:19 . 2008-09-11 18:49 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\skypePM

2008-09-07 20:19 . 2008-09-07 20:19 56 --ah----- C:\Users\All Users\ezsidmv.dat

2008-09-07 20:19 . 2008-09-07 20:19 56 --ah----- C:\ProgramData\ezsidmv.dat

2008-09-07 20:17 . 2008-09-07 20:17 <DIR> d-------- C:\Program Files\Common Files\Skype

2008-09-07 19:18 . 2008-09-11 22:38 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\Skype

2008-09-07 19:17 . 2008-09-07 20:17 <DIR> d-------- C:\Users\All Users\Skype

2008-09-07 19:17 . 2008-09-07 20:17 <DIR> d-------- C:\ProgramData\Skype

2008-09-07 19:17 . 2008-09-07 20:17 <DIR> dr------- C:\Program Files\Skype

2008-09-07 17:15 . 2008-09-07 17:15 <DIR> d--hs---- C:\found.000

2008-09-07 12:31 . 2008-09-07 12:31 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf

2008-09-07 12:27 . 2008-09-07 12:27 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\Backup MyPC

2008-09-07 12:22 . 2008-09-07 12:22 <DIR> d-------- C:\HP Personal Media Drive

2008-09-07 12:15 . 2008-09-07 12:34 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\ICAClient

2008-09-07 12:14 . 2008-09-07 12:14 <DIR> d-------- C:\Program Files\Citrix

2008-09-06 23:06 . 2008-09-06 23:06 378 --a------ C:\Windows\wininit.ini

2008-09-06 22:32 . 2008-09-06 23:47 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy

2008-09-06 22:32 . 2008-09-06 23:47 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy

2008-09-06 22:32 . 2008-09-06 22:35 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy

2008-09-06 16:59 . 2008-03-03 14:25 5,702 --ah----- C:\Windows\nod32restoretemdono.reg

2008-09-06 16:59 . 2008-03-03 18:21 568 --ah----- C:\Windows\nod32fixtemdono.reg

2008-09-06 16:56 . 2008-09-06 16:56 <DIR> d-------- C:\Users\All Users\ESET

2008-09-06 16:56 . 2008-09-06 16:56 <DIR> d-------- C:\ProgramData\ESET

2008-09-06 16:56 . 2008-09-06 16:56 <DIR> d-------- C:\Program Files\ESET

2008-09-06 16:36 . 2008-09-06 16:36 <DIR> d-------- C:\Program Files\7-Zip

2008-09-06 15:09 . 2008-09-06 15:09 90,112 --a------ C:\Windows\System32\QuickTimeVR.qtx

2008-09-06 15:09 . 2008-09-06 15:09 57,344 --a------ C:\Windows\System32\QuickTime.qts

2008-09-06 14:23 . 2006-12-04 10:25 22,723 --a------ C:\Windows\System32\sugs1l3.dll

2008-09-06 13:44 . 2008-09-06 13:44 <DIR> d-------- C:\Program Files\Trend Micro

2008-09-06 13:40 . 2008-09-06 13:40 <DIR> d-------- C:\VundoFix Backups

2008-09-06 03:10 . 2008-09-06 03:10 <DIR> d-------- C:\PerfLogs

2008-09-06 02:01 . 2008-09-06 02:21 <DIR> d-------- C:\Windows\nvidia icons

2008-09-06 00:54 . 2008-09-06 00:56 <DIR> d-------- C:\Users\All Users\Lavasoft

2008-09-06 00:54 . 2008-09-06 00:56 <DIR> d-------- C:\ProgramData\Lavasoft

2008-09-05 23:15 . 2008-09-05 23:15 <DIR> d-------- C:\Windows\System32\AGEIA

2008-09-05 23:15 . 2008-09-06 23:00 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard

2008-09-05 23:15 . 2008-09-05 23:16 <DIR> d-------- C:\Program Files\AGEIA Technologies

2008-09-05 22:06 . 2008-05-03 05:46 313,888 --a------ C:\Windows\System32\nvexpbar.dll

2008-09-05 20:33 . 2008-08-15 23:22 1,108,512 --a------ C:\Windows\System32\nvcpluir.dll

2008-09-05 20:33 . 2008-08-15 23:22 797,216 --a------ C:\Windows\System32\nvcplui.exe

2008-09-05 20:33 . 2008-08-15 23:22 420,384 --a------ C:\Windows\System32\nvcpl.cpl

2008-09-05 20:11 . 2008-09-05 20:11 <DIR> d-------- C:\Program Files\NVIDIA

2008-09-04 20:51 . 2008-09-12 21:39 <DIR> d-------- C:\Users\Tangemo\AppData\Roaming\Apple Computer

2008-09-04 20:48 . 2008-09-04 20:50 <DIR> d-------- C:\Users\All Users\Apple Computer

2008-09-04 20:48 . 2008-09-04 20:50 <DIR> d-------- C:\ProgramData\Apple Computer

2008-09-04 20:46 . 2008-09-04 20:46 <DIR> d-------- C:\Users\All Users\Apple

2008-09-04 20:46 . 2008-09-04 20:46 <DIR> d-------- C:\ProgramData\Apple

2008-09-04 20:46 . 2008-09-12 21:22 <DIR> d-------- C:\Program Files\Common Files\Apple

2008-09-04 20:30 . 2008-09-04 21:22 <DIR> d-------- C:\Program Files\The GodFather

2008-09-04 19:32 . 2008-09-18 19:59 <DIR> d-------- C:\Temp

2008-09-04 19:31 . 2008-09-04 19:51 <DIR> d-------- C:\Users\All Users\RoboForm

2008-09-04 19:31 . 2008-09-04 19:51 <DIR> d-------- C:\ProgramData\RoboForm

2008-09-03 23:41 . 2008-07-19 07:09 1,811,656 --a------ C:\Windows\System32\wuaueng.dll

2008-09-03 23:41 . 2008-07-19 05:44 1,524,736 --a------ C:\Windows\System32\wucltux.dll

2008-09-03 23:41 . 2008-07-19 07:09 563,912 --a------ C:\Windows\System32\wuapi.dll

2008-09-03 23:41 . 2008-07-18 22:08 163,904 --a------ C:\Windows\System32\wuwebv.dll

2008-09-03 23:41 . 2008-07-19 05:44 83,456 --a------ C:\Windows\System32\wudriver.dll

2008-09-03 23:41 . 2008-07-19 07:10 53,448 --a------ C:\Windows\System32\wuauclt.exe

2008-09-03 23:41 . 2008-07-19 07:10 45,768 --a------ C:\Windows\System32\wups2.dll

 

.

(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-09-18 20:27 --------- d--h--w C:\Program Files\InstallShield Installation Information

2008-09-17 16:57 --------- d-----w C:\Program Files\Java

2008-09-11 16:52 --------- d-----w C:\Program Files\Microsoft Works

2008-09-10 20:55 --------- d-----w C:\Users\Tangemo\AppData\Roaming\vlc

2008-09-08 16:09 --------- d-----w C:\ProgramData\Sonic

2008-09-07 15:39 --------- d-----w C:\ProgramData\NVIDIA

2008-09-07 10:22 --------- d-----w C:\Program Files\Roxio

2008-09-06 12:22 65,536 ----a-w C:\Windows\System32\sugs1ci.dll

2008-09-06 12:22 151,552 ----a-w C:\Windows\System32\sugs1ci.exe

2008-09-06 01:22 174 --sha-w C:\Program Files\desktop.ini

2008-09-06 01:12 --------- d-----w C:\Program Files\Windows Sidebar

2008-09-06 01:12 --------- d-----w C:\Program Files\Windows Photo Gallery

2008-09-06 01:12 --------- d-----w C:\Program Files\Windows Mail

2008-09-06 01:12 --------- d-----w C:\Program Files\Windows Journal

2008-09-06 01:12 --------- d-----w C:\Program Files\Windows Defender

2008-09-06 01:12 --------- d-----w C:\Program Files\Windows Collaboration

2008-09-06 01:12 --------- d-----w C:\Program Files\Windows Calendar

2008-09-06 00:45 82,432 ----a-w C:\Windows\System32\axaltocm.dll

2008-09-06 00:45 101,888 ----a-w C:\Windows\System32\ifxcardm.dll

2008-09-03 21:22 --------- d-----w C:\Program Files\MSBuild

2008-09-02 19:29 --------- d-----w C:\Program Files\Common Files\PX Storage Engine

2008-09-01 17:48 --------- d-----w C:\Program Files\HP

2008-08-24 09:00 --------- d-----w C:\Program Files\Google

2008-08-24 08:38 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll

2008-08-24 07:43 --------- d-sh--w C:\ProgramData\Vorlagen

2008-08-24 07:43 --------- d-sh--w C:\ProgramData\Startmenü

2008-08-24 07:43 --------- d-sh--w C:\ProgramData\Favoriten

2008-08-24 07:43 --------- d-sh--w C:\ProgramData\Dokumente

2008-08-24 07:43 --------- d-sh--w C:\ProgramData\Anwendungsdaten

2008-08-24 07:43 --------- d-sh--w C:\Program Files\Gemeinsame Dateien

2008-08-01 09:05 70,936 ----a-w C:\Windows\System32\PhysXLoader.dll

2008-07-31 03:32 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll

2008-07-31 03:32 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll

2008-07-31 03:32 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll

2008-07-22 18:32 32,000 ----a-w C:\Windows\system32\drivers\usbaapl.sys

2008-07-18 18:39 586,752 ----a-w C:\Windows\WLXPGSS.SCR

2008-07-09 03:05 129,520 ------w C:\Windows\System32\PxAFS.DLL

2008-07-09 03:05 120,568 ------w C:\Windows\System32\pxcpyi64.exe

2008-07-09 03:05 118,256 ------w C:\Windows\System32\pxinsi64.exe

2008-02-07 19:46 13,624 ----a-w C:\Program Files\mozilla firefox\plugins\cgpcfg.dll

2008-02-07 19:46 87,360 ----a-w C:\Program Files\mozilla firefox\plugins\CgpCore.dll

2008-02-07 19:46 91,448 ----a-w C:\Program Files\mozilla firefox\plugins\confmgr.dll

2008-02-07 19:46 21,824 ----a-w C:\Program Files\mozilla firefox\plugins\ctxlogging.dll

2008-02-07 19:46 206,136 ----a-w C:\Program Files\mozilla firefox\plugins\ctxmui.dll

2008-02-07 19:46 31,544 ----a-w C:\Program Files\mozilla firefox\plugins\icafile.dll

2008-02-07 19:46 40,248 ----a-w C:\Program Files\mozilla firefox\plugins\icalogon.dll

2007-03-16 15:27 479,232 ----a-w C:\Program Files\mozilla firefox\plugins\msvcm80.dll

2007-03-16 15:27 548,864 ----a-w C:\Program Files\mozilla firefox\plugins\msvcp80.dll

2007-03-16 15:27 626,688 ----a-w C:\Program Files\mozilla firefox\plugins\msvcr80.dll

2007-07-20 10:47 981,170 ----a-w C:\Program Files\mozilla firefox\plugins\sslsdk_b.dll

2008-02-07 19:46 24,384 ----a-w C:\Program Files\mozilla firefox\plugins\TcpPServ.dll

.

 

((((((((((((((((((((((((((((( snapshot_2008-09-17_22.51.17.61 )))))))))))))))))))))))))))))))))))))))))

.

- 2008-09-07 15:34:14 51,200 ----a-w C:\Windows\inf\infpub.dat

+ 2008-09-18 20:29:38 51,200 ----a-w C:\Windows\inf\infpub.dat

- 2008-09-07 15:34:13 86,016 ----a-w C:\Windows\inf\infstor.dat

+ 2008-09-18 20:29:38 86,016 ----a-w C:\Windows\inf\infstor.dat

- 2008-09-07 15:34:14 143,360 ----a-w C:\Windows\inf\infstrng.dat

+ 2008-09-18 20:29:38 143,360 ----a-w C:\Windows\inf\infstrng.dat

+ 2008-09-18 20:29:28 10,134 ----a-r C:\Windows\Installer\{0C826C5B-B131-423A-A229-C71B3CACCD6A}\ARPPRODUCTICON.exe

+ 2008-09-18 20:27:19 10,134 ----a-r C:\Windows\Installer\{3101CB58-3482-4D21-AF1A-7057FC935355}\ARPPRODUCTICON.exe

+ 2008-02-29 01:12:38 76,304 ----a-w C:\Windows\KHALMNPR.Exe

- 2008-09-17 20:38:29 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2008-09-19 15:53:51 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2008-09-17 20:38:29 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2008-09-19 15:53:51 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

- 2008-09-17 20:39:14 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT

+ 2008-09-19 15:55:19 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT

+ 2008-09-19 15:55:19 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1

- 2008-09-17 20:39:53 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT

+ 2008-09-19 16:19:12 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT

+ 2008-09-19 16:19:12 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1

- 2008-08-24 07:42:51 87,640 ----a-w C:\Windows\System32\config\systemprofile\AppData\Local\GDIPFONTCACHEV1.DAT

+ 2008-09-19 16:19:59 123,696 ----a-w C:\Windows\System32\config\systemprofile\AppData\Local\GDIPFONTCACHEV1.DAT

+ 2008-02-29 01:13:16 35,344 ----a-w C:\Windows\System32\drivers\LHidFilt.Sys

+ 2008-02-29 01:13:24 36,880 ----a-w C:\Windows\System32\drivers\LMouFilt.Sys

+ 2008-02-29 01:13:46 28,944 ----a-w C:\Windows\System32\drivers\LUsbFilt.sys

+ 2007-01-03 15:25:18 27,536 ----a-w C:\Windows\System32\DriverStore\FileRepository\frmupgr.inf_7b6176c6\frmupgr.sys

+ 2007-12-14 14:13:24 53,248 ----a-w C:\Windows\System32\DriverStore\FileRepository\lbtcoins.inf_62a837b6\LBTCoIns.DLL

+ 2008-02-29 01:13:16 35,344 ----a-w C:\Windows\System32\DriverStore\FileRepository\lfhidhid.inf_7ed4c2ab\LHidFilt.Sys

+ 2007-06-22 10:34:02 1,419,232 ----a-w C:\Windows\System32\DriverStore\FileRepository\lfhidhid.inf_7ed4c2ab\WdfCoInstaller01005.dll

+ 2008-02-29 01:13:46 28,944 ----a-w C:\Windows\System32\DriverStore\FileRepository\lfhidusb.inf_90b730bc\LUsbFilt.sys

+ 2007-06-22 10:34:02 1,419,232 ----a-w C:\Windows\System32\DriverStore\FileRepository\lfhidusb.inf_90b730bc\WdfCoInstaller01005.dll

+ 2008-02-29 01:13:16 35,344 ----a-w C:\Windows\System32\DriverStore\FileRepository\lfkbdhid.inf_0a27b118\LHidFilt.Sys

+ 2007-06-22 10:34:02 1,419,232 ----a-w C:\Windows\System32\DriverStore\FileRepository\lfkbdhid.inf_0a27b118\WdfCoInstaller01005.dll

+ 2008-02-29 01:12:38 76,304 ----a-w C:\Windows\System32\DriverStore\FileRepository\lfmouhid.inf_d39a75a3\KHALMNPR.Exe

+ 2008-02-29 01:13:16 35,344 ----a-w C:\Windows\System32\DriverStore\FileRepository\lfmouhid.inf_d39a75a3\LHidFilt.Sys

+ 2008-02-29 01:13:24 36,880 ----a-w C:\Windows\System32\DriverStore\FileRepository\lfmouhid.inf_d39a75a3\LMouFilt.Sys

+ 2007-06-22 10:34:02 1,419,232 ----a-w C:\Windows\System32\DriverStore\FileRepository\lfmouhid.inf_d39a75a3\WdfCoInstaller01005.dll

+ 2008-02-29 01:12:48 20,240 ----a-w C:\Windows\System32\DriverStore\FileRepository\lkbdps2k.inf_62e2e933\L8042Kbd.sys

+ 2008-02-29 01:12:38 76,304 ----a-w C:\Windows\System32\DriverStore\FileRepository\lmoups2k.inf_d8a49505\KHALMNPR.Exe

+ 2008-02-29 01:12:56 63,120 ----a-w C:\Windows\System32\DriverStore\FileRepository\lmoups2k.inf_d8a49505\L8042mou.Sys

+ 2008-02-29 01:13:36 79,120 ----a-w C:\Windows\System32\DriverStore\FileRepository\lmoups2k.inf_d8a49505\LMouKE.Sys

- 2008-09-12 17:51:31 122,018 ----a-w C:\Windows\System32\perfc007.dat

+ 2008-09-18 19:59:01 122,018 ----a-w C:\Windows\System32\perfc007.dat

- 2008-09-12 17:51:31 101,052 ----a-w C:\Windows\System32\perfc009.dat

+ 2008-09-18 19:59:01 101,052 ----a-w C:\Windows\System32\perfc009.dat

- 2008-09-12 17:51:31 607,544 ----a-w C:\Windows\System32\perfh007.dat

+ 2008-09-18 19:59:01 607,544 ----a-w C:\Windows\System32\perfh007.dat

- 2008-09-12 17:51:31 586,980 ----a-w C:\Windows\System32\perfh009.dat

+ 2008-09-18 19:59:01 586,980 ----a-w C:\Windows\System32\perfh009.dat

+ 2007-06-22 10:34:02 1,419,232 ----a-w C:\Windows\System32\WdfCoInstaller01005.dll

- 2008-09-17 20:40:14 7,830 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1997900430-2287122297-485223492-1001_UserData.bin

+ 2008-09-19 15:56:08 7,838 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1997900430-2287122297-485223492-1001_UserData.bin

- 2008-09-17 20:40:14 64,002 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin

+ 2008-09-19 15:56:08 64,388 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin

- 2008-09-17 20:40:10 46,072 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2008-09-19 15:56:07 46,924 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin

.

.

(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))

.

.

*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]

"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 125952]

"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]

"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [2008-09-03 267056]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CCUTRAYICON"="FactoryMode" [X]

"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]

"KBD"="C:\HP\KBD\KbdStub.EXE" [2006-12-08 65536]

"OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]

"HP Health Check Scheduler"="c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-05-24 71176]

"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]

"SunJavaUpdateReg"="C:\Windows\system32\jureg.exe" [2008-06-10 54672]

"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]

"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]

"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-06-10 1447168]

"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-08-15 13576736]

"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-08-15 92704]

"MagicRotation"="C:\Program Files\MagicRotation\MagicPvt.exe" [2007-08-01 2572410]

"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]

"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]

"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-10 289576]

"MagicTuneEngine"="C:\Program Files\MagicTune Premium\MagicTuneEngine.exe" [2008-08-05 69632]

"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]

"RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 C:\Windows\RtHDVCpl.exe]

"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 C:\Windows\KHALMNPR.Exe]

 

C:\Users\Tangemo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartupBUFFALO NAS Navigator.lnk - C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe [2007-05-11 1070648]

Sk„rmurklipp och start f”r OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]

 

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartupLogitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-09-18 805392]

Personal.lnk - C:\Program Files\Personal\bin\Personal.exe [2008-08-29 910864]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableUIADesktopToggle"= 0 (0x0)

 

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GammaTray.lnk]

path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GammaTray.lnk

backup=C:\Windows\pss\GammaTray.lnk.CommonStartup

backupExtension=.CommonStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MagicTuneEngine]

--a------ 2008-08-05 03:42 69632 C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"UacDisableNotify"=dword:00000001

"InternetSettingsDisableNotify"=dword:00000001

"AutoUpdateDisableNotify"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{1CA32AD2-4EEB-4DA7-A9DF-E3E61BA3A5F4}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM

"{63C6B2CA-BA49-471D-945A-8674446304B8}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM

"{C69AD56D-94B9-473E-9FD2-25C57F5D91EF}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv Media Server

"{2B53614B-68D7-4679-AB96-7D068765ED7B}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv Media Server

"{E89BC0FB-7491-4272-B575-6B0F18FC60B0}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service

"{808F38D9-0B42-480A-A3B3-104C491FFC4E}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service

"{D9C14108-24FB-4F3A-A4C2-C25EA317FAFE}"= TCP:9442:127.0.0.1:Intel® Viiv Media Server Discovery

"{60D7B77D-8F66-418D-86A6-B3CAE8C7B4DB}"= TCP:1900:LocalSubnet:LocalSubnet:Intel® Viiv Media Server UPnP Discovery

"{34456AA8-885F-4402-8FDC-8EEAD919BA36}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

"{AFE2C24B-F377-4222-8395-201B77B37026}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (TCP-In)

"{21553A70-2072-4A7A-B49D-0FBDF57822B7}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (UDP-In)

"{104157BD-6511-440F-969B-DADCBD7DD19F}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook

"{0310470A-21F5-4F63-98D3-8B403A83B13E}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove

"{AEC4103E-4B3D-47AC-9916-FB80A964CC24}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove

"{33F701C6-CD2E-4CC0-930B-9FBCCA3AF0BC}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote

"{9FD332A1-E2D7-4739-8E27-2F1001621A24}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote

"TCP Query User{46C4FFEC-6DF3-4C3D-9ADB-DCEB68179216}C:\\program files\\skype\\phone\\skype.exe"= UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath

"UDP Query User{78ACFFB9-F195-4346-A8D6-8DB1C0B54566}C:\\program files\\skype\\phone\\skype.exe"= TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath

"{A9189C8B-A74D-42BA-86D4-C789312B0CF2}"= C:\Program Files\Skype\Phone\Skype.exe:Skype

"TCP Query User{E83AD50C-FE18-435C-9E58-7D4DB2E018CD}C:\\program files\\magictune premium\\magictune.exe"= UDP:C:\program files\magictune premium\magictune.exe:MagicTune

"UDP Query User{16D3F237-9EBD-4D38-9522-88D70A37E7F9}C:\\program files\\magictune premium\\magictune.exe"= TCP:C:\program files\magictune premium\magictune.exe:MagicTune

"{1501D97F-4171-4D6D-AF58-589234502B6A}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour

"{3B531429-BCB1-4A57-96C4-2A965673133B}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour

"{AA23DB46-B3DE-48A7-90B1-CF4F9DB2C805}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes

"{9A6C4C4D-BE3E-45FF-BB2A-44064D19E417}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes

"TCP Query User{B5F2187C-3744-4B5C-A154-43ADB67B857E}C:\\program files\\totalcmd\\totalcmd.exe"= UDP:C:\program files\totalcmd\totalcmd.exe:Total Commander 32 bit international version, file manager replacement for Windows

"UDP Query User{3C19E335-400D-4BA9-9411-3BBE350D6940}C:\\program files\\totalcmd\\totalcmd.exe"= TCP:C:\program files\totalcmd\totalcmd.exe:Total Commander 32 bit international version, file manager replacement for Windows

"TCP Query User{B79E5A7A-1970-40AD-B0DC-2ABBAF7892CB}C:\\program files\\allway sync\\bin\\syncappw.exe"= UDP:C:\program files\allway sync\bin\syncappw.exe:syncappw

"UDP Query User{58BF8E92-704A-4D49-BF98-49195EA3C017}C:\\program files\\allway sync\\bin\\syncappw.exe"= TCP:C:\program files\allway sync\bin\syncappw.exe:syncappw

"{81860274-0DB0-45B1-9C1B-A2AED1EAE96C}"= UDP:C:\Users\Tangemo\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool

"{DC2A8279-EDB6-49B2-98CF-EE4412DA95DE}"= TCP:C:\Users\Tangemo\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]

"EnableFirewall"= 0 (0x0)

 

R1 epfwtdir;epfwtdir;C:\Windows\system32\DRIVERS\epfwtdir.sys [2008-06-10 34312]

R1 magicpvt;magicpvt;C:\Windows\system32\drivers\magicpvt.sys [2006-12-04 26240]

R2 DQLWinService;DQLWinService;C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2006-09-03 208896]

R2 HPBtnSrv;HP Chasis Button Service;c:\hp\HPEZBTN\HPBtnSrv.exe [2007-05-29 198240]

R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;C:\Windows\system32\drivers\HCW85BDA.sys [2007-06-11 968064]

R3 PID_0920;Logitech QuickCam Express(PID_0920);C:\Windows\system32\DRIVERS\LV532AV.SYS [2005-01-31 163328]

S2 IntelDHSvcConf;Intel DH Service;C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe [2006-05-10 29696]

S2 NOD32FiXTemDono;Eset Nod32 Boot;C:\Windows\system32\regedt32.exe [2006-11-02 9216]

S3 netr73;USB Wireless 802.11 b/g Adaptor Driver for Vista;C:\Windows\system32\DRIVERS\netr73.sys [2007-04-20 265216]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]

\shell\AutoRun\command - E:\monsetup.exe

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{581079a0-7dc3-11dd-8fe3-001d60e0fc4f}]

\shell\AutoRun\command - F:\Install.exe

.

Inhalt des "geplante Tasks" Ordners

.

.

------- Zusätzlicher Suchlauf -------

.

FireFox -: Profile - C:\Users\Tangemo\AppData\Roaming\Mozilla\Firefox\Profiles\60vz7hqr.defaultFireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.gp.se/

FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll

FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npicaN.dll

FF -: plugin - C:\Program Files\Personal\bin\np_prsnl.dll

FF -: plugin - C:\Program Files\Picasa2\npPicasa2.dll

.

 

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-09-19 18:52:19

Windows 6.0.6001 Service Pack 1 NTFS

 

Scanne versteckte Prozesse...

 

Scanne versteckte Autostarteinträge...

 

Scanne versteckte Dateien...

 

Scan erfolgreich abgeschlossen

versteckte Dateien: 0

 

**************************************************************************

.

Zeit der Fertigstellung: 2008-09-19 18:56:22

ComboFix-quarantined-files.txt 2008-09-19 16:55:39

ComboFix2.txt 2008-09-18 17:56:37

ComboFix3.txt 2008-09-17 20:52:31

ComboFix4.txt 2008-09-08 21:52:10

ComboFix5.txt 2008-09-19 16:50:05

 

Vor Suchlauf: 9 Verzeichnis(se), 119,742,918,656 Bytes frei

Nach Suchlauf: 19 Verzeichnis(se), 119,747,366,912 Bytes frei

 

380 --- E O F --- 2008-09-18 16:55:02[/log]

;);)

 

Länk till kommentar
Dela på andra webbplatser

Arkiverat

Det här ämnet är nu arkiverat och är stängt för ytterligare svar.

×
×
  • Skapa nytt...