Just nu i M3-nätverket
Gå till innehåll

jag har fått ett konstigt virus som har förstört min säkerhetcenter..


JohnyNguyen

Rekommendera Poster

[log]

ComboFix 09-02-21.01 - Acer 2009-02-23 18:50:20.2 - FAT32x86

Microsoft Windows XP Professional 5.1.2600.3.1252.46.1033.18.894.528 [GMT 1:00]

Körs från: c:\documents and settings\Acer\Desktop\ComboFix.exe

Använda kommandoväxlar :: c:\documents and settings\Acer\Desktop\CFScript.txt

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)

* Skapade en ny återställningspunkt

 

FILE ::

c:\windows\system32\drivers\senekarnmwjvlj.sys

c:\windows\system32\mymampyt.tmp

c:\windows\system32\senekaeaavfyqv.dat

.

 

((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\windows\system32\mymampyt.tmp

 

.

(((((((((((((((((((((((( Filer Skapade från 2009-01-23 till 2009-02-23 ))))))))))))))))))))))))))))))

.

 

2009-02-22 19:35 . 2009-02-22 19:35 <DIR> d-------- C:\VundoFix Backups

2009-02-22 19:33 . 2009-02-22 19:33 <DIR> d-------- c:\documents and settings\Acer\Application Data\AVG8

2009-02-21 18:52 . 2009-02-21 18:53 <DIR> d-------- c:\program files\Common Files\Adobe

2009-02-21 18:39 . 2009-02-21 18:39 <DIR> d-------- c:\program files\NOS

2009-02-21 18:39 . 2009-02-21 18:39 <DIR> d-------- c:\documents and settings\All Users\Application Data\NOS

2009-02-21 09:58 . 2009-02-21 09:58 <DIR> d-------- c:\documents and settings\All Users\Application Data\TEMP

2009-02-20 21:47 . 2009-02-20 21:47 <DIR> d--h----- C:\$AVG8.VAULT$

2009-02-20 21:46 . 2009-02-20 21:46 325,128 --a------ c:\windows\system32\drivers\avgldx86.sys

2009-02-20 21:46 . 2009-02-20 21:46 107,272 --a------ c:\windows\system32\drivers\avgtdix.sys

2009-02-20 21:46 . 2009-02-20 21:46 10,520 --a------ c:\windows\system32\avgrsstx.dll

2009-02-20 21:45 . 2009-02-20 21:45 <DIR> d-------- c:\windows\system32\drivers\Avg

2009-02-20 21:45 . 2009-02-20 21:45 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8

2009-02-20 21:45 . 2009-02-20 21:45 <DIR> d-------- c:\documents and settings\Acer\Application Data\AVGTOOLBAR

2009-02-20 21:43 . 2009-02-20 21:43 <DIR> d-------- C:\ProgramData

2009-02-20 21:43 . 2009-02-20 21:43 <DIR> d-------- c:\program files\Angle Interactive

2009-02-12 20:53 . 2009-02-12 20:53 <DIR> d-------- c:\program files\DVDVideoSoft

2009-02-12 20:53 . 2009-02-12 20:53 <DIR> d-------- c:\program files\Common Files\DVDVideoSoft

2009-02-08 12:59 . 2009-02-08 12:59 <DIR> d-------- c:\program files\MSN Messenger

2009-02-08 12:58 . 2009-02-08 12:58 <DIR> d-------- c:\program files\iTunes

2009-02-08 12:58 . 2009-02-08 12:58 <DIR> d-------- c:\program files\iPod

2009-02-08 12:58 . 2009-02-08 12:58 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

2009-02-08 12:58 . 2008-04-17 13:12 107,368 --a------ c:\windows\system32\GEARAspi.dll

2009-02-08 12:58 . 2008-04-17 13:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys

2009-02-08 12:57 . 2009-02-08 12:57 <DIR> d-------- c:\program files\QuickTime

2009-02-01 22:43 . 2009-02-01 22:43 <DIR> d-------- c:\program files\Vodei

2009-02-01 11:32 . 2009-02-01 11:32 <DIR> d-------- c:\windows\system32\XPSViewer

2009-02-01 11:32 . 2009-02-01 11:32 <DIR> d-------- c:\program files\Reference Assemblies

2009-02-01 11:31 . 2009-02-01 11:31 <DIR> d-------- c:\windows\SxsCaPendDel

2009-02-01 11:31 . 2008-07-06 13:06 1,676,288 --------- c:\windows\system32\xpssvcs.dll

2009-02-01 11:31 . 2008-07-06 13:06 1,676,288 --------- c:\windows\system32\dllcache\xpssvcs.dll

2009-02-01 11:31 . 2008-07-06 11:50 597,504 --------- c:\windows\system32\dllcache\printfilterpipelinesvc.exe

2009-02-01 11:31 . 2008-07-06 13:06 575,488 --------- c:\windows\system32\xpsshhdr.dll

2009-02-01 11:31 . 2008-07-06 13:06 575,488 --------- c:\windows\system32\dllcache\xpsshhdr.dll

2009-02-01 11:31 . 2008-07-06 13:06 117,760 --------- c:\windows\system32\prntvpt.dll

2009-02-01 11:31 . 2008-07-06 13:06 89,088 --------- c:\windows\system32\dllcache\filterpipelineprintproc.dll

2009-02-01 11:27 . 2009-02-01 11:27 <DIR> d-------- c:\program files\Microsoft CAPICOM 2.1.0.2

2009-01-31 22:09 . 2009-01-31 22:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\Birdstep Technology

2009-01-31 22:09 . 2009-01-31 22:09 <DIR> d-------- c:\documents and settings\Acer\Application Data\Birdstep Technology

2009-01-31 22:09 . 2007-05-28 17:00 10,240 --------- c:\windows\system32\drivers\mdvrmng.sys

2009-01-31 22:08 . 2009-01-31 22:08 <DIR> d-------- c:\program files\Huawei Modems

2009-01-31 22:08 . 2009-01-31 22:08 <DIR> d-------- c:\program files\3

2009-01-31 22:08 . 2007-08-08 11:12 101,120 --a------ c:\windows\system32\drivers\ewusbmdm.sys

2009-01-31 22:08 . 2009-01-31 22:08 69,361 --a------ c:\windows\Huawei ModemsUninstall.exe

2009-01-31 22:08 . 2004-08-10 20:00 31,616 --a------ c:\windows\system32\drivers\usbccgp.sys

2009-01-31 22:08 . 2004-08-10 20:00 31,616 --a------ c:\windows\system32\dllcache\usbccgp.sys

2009-01-31 22:08 . 2007-08-08 11:13 24,448 --a------ c:\windows\system32\drivers\ewdcsc.sys

2009-01-30 23:57 . 2009-01-30 23:57 268 --ah----- C:\sqmdata00.sqm

2009-01-30 23:57 . 2009-01-30 23:57 244 --ah----- C:\sqmnoopt00.sqm

2009-01-30 23:43 . 2009-01-30 23:43 <DIR> d-------- c:\program files\Bonjour

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-02-22 20:42 410,984 ----a-w c:\windows\system32\deploytk.dll

2009-02-11 09:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys

2009-02-11 09:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys

2009-02-01 21:43 --------- d-----w c:\program files\Vodei

2009-01-26 12:49 34 ----a-w c:\documents and settings\Acer\jagex_runescape_preferences.dat

2009-01-16 20:35 3,594,752 ------w c:\windows\system32\dllcache\mshtml.dll

2009-01-13 11:55 --------- d-----w c:\documents and settings\All Users\Application Data\AVS4YOU

2009-01-13 11:55 --------- d-----w c:\documents and settings\Acer\Application Data\AVS4YOU

2009-01-13 11:54 --------- d-----w c:\program files\Common Files\AVSMedia

2009-01-13 11:54 --------- d-----w c:\program files\AVS4YOU

2009-01-05 13:43 --------- d-----w c:\program files\Common Files\DirectX

2009-01-05 13:23 --------- d-----w c:\program files\Gamigo Games

2008-12-19 09:10 70,656 ------w c:\windows\system32\dllcache\ie4uinit.exe

2008-12-19 09:10 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe

2008-12-19 05:25 634,024 ------w c:\windows\system32\dllcache\iexplore.exe

2008-12-19 05:23 161,792 ------w c:\windows\system32\dllcache\ieakui.dll

2008-12-12 10:18 87,336 ----a-w c:\windows\system32\dns-sd.exe

2008-12-12 10:11 61,440 ----a-w c:\windows\system32\dnssd.dll

2008-12-11 10:57 333,952 ------w c:\windows\system32\dllcache\srv.sys

2008-09-11 05:53 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008091120080912\index.dat

.

 

((((((((((((((((((((((((((((( SnapShot@2009-02-22_22.36.30.32 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-02-23 17:06:10 16,384 ----a-w c:\windows\TEMP\Perflib_Perfdata_200.dat

+ 2009-02-23 17:06:08 16,384 ----a-w c:\windows\TEMP\Perflib_Perfdata_7cc.dat

+ 2009-02-23 17:25:14 16,384 ----a-w c:\windows\TEMP\Perflib_Perfdata_dcc.dat

.

(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Not* Tomma poster & legitima standardposter visas inte.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-07-02 393216]

"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-30 4670704]

"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]

"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2006-04-14 53248]

"ntiMUI"="c:\program files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 45056]

"Acer ePresentation HPD"="c:\acer\Empowering Technology\ePresentation\ePresentation.exe" [2006-03-31 204800]

"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]

"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 59392]

"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]

"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]

"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]

"ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-05-30 421888]

"Boot"="c:\acer\Empowering Technology\ePower\Boot.exe" [2006-03-15 579584]

"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 761946]

"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2006-06-23 602112]

"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2006-06-01 413696]

"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]

"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-02-06 177472]

"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-04-17 98616]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]

"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-20 1601304]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-22 148888]

"RTHDCPL"="RTHDCPL.EXE" [2006-05-17 c:\windows\RTHDCPL.exe]

"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

 

c:\documents and settings\Acer\Start Menu\Programs\StartupLimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2007-01-29 122880]

 

c:\documents and settings\All Users\Start Menu\Programs\StartupAcer Empowering Technology.lnk - c:\acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2006-03-27 45056]

PHOTOfunSTUDIO -viewer-.lnk - c:\program files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe [2008-11-29 40960]

Uppdateringsagent.lnk - c:\program files\3\3Connect\AutoUpdateSrv.exe [2008-10-23 442368]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]

2009-02-20 21:46 10520 c:\windows\system32\avgrsstx.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

"AntiVirusOverride"=dword:00000001

"FirewallOverride"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\BitComet\\BitComet.exe"=

"c:\\Program Files\\LimeWire\\LimeWire.exe"=

"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\groove.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Messenger\\MSMSGS.EXE"=

"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\English\\setup.exe"=

"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=

"c:\\WINDOWS\\PCHEALTH\\HELPCTR\\BINARIES\\HelpCtr.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=

"c:\\Program Files\\MSN Messenger\\livecall.exe"=

"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"10042:TCP"= 10042:TCP:BitComet 10042 TCP

"10042:UDP"= 10042:UDP:BitComet 10042 UDP

 

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-02-20 325128]

R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-02-20 107272]

R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-20 298264]

R2 mdvrmng;Mobile IP Route Manager;c:\windows\system32\drivers\mdvrmng.sys [2009-01-31 10240]

S2 eLock2BurnerLockDriver;eLock2BurnerLockDriver;\??\c:\windows\system32\eLock2BurnerLockDriver.sys --> c:\windows\system32\eLock2BurnerLockDriver.sys [?]

S2 eLock2FSCTLDriver;eLock2FSCTLDriver;\??\c:\windows\system32\eLock2FSCTLDriver.sys --> c:\windows\system32\eLock2FSCTLDriver.sys [?]

S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2009-02-21 33752]

S3 NTProcDrv;Process creation detector for NT.;\??\c:\documents and settings\Acer\Desktop\RohanBotEn1.0.12\NtProcDrv.sys --> c:\documents and settings\Acer\Desktop\RohanBotEn1.0.12\NtProcDrv.sys [?]

S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\drivers\s115bus.sys [2007-04-23 83208]

S3 s3017bus;Sony Ericsson Device 3017 driver (WDM);c:\windows\system32\drivers\s3017bus.sys [2008-08-12 83880]

S3 s3017mdfl;Sony Ericsson Device 3017 USB WMC Modem Filter;c:\windows\system32\drivers\s3017mdfl.sys [2008-08-12 15016]

S3 s3017mdm;Sony Ericsson Device 3017 USB WMC Modem Driver;c:\windows\system32\drivers\s3017mdm.sys [2008-08-12 110632]

S3 s3017mgmt;Sony Ericsson Device 3017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s3017mgmt.sys [2008-08-12 104616]

S3 s3017nd5;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (NDIS);c:\windows\system32\drivers\s3017nd5.sys [2008-08-12 25512]

S3 s3017obex;Sony Ericsson Device 3017 USB WMC OBEX Interface;c:\windows\system32\drivers\s3017obex.sys [2008-08-12 100648]

S3 s3017unic;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (WDM);c:\windows\system32\drivers\s3017unic.sys [2008-08-12 110120]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2c21f1a2-efdb-11dd-8910-0016d4169248}]

\Shell\AutoRun\command - F:\AutoRun.exe

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2c21f1a3-efdb-11dd-8910-0016d4169248}]

\Shell\AutoRun\command - F:\AutoRun.exe

.

Innehållet i mappen 'Schemalagda aktiviteter':

 

2009-02-13 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

.

.

------- Extra genomsökning -------

.

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

mStart Page = hxxp://www.yahoo.com/

mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html

uInternet Connection Wizard,ShellNext = hxxp://www.aceradvantage.com/stdreg

uInternet Settings,ProxyOverride = *.local

uSearchURL,(Default) = hxxp://g.msn.se/0SESVSE/SAOS01?FORM=TOOLBR

IE: Download all links using BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm

IE: Download all videos using BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm

IE: Download link using &BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

FF - ProfilePath - c:\documents and settings\Acer\Application Data\Mozilla\Firefox\Profiles\d0nw8raf.defaultFF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=

FF - prefs.js: browser.search.selectedEngine - Ask

FF - prefs.js: browser.startup.homepage - www.google.se

FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q=

FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll

FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

 

---- FIREFOX POLICY ----

c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-02-23 18:53:21

Windows 5.1.2600 Service Pack 3 FAT NTAPI

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

--------------------- DLLer som "laddats" under processer som körs ---------------------

 

- - - - - - - > 'winlogon.exe'(732)

c:\windows\system32\Ati2evxx.dll

.

Sluttid: 2009-02-23 18:54:47

ComboFix-quarantined-files.txt 2009-02-23 17:54:46

ComboFix2.txt 2009-02-22 21:37:30

 

Före genomsökningen: 7 230 554 112 bytes free

Efter genomsökningen: 7,228,489,728 byte ledigt

 

239 --- E O F --- 2009-02-12 11:24:20

[/log]

 

Länk till kommentar
Dela på andra webbplatser

Arkiverat

Det här ämnet är nu arkiverat och är stängt för ytterligare svar.

×
×
  • Skapa nytt...