Just nu i M3-nätverket
Gå till innehåll

Virus problem, kan ej surfa.


AstroCreep

Rekommendera Poster

Ah okay.

 

Nod32 är avinstallerat, körs Avast istället.

MBAM hittade nån trojan som den tog bort, men bror min han göra de utan min vetskap så har ingen log kvar, men verkar som att de är lite små dret kvar. Återkommer!

Länk till kommentar
Dela på andra webbplatser

  • Svars 110
  • Skapad
  • Senaste svar

Kolla på fliken Loggar i MBAM om inte loggen finns kvar där.

 

Har du sökt igenom datorn med Avast? Hittades något och i så fall vad?

Länk till kommentar
Dela på andra webbplatser

  • 2 veckor senare...

Sådär, tillbaka till verkligheten efter att ha varit bortrest ett tag.

Vi har nu skannat datorn med alla samma program igen.

Malaware har hittat en massa men det har tagits bort nu enligt programmet.

Men ändå nåt skit kvar som kopplar upp sig till vissa sidor av nån anledning, hoppar till vissa andra sidor (kommer upp som en ny flik hela tiden i Mozilla Firefox.

 

Här är lite loggar på programmen vi kört igen efter att kommit hem tillbaka;

 

Combofix igen;

 

ComboFix 10-08-02.03 - Anvädaren 2010-08-04 19:53:50.7.2 - x86

Microsoft Windows XP Home Edition 5.1.2600.3.1252.46.1053.18.2047.1649 [GMT 2:00]

Körs från: c:\documents and settings\Anvädaren\Mina dokument\Hämtade filer\ComboFix.exe

.

 

(((((((((((((((((((((((( Filer Skapade från 2010-07-04 till 2010-08-04 ))))))))))))))))))))))))))))))

.

 

2010-08-03 17:34 . 2010-08-03 17:34 16968 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys

2010-08-03 17:33 . 2010-08-03 17:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Hitman Pro

2010-08-03 17:33 . 2010-08-03 17:33 -------- d-----w- c:\program\Hitman Pro 3.5

2010-08-03 06:03 . 2010-08-03 06:03 664 ----a-w- c:\windows\system32\d3d9caps.dat

2010-08-02 14:53 . 2010-08-02 14:53 0 ----a-w- c:\windows\nsreg.dat

2010-08-02 06:31 . 2010-08-02 07:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy

2010-08-02 06:31 . 2010-08-02 06:37 -------- d-----w- c:\program\Spybot - Search & Destroy

2010-08-02 06:16 . 2010-08-02 06:16 -------- d-----w- c:\program\Delade filer\Java

2010-08-02 06:16 . 2010-07-17 03:00 423656 ----a-w- c:\windows\system32\deployJava1.dll

2010-08-01 15:48 . 2009-06-30 07:37 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys

2010-08-01 15:48 . 2010-08-01 15:48 -------- d-----w- c:\program\Panda Security

2010-07-29 12:03 . 2010-07-29 12:03 -------- d-----r- c:\documents and settings\NetworkService\Favoriter

2010-07-24 11:09 . 2010-07-12 08:56 2979280 -c--a-w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}\Ad-AwareInstall.exe

2010-07-24 11:01 . 2010-07-24 11:09 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}

2010-07-23 11:53 . 2010-07-23 11:53 -------- d-----w- c:\program\Alwil Software

2010-07-23 11:53 . 2010-07-23 11:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software

2010-07-21 16:58 . 2010-07-21 16:58 -------- d-----w- c:\windows\system32\wbem\Repository

2010-07-19 20:22 . 2010-07-12 08:55 15880 ----a-w- c:\windows\system32\lsdelete.exe

2010-07-19 19:41 . 2010-07-19 19:47 -------- d-----w- c:\windows\SxsCaPendDel

2010-07-19 19:16 . 2010-07-19 19:16 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-08-04 17:50 . 2009-12-09 19:31 -------- d-----w- c:\documents and settings\LocalService\Application Data\WTablet

2010-08-02 07:06 . 2009-11-18 12:17 67072 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT

2010-08-02 06:19 . 2009-11-03 19:43 -------- d-----w- c:\program\HP

2010-08-02 06:17 . 2009-11-03 19:51 -------- d-----w- c:\program\Delade filer\HP

2010-08-02 06:15 . 2009-10-26 08:11 -------- d-----w- c:\program\Java

2010-07-31 07:46 . 2009-10-30 09:38 -------- d-----w- c:\program\BitComet

2010-07-21 16:47 . 2010-07-21 16:55 214694 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Personal_32_1053.dat

2010-07-20 08:30 . 2009-12-31 16:55 -------- d-----w- c:\program\Malwarebytes' Anti-Malware

2010-07-20 04:41 . 2009-10-28 17:21 -------- d-----w- c:\program\Norman

2010-07-19 20:04 . 2009-10-31 07:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft

2010-07-12 08:55 . 2010-03-25 06:40 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys

2010-06-23 20:49 . 2008-04-15 12:00 92094 ----a-w- c:\windows\system32\perfc01D.dat

2010-06-23 20:49 . 2008-04-15 12:00 463742 ----a-w- c:\windows\system32\perfh01D.dat

2010-06-23 18:52 . 2009-12-02 19:07 -------- d-----w- c:\program\Tablet

2010-06-16 19:25 . 2010-06-16 19:25 -------- d-----w- c:\program\iTunes

2010-06-16 19:25 . 2010-06-16 19:25 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}

2010-06-16 19:25 . 2010-06-16 19:25 -------- d-----w- c:\program\iPod

2010-06-16 19:25 . 2009-10-31 08:10 -------- d-----w- c:\program\Delade filer\Apple

2010-06-16 19:23 . 2009-10-31 12:17 -------- d-----w- c:\program\QuickTime

2010-06-16 19:21 . 2010-06-16 19:21 -------- d-----w- c:\program\Bonjour

2010-06-16 19:16 . 2009-10-28 18:30 -------- d-----w- c:\program\VideoLAN

2010-06-16 19:16 . 2010-06-16 19:16 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe

2010-06-14 14:31 . 2009-10-22 12:23 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe

2010-05-23 06:12 . 2009-11-10 06:59 8 ----a-w- c:\windows\system32\nvModes.dat

.

 

((((((((((((((((((((((((((((( SnapShot@2010-07-20_11.40.15 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-07-11 22:02 . 2009-07-11 22:02 51008 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90rus.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90kor.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90jpn.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90ita.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90fra.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 61760 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esp.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esn.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 53568 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 63296 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90deu.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90cht.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 35648 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90chs.dll

+ 2009-07-11 22:05 . 2009-07-11 22:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll

+ 2009-07-11 22:05 . 2009-07-11 22:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll

+ 2010-08-04 17:50 . 2010-08-04 17:50 16384 c:\windows\temp\Perflib_Perfdata_770.dat

+ 2010-07-24 11:22 . 2010-07-12 08:55 64288 c:\windows\system32\DRVSTORE\lbd_9C578CA880A99903668A8694DEFB21244E9C4C62\Lbd.sys

+ 2009-07-11 22:02 . 2009-07-11 22:02 653120 begin_of_the_skype_highlighting              02 653120      end_of_the_skype_highlighting begin_of_the_skype_highlighting              02 653120      end_of_the_skype_highlighting c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll

+ 2009-07-11 22:05 . 2009-07-11 22:05 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll

+ 2009-11-13 14:56 . 2010-07-21 17:13 144476 c:\windows\system32\Restore\rstrlog.dat

+ 2010-07-24 05:44 . 2010-07-24 05:44 231888 c:\windows\system32\Macromed\Flash\FlashUtil10h_Plugin.exe

+ 2010-08-02 06:16 . 2010-07-17 03:00 153376 c:\windows\system32\javaws.exe

- 2009-10-26 08:38 . 2009-07-25 04:23 145184 c:\windows\system32\javaw.exe

+ 2010-08-02 06:16 . 2010-07-17 03:00 145184 c:\windows\system32\javaw.exe

+ 2010-08-02 06:15 . 2010-07-17 03:00 145184 c:\windows\system32\java.exe

- 2009-10-26 08:38 . 2009-07-25 04:23 145184 c:\windows\system32\java.exe

+ 2010-07-23 11:53 . 2010-07-23 11:53 219648 c:\windows\Installer\a68730.msi

+ 2010-08-02 06:16 . 2010-08-02 06:16 180224 c:\windows\Installer\1ca14.msi

+ 2009-07-11 22:02 . 2009-07-11 22:02 3780424 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 3765048 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90.dll

+ 2010-07-24 05:44 . 2010-07-24 05:44 5612496 c:\windows\system32\Macromed\Flash\NPSWF32.dll

+ 2009-10-22 14:15 . 2010-08-02 06:26 3488384 c:\windows\system32\FNTCACHE.DAT

+ 2010-07-24 11:09 . 2010-07-24 11:09 1866752 c:\windows\Installer\1b4db.msi

+ 2010-06-20 08:01 . 2010-06-20 08:01 8040960 c:\windows\Installer\145356.msp

.

(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Not* Tomma poster & legitima standardposter visas inte.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SpybotSD TeaTimer"="c:\program\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe" [2009-07-31 468408]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 16132608]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-06 8523776]

"nwiz"="nwiz.exe" [2007-11-06 1626112]

"VolPanel"="c:\program\Creative\Volume Panel\VolPanlu.exe" [2008-08-06 233576]

"CTxfiHlp"="CTXFIHLP.EXE" [2009-06-03 25600]

"SunJavaUpdateSched"="c:\program\Delade filer\Java\Java Update\jusched.exe" [2010-05-14 248552]

"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

"AdobeCS4ServiceManager"="c:\program\Delade filer\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]

"Adobe Reader Speed Launcher"="c:\program\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]

"Adobe ARM"="c:\program\Delade filer\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

"QuickTime Task"="c:\program\QuickTime\qttask.exe" [2010-03-17 421888]

"iTunesHelper"="c:\program\iTunes\iTunesHelper.exe" [2010-04-28 142120]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]

 

c:\documents and settings\All Users\Start-meny\Program\Autostart\

Adobe Gamma Loader.lnk - c:\program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe [2009-10-30 110592]

Windows Search.lnk - c:\program\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ lsdelete

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program\\Delade filer\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=

"c:\\Program\\BitComet\\BitComet.exe"=

"c:\\Program\\Spotify\\spotify.exe"=

"c:\\Program\\Warcraft II BNE\\Warcraft II BNE.exe"=

"c:\\Program\\Malwarebytes' Anti-Malware\\mbam.exe"=

"c:\\Program\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program\\Windows Live\\Sync\\WindowsLiveSync.exe"=

"c:\\Program\\DC++\\DCPlusPlus.exe"=

"c:\\Program\\Tablet\\Wacom\\PrefUtil.exe"=

"c:\\Program\\Bonjour\\mDNSResponder.exe"=

"c:\\Program\\iTunes\\iTunes.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"5353:TCP"= 5353:TCP:Adobe CSI CS4

"7303:TCP"= 7303:TCP:BitComet 7303 TCP

"7303:UDP"= 7303:UDP:BitComet 7303 UDP

 

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-03-25 64288]

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2010-08-01 28552]

R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program\Lavasoft\Ad-Aware\AAWService.exe [2010-07-12 1352832]

R2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2009-12-02 5010288]

R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\l151x86.sys [2009-10-23 39424]

R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [2009-06-04 171032]

R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [2009-06-04 1324056]

R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [2009-06-04 72728]

R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2009-11-18 16168]

S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program\Delade filer\Creative Labs Shared\Service\CTAELicensing.exe [2009-10-23 79360]

S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [2009-06-04 171032]

S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [2009-06-04 1324056]

S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [2009-06-04 72728]

S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2009-12-02 691696]

.

Innehållet i mappen 'Schemalagda aktiviteter':

 

2010-08-04 c:\windows\Tasks\Ad-Aware Update (Weekly).job

- c:\program\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-07-12 08:55]

 

2010-07-30 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program\Apple Software Update\SoftwareUpdate.exe [2007-08-29 11:34]

 

2010-08-04 c:\windows\Tasks\User_Feed_Synchronization-{8549F50F-53DC-4CE4-A61C-F9C05D34D743}.job

- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]

.

.

------- Extra genomsökning -------

.

uStart Page = hxxp://www.google.se/

mWindow Title = Erhållen av Wermlandsdata

uInternet Settings,ProxyOverride = <local>

IE: &D&ownload &with BitComet - c:\program\BitComet\BitComet.exe/AddLink.htm

IE: &D&ownload all video with BitComet - c:\program\BitComet\BitComet.exe/AddVideo.htm

IE: &D&ownload all with BitComet - c:\program\BitComet\BitComet.exe/AddAllLink.htm

DPF: {6CCE3920-3183-4B3D-808A-B12EB769DE12} - hxxp://www.commandondemand.com/eval/cod/cabs/cssweb.cab

DPF: {E6BB2089-163F-466B-812A-748096614DFD} - hxxp://cainternetsecurity.net/scanner/cascanner.cab

FF - ProfilePath - c:\documents and settings\Anvädaren\Application Data\Mozilla\Firefox\Profiles\40amxa4k.default\

FF - plugin: c:\program\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll

FF - plugin: c:\program\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll

FF - plugin: c:\program\TabletPlugins\npwacom.dll

FF - plugin: c:\program\Windows Live\Photo Gallery\NPWLPG.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

 

---- FIREFOX POLICY ----

c:\program\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);

c:\program\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);

c:\program\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);

c:\program\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);

c:\program\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net'>http://www.gmer.net'>http://www.gmer.net

Rootkit scan 2010-08-04 20:01

Windows 5.1.2600 Service Pack 3 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

CTxfiHlp = CTXFIHLP.EXE?

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

 

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

 

device: opened successfully

user: MBR read successfully

called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys >>UNKNOWN [0x8A871A17]<<

kernel: MBR read successfully

detected MBR rootkit hooks:

\Driver\Disk -> CLASSPNP.SYS @ 0xba0ecf28

\Driver\ACPI -> ACPI.sys @ 0xb9f7fcb8

\Driver\atapi -> atapi.sys @ 0xb9f37852

IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8

ParseProcedure -> ntkrnlpa.exe @ 0x805827e8

\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8

ParseProcedure -> ntkrnlpa.exe @ 0x805827e8

NDIS: Atheros L1 Gigabit Ethernet 10/100/1000Base-T Controller -> SendCompleteHandler -> NDIS.sys @ 0xb9e30bb0

PacketIndicateHandler -> NDIS.sys @ 0xb9e1fa0d

SendHandler -> NDIS.sys @ 0xb9e33b40

user & kernel MBR OK

 

**************************************************************************

.

--------------------- LÅSTA REGISTERNYCKLAR ---------------------

 

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•6~*]

"D140211900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

.

--------------------- DLLer som "laddats" under processer som körs ---------------------

 

- - - - - - - > 'winlogon.exe'(520)

c:\program\Delade filer\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

.

Sluttid: 2010-08-04 20:04:56

ComboFix-quarantined-files.txt 2010-08-04 18:04

ComboFix2.txt 2010-07-22 17:27

ComboFix3.txt 2010-07-22 16:13

ComboFix4.txt 2010-07-22 12:58

ComboFix5.txt 2010-08-03 17:43

 

Före genomsökningen: 17 727 574 016 byte ledigt

Efter genomsökningen: 17 713 582 080 byte ledigt

 

Current=9 Default=9 Failed=8 LastKnownGood=10 Sets=1,2,3,4,5,6,7,8,9,10

- - End Of File - - 750D04794E57FFD8D8EFA56611B55705

 

 

 

 

Combofix karantän filer;

 

2010-07-22 12:47:57 . 2010-07-22 12:47:57 1,432 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Service_yvtikpdt.reg.dat

2010-07-22 12:47:56 . 2010-07-22 12:47:56 1,220 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_yvtikpdt.reg.dat

2010-07-20 14:00:07 . 2010-07-20 14:00:07 2,168 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Service_bjbrqlbu.reg.dat

2010-07-20 14:00:06 . 2010-07-20 14:00:06 1,088 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_BJBRQLBU.reg.dat

2010-07-20 13:51:51 . 2010-07-20 13:51:51 0 ----a-w- C:\Qoobox\Quarantine\catchme.txt

2010-07-20 11:45:34 . 2010-07-20 11:45:34 2,818 ----a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}.reg.dat

2010-07-20 11:45:34 . 2010-07-20 11:45:34 608 ----a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-Steinberg Cubase SX v2.2.0.33.reg.dat

2010-07-20 11:45:34 . 2010-07-20 11:45:34 616 ----a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-Native Instruments Battery v2.1.reg.dat

2010-07-20 11:44:30 . 2010-07-20 11:44:30 130 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-dfttuyox.reg.dat

2010-07-20 11:44:30 . 2010-07-20 11:44:30 117 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-sta.reg.dat

2010-07-20 11:44:21 . 2010-07-20 11:44:22 1,997 ----a-w- C:\Qoobox\Quarantine\Registry_backups\ShellIconOverlayIdentifiers-{B26DA910-F1DE-426A-8282-5B55958E11B6}.reg.dat

2010-07-20 11:44:19 . 2010-07-20 11:44:20 2,143 ----a-w- C:\Qoobox\Quarantine\Registry_backups\ShellIconOverlayIdentifiers-{1D0B2E83-D473-4E1F-B213-AA7BC759DE20}.reg.dat

2010-07-20 11:44:18 . 2010-07-20 11:44:18 2,000 ----a-w- C:\Qoobox\Quarantine\Registry_backups\ShellIconOverlayIdentifiers-{E309578C-8EDE-4731-99FA-6810B408B1BC}.reg.dat

2010-07-20 11:35:51 . 2010-07-20 11:35:51 14,778 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\_yhhjmjti_.sys.zip

2010-07-20 11:35:41 . 2010-07-20 11:35:41 1,640 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Service_gajnzinf.reg.dat

2010-07-20 11:35:41 . 2010-07-20 11:35:41 1,276 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_gajnzinf.reg.dat

2010-07-20 11:34:04 . 2010-08-04 17:58:52 6,440 ----a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg

2010-07-20 11:11:10 . 2010-08-04 17:50:54 1,282 ----a-w- C:\Qoobox\Quarantine\catchme.log

2010-07-20 09:56:37 . 2010-07-20 10:19:51 1,772 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\dfttuyo.txt.vir

2010-07-20 09:56:09 . 2010-07-20 09:56:09 40 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\service.sys.vir

2010-07-19 19:04:23 . 2010-07-20 18:07:18 0 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\yvtikpdt.sys.vir

2009-11-03 19:52:08 . 2009-11-03 19:52:08 915 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Start-meny\HP Image Zone .lnk.vir

2008-04-15 12:00:00 . 2008-04-15 12:00:00 9 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\comsats.sys.vir

2008-04-15 12:00:00 . 2008-04-15 12:00:00 239 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\Install.txt.vir

2008-04-15 12:00:00 . 2008-04-15 12:00:00 26,112 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\userinit.exe.vir

2008-04-15 12:00:00 . 2008-04-15 12:00:00 23,424 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\gajnzinf.sys.vir

2008-04-15 12:00:00 . 2008-04-15 12:00:00 23,424 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\yhhjmjti.sys.vir

 

 

 

 

Nånting som man kan ta bort?

 

 

 

Gmer;

 

 

GMER 1.0.15.15281 - http://www.gmer.net

Rootkit scan 2010-08-04 22:20:13

Windows 5.1.2600 Service Pack 3

Running: 93u6mbnh.exe; Driver: C:\DOCUME~1\ANVDAR~1\LOKALA~1\Temp\fwnyyaod.sys

 

 

---- System - GMER 1.0.15 ----

 

SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xBA0F887E]

SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xBA0F8BFE]

 

---- Kernel code sections - GMER 1.0.15 ----

 

.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB96A3360, 0x3441C7, 0xE8000020]

 

---- User code sections - GMER 1.0.15 ----

 

.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 009F000A

.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00A0000A

.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 009E000C

.text C:\WINDOWS\System32\svchost.exe[1028] ole32.dll!CoCreateInstance 774F057E 5 Bytes JMP 00E9000A

.text C:\WINDOWS\system32\SearchIndexer.exe[1056] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)

.text C:\WINDOWS\Explorer.EXE[1464] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00BD000A

.text C:\WINDOWS\Explorer.EXE[1464] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00CB000A

.text C:\WINDOWS\Explorer.EXE[1464] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00BC000C

.text C:\WINDOWS\system32\wuauclt.exe[2188] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 009F000A

.text C:\WINDOWS\system32\wuauclt.exe[2188] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00A0000A

.text C:\WINDOWS\system32\wuauclt.exe[2188] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 003F000C

 

---- Devices - GMER 1.0.15 ----

 

AttachedDevice \Driver\Tcpip \Device\Tcp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)

AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)

 

---- Registry - GMER 1.0.15 ----

 

Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys@start 1

Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys@type 1

Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys@imagepath \systemroot\system32\drivers\H8SRTdlhhlggibr.sys

Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys@group file system

Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys\modules (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys\modules@H8SRTd

Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys\modules@H8SRTc

Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys\modules@H8SRTsrcr

Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys\modules@h8srtserf

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program\DAEMON Tools Lite\

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x3A 0xFB 0x63 0x48 ...

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x92 0x3B 0x41 0xA8 ...

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x82 0x73 0x1F 0xF8 ...

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x35 0xDE 0xD0 0x99 ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program\DAEMON Tools Lite\

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x8B 0xCD 0x6B 0xBE ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x92 0x3B 0x41 0xA8 ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x82 0x73 0x1F 0xF8 ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xED 0xD8 0xB3 0xB0 ...

Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program\DAEMON Tools Lite\

Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...

Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0

Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x94 0x0C 0xBB 0x12 ...

Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...

Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x92 0x3B 0x41 0xA8 ...

Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x82 0x73 0x1F 0xF8 ...

Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xED 0xD8 0xB3 0xB0 ...

Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program\DAEMON Tools Lite\

Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...

Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0

Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x94 0x0C 0xBB 0x12 ...

Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...

Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x92 0x3B 0x41 0xA8 ...

Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x82 0x73 0x1F 0xF8 ...

Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xED 0xD8 0xB3 0xB0 ...

Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program\DAEMON Tools Lite\

Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...

Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0

Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x94 0x0C 0xBB 0x12 ...

Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...

Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x92 0x3B 0x41 0xA8 ...

Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x82 0x73 0x1F 0xF8 ...

Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xED 0xD8 0xB3 0xB0 ...

Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program\DAEMON Tools Lite\

Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...

Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0

Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x94 0x0C 0xBB 0x12 ...

Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...

Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x92 0x3B 0x41 0xA8 ...

Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x82 0x73 0x1F 0xF8 ...

Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xED 0xD8 0xB3 0xB0 ...

Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program\DAEMON Tools Lite\

Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...

Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0

Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x94 0x0C 0xBB 0x12 ...

Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...

Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x92 0x3B 0x41 0xA8 ...

Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x82 0x73 0x1F 0xF8 ...

Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xED 0xD8 0xB3 0xB0 ...

Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program\DAEMON Tools Lite\

Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...

Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0

Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x94 0x0C 0xBB 0x12 ...

Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...

Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x92 0x3B 0x41 0xA8 ...

Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x82 0x73 0x1F 0xF8 ...

Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xED 0xD8 0xB3 0xB0 ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program\DAEMON Tools Lite\

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x94 0x0C 0xBB 0x12 ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x92 0x3B 0x41 0xA8 ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x82 0x73 0x1F 0xF8 ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xED 0xD8 0xB3 0xB0 ...

Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program\DAEMON Tools Lite\

Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...

Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0

Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x94 0x0C 0xBB 0x12 ...

Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...

Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x92 0x3B 0x41 0xA8 ...

Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x82 0x73 0x1F 0xF8 ...

Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)

Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xED 0xD8 0xB3 0xB0 ...

 

---- EOF - GMER 1.0.15 ----

 

 

 

 

 

och Rootrepeal;

 

 

ROOTREPEAL © AD, 2007-2009

==================================================

Scan Start Time: 2010/08/04 20:44

Program Version: Version 1.3.5.0

Windows Version: Windows XP SP3

==================================================

 

Drivers

-------------------

Name: dump_atapi.sys

Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys

Address: 0xA896D000 Size: 98304 File Visible: No Signed: -

Status: -

 

Name: dump_WMILIB.SYS

Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS

Address: 0xBA63A000 Size: 8192 File Visible: No Signed: -

Status: -

 

Name: rootrepeal.sys

Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys

Address: 0xA7607000 Size: 49152 File Visible: No Signed: -

Status: -

 

SSDT

-------------------

#: 041 Function Name: NtCreateKey

Status: Hooked by "Lbd.sys" at address 0xba0f887e

 

#: 247 Function Name: NtSetValueKey

Status: Hooked by "Lbd.sys" at address 0xba0f8bfe

 

==EOF==

 

 

 

 

 

 

 

 

 

 

 

Tack för all hjälp so far Cecilia!

Länk till kommentar
Dela på andra webbplatser

Kan du klistra in dagens logg från MBAM? Du hittar den på fliken Loggar i MBAM.

 

Sök igenom datorn med Avast och klistra in loggen om något hittas.

 

Klistra in loggen C:\Qoobox\ComboFix5.txt för den skapades för tre dagar sedan så den har jag inte sett.

 

På sidan http://www.virustotal.com trycker du på Bläddra-knappen och klistrar in följande filnamn i rutan, tryck på Öppna och sedan Skicka Fil. Vänta tills resultatet är klart (Närvarande status blir genomförd). Klistra in en länk till resultatet här.

c:\windows\pchealth\helpctr\binaries\helpsvc.exe

 

Avinstallera det som finns med Panda i Lägg till och ta bort program. Starta sedan om datorn och kör ComboFix igen och klistra in dess logg.

Länk till kommentar
Dela på andra webbplatser

Har skannat med Avast och den hittar nåt som är satt i karantän, men varken jag eller brorsan lyckas hitta några loggar.

 

Skickar båda Malaware, före och efter;

 

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

 

Databasversion: 4393

 

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

 

2010-08-05 17:56:03

mbam-log-2010-08-05 (17-56-03).txt

 

Skanningstyp: Fullständig skanning (C:\|D:\|)

Antal skannade objekt: 254151

Förfluten tid: 51 minut(er), 35 sekund(er)

 

Infekterade minnesprocesser: 0

Infekterade minnesmoduler: 0

Infekterade registernycklar: 0

Infekterade registervärden: 0

Infekterade registerdataposter: 0

Infekterade mappar: 0

Infekterade filer: 1

 

Infekterade minnesprocesser:

(Inga illasinnade poster hittades)

 

Infekterade minnesmoduler:

(Inga illasinnade poster hittades)

 

Infekterade registernycklar:

(Inga illasinnade poster hittades)

 

Infekterade registervärden:

(Inga illasinnade poster hittades)

 

Infekterade registerdataposter:

(Inga illasinnade poster hittades)

 

Infekterade mappar:

(Inga illasinnade poster hittades)

 

Infekterade filer:

C:\System Volume Information\_restore{EF285882-231C-4C1A-A3D4-3944938805B3}\RP13\A0006366.exe (Malware.Packer.Gen) -> No action taken.

 

 

Efter;

 

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

 

Databasversion: 4393

 

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

 

2010-08-05 18:54:18

mbam-log-2010-08-05 (18-54-18).txt

 

Skanningstyp: Fullständig skanning (C:\|D:\|)

Antal skannade objekt: 253957

Förfluten tid: 49 minut(er), 14 sekund(er)

 

Infekterade minnesprocesser: 0

Infekterade minnesmoduler: 0

Infekterade registernycklar: 0

Infekterade registervärden: 0

Infekterade registerdataposter: 0

Infekterade mappar: 0

Infekterade filer: 0

 

Infekterade minnesprocesser:

(Inga illasinnade poster hittades)

 

Infekterade minnesmoduler:

(Inga illasinnade poster hittades)

 

Infekterade registernycklar:

(Inga illasinnade poster hittades)

 

Infekterade registervärden:

(Inga illasinnade poster hittades)

 

Infekterade registerdataposter:

(Inga illasinnade poster hittades)

 

Infekterade mappar:

(Inga illasinnade poster hittades)

 

Infekterade filer:

(Inga illasinnade poster hittades)

 

 

http://www.virustotal.com/sv/reanalisis.html?adbf3948908ab0c487d2b536e2f8e0c0803ef2bde109ac525677582549f7a7e2-1281116365

 

 

Avast verkar hindra Combofix från att söka(trots att vi stängt av som guiden hänvisar till), så brorsan ska avinstallera de och skanna nu så kommer loggen imorn.

Länk till kommentar
Dela på andra webbplatser

Länken till virustotal fungerar inte. Du får klicka på knappen "Visa senaste rapport" innan du kopierar länken.

 

Du klistrade in tre ComboFix-länkar som redan är inklistrade i tråden i stället för den som gjordes för tre dagar sedan, ComboFix5.txt 2010-08-03 17:43

 

I Avast kan du hitta loggar genom att välja "Skanna dator" till vänster och sedan "Skanningslogg". Markera en logg och klicka sedan på en knapp för att visa resultatet.

Länk till kommentar
Dela på andra webbplatser

Nån annan CombiFix5.txt finns inte längre från den tredje augusti, måste ha blivit ersatt?

 

Här är nya länken, nu bör den funka iaf;

http://www.virustotal.com/sv/analisis/adbf3948908ab0c487d2b536e2f8e0c0803ef2bde109ac525677582549f7a7e2-1281082415

 

 

Avast har han avinstallerat för att kunna köra Combofix för tillfället, programmet blockar Comobofix även om man stängt av allt som man ska nämligen.

Men Avast är installerat igen och hittar nu inte dom filerna som låg i karantän dock, så dom ligegr väl å spökar nånstans.

 

Jäkla avancerade datorer, haha! :D

Länk till kommentar
Dela på andra webbplatser

När man avinstallerar ett antivirusprogram kan det vara så att det som finns i karantänen tas bort helt från datorn.

 

Hittar Avast något vid en skanning av datorn? I så fall klistra in den loggen.

 

Spara GooredFix på Skrivbordet, från en av länkarna:

http://jpshortstuff.247fixes.com/GooredFix.exe

http://downloads.securitycadets.com/GooredFix.exe

 

Dubbelklicka på programmet för att starta det.

Klicka på Yes för att starta skanningen.

Kopiera innehållet i loggen som kommer upp och den finns även på skrivbordet med namnet GooredFix.txt.

Länk till kommentar
Dela på andra webbplatser

Tjo, här är senaste loggen;

 

 

 

GooredFix by jpshortstuff (03.07.10.1)

Log created at 18:44 on 07/08/2010 (Anvädaren)

Firefox version 3.6.6 (sv-SE)

 

========== GooredScan ==========

 

 

========== GooredLog ==========

 

C:\Program\Mozilla Firefox\extensions\

{972ce4c6-7e08-4474-a285-3208198ce6fd} [14:53 02/08/2010]

{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [06:16 02/08/2010]

 

C:\Documents and Settings\Anvädaren\Application Data\Mozilla\Firefox\Profiles\40amxa4k.default\extensions\

{20a82645-c095-46ed-80e3-08825760534b} [18:19 03/08/2010]

 

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]

"{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [14:43 23/10/2009]

"jqs@sun.com"="C:\Program\Java\jre6\lib\deploy\jqs\ff" [08:11 26/10/2009]

 

-=E.O.F=-

Länk till kommentar
Dela på andra webbplatser

Inget konstigt där.

 

Spara MBRCheck.exe av a_d_13 på Skrivbordet.

Kör programmet.

Vänta tills programmet är klart eller till texten "Enter 'Y' and hit ENTER for more options, or 'N' to exit:" visas. I det senare fallet tryck på N följt av Enter.

När det är klart skapas en loggfil på Skrivbordet som heter MBRCheckxxxxxx.txt där xxxxxx är klockslaget för körningen. Öppna loggen i Anteckningar genom att dubbelklicka på loggen och klistra in innehållet i ditt svar.

 

Samt dags för en ny ComboFix-logg eftersom det gått flera dagar. Ta bort den du har och hämta en ny. Kör på samma sätt som tidigare. http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Länk till kommentar
Dela på andra webbplatser

Jäkla envisa rackare på datan.

 

MBRCheck, version 1.2.3

© 2010, AD

 

Command-line:

Windows Version: Windows XP Home Edition

Windows Information: Service Pack 3 (build 2600)

Logical Drives Mask: 0x000007fc

 

Kernel Drivers (total 135):

0x804D7000 \WINDOWS\system32\ntkrnlpa.exe

0x806E4000 \WINDOWS\system32\hal.dll

0x8A710000 \WINDOWS\system32\KDCOM.DLL

0xBA4BC000 \WINDOWS\system32\BOOTVID.dll

0xB9F79000 ACPI.sys

0xBA5A8000 \WINDOWS\system32\DRIVERS\WMILIB.SYS

0xB9F68000 pci.sys

0xBA0A8000 isapnp.sys

0xBA5AA000 avgarkt.sys

0xBA670000 pciide.sys

0xBA328000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS

0xBA0B8000 MountMgr.sys

0xB9F49000 ftdisk.sys

0xBA330000 PartMgr.sys

0xBA0C8000 VolSnap.sys

0xB9F31000 atapi.sys

0xBA0D8000 disk.sys

0xBA0E8000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS

0xB9F11000 fltMgr.sys

0xB9EFF000 sr.sys

0xBA0F8000 Lbd.sys

0xBA108000 PxHelp20.sys

0xB9EE8000 KSecDD.sys

0xB9ED5000 WudfPf.sys

0xB9E48000 Ntfs.sys

0xB9E1B000 NDIS.sys

0xB9E01000 Mup.sys

0xBA208000 \SystemRoot\system32\DRIVERS\intelppm.sys

0xB96A3000 \SystemRoot\system32\DRIVERS\nv4_mini.sys

0xB968F000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS

0xB9667000 \SystemRoot\system32\DRIVERS\HDAudBus.sys

0xBA218000 \SystemRoot\system32\DRIVERS\l151x86.sys

0xBA3B8000 \SystemRoot\system32\DRIVERS\usbuhci.sys

0xB9643000 \SystemRoot\system32\DRIVERS\USBPORT.SYS

0xBA3C0000 \SystemRoot\system32\DRIVERS\usbehci.sys

0xB95C4000 \SystemRoot\system32\drivers\ctaud2k.sys

0xB95A0000 \SystemRoot\system32\drivers\portcls.sys

0xBA228000 \SystemRoot\system32\drivers\drmk.sys

0xB957D000 \SystemRoot\system32\drivers\ks.sys

0xB9548000 \SystemRoot\system32\drivers\ctoss2k.sys

0xBA3C8000 \SystemRoot\system32\drivers\ctprxy2k.sys

0xBA238000 \SystemRoot\system32\DRIVERS\serial.sys

0xBA56C000 \SystemRoot\system32\DRIVERS\serenum.sys

0xB9534000 \SystemRoot\system32\DRIVERS\parport.sys

0xBA5CA000 \SystemRoot\system32\DRIVERS\ASACPI.sys

0xBA248000 \SystemRoot\system32\DRIVERS\cdrom.sys

0xBA258000 \SystemRoot\system32\DRIVERS\redbook.sys

0xBA3D8000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys

0xBA268000 \SystemRoot\system32\DRIVERS\imapi.sys

0xBA5CC000 \SystemRoot\system32\DRIVERS\wacomvhid.sys

0xBA278000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS

0xBA3E0000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS

0xBA5CE000 \SystemRoot\system32\DRIVERS\WacomVKHid.sys

0xBA7F1000 \SystemRoot\system32\DRIVERS\audstub.sys

0xBA288000 \SystemRoot\system32\DRIVERS\rasl2tp.sys

0xBA580000 \SystemRoot\system32\DRIVERS\ndistapi.sys

0xB951D000 \SystemRoot\system32\DRIVERS\ndiswan.sys

0xBA298000 \SystemRoot\system32\DRIVERS\raspppoe.sys

0xBA2A8000 \SystemRoot\system32\DRIVERS\raspptp.sys

0xBA3E8000 \SystemRoot\system32\DRIVERS\TDI.SYS

0xB9444000 \SystemRoot\system32\DRIVERS\psched.sys

0xBA2B8000 \SystemRoot\system32\DRIVERS\msgpc.sys

0xBA3F0000 \SystemRoot\system32\DRIVERS\ptilink.sys

0xBA3F8000 \SystemRoot\system32\DRIVERS\raspti.sys

0xBA2C8000 \SystemRoot\system32\DRIVERS\termdd.sys

0xBA400000 \SystemRoot\system32\DRIVERS\kbdclass.sys

0xBA408000 \SystemRoot\system32\DRIVERS\mouclass.sys

0xBA5D0000 \SystemRoot\system32\DRIVERS\swenum.sys

0xB93E6000 \SystemRoot\system32\DRIVERS\update.sys

0xBA58C000 \SystemRoot\system32\DRIVERS\mssmbios.sys

0xBA5A0000 \SystemRoot\system32\DRIVERS\mouhid.sys

0xBA410000 \SystemRoot\system32\DRIVERS\wacommousefilter.sys

0xB9DD9000 \SystemRoot\system32\DRIVERS\kbdhid.sys

0xBA2D8000 \SystemRoot\System32\Drivers\NDProxy.SYS

0xB6E90000 \SystemRoot\system32\drivers\RtkHDAud.sys

0xBA2E8000 \SystemRoot\system32\DRIVERS\usbhub.sys

0xBA5E8000 \SystemRoot\system32\DRIVERS\USBD.SYS

0xB2ADD000 \SystemRoot\system32\drivers\ha20x2k.sys

0xB2AAD000 \SystemRoot\system32\drivers\emupia2k.sys

0xB2A84000 \SystemRoot\system32\drivers\ctsfm2k.sys

0xB29E8000 \SystemRoot\system32\drivers\ctac32k.sys

0xB29D3000 \SystemRoot\System32\drivers\CTHWIUT.SYS

0xB29A7000 \SystemRoot\System32\drivers\CT20XUT.SYS

0xB2860000 \SystemRoot\System32\drivers\CTEXFIFX.SYS

0xBA5EA000 \SystemRoot\System32\Drivers\Fs_Rec.SYS

0xBA7FA000 \SystemRoot\System32\Drivers\Null.SYS

0xBA5EC000 \SystemRoot\System32\Drivers\Beep.SYS

0xBA7FD000 \SystemRoot\System32\DRIVERS\AvgArCln.sys

0xBA430000 \SystemRoot\System32\drivers\vga.sys

0xBA5EE000 \SystemRoot\System32\Drivers\mnmdd.SYS

0xBA5F0000 \SystemRoot\System32\DRIVERS\RDPCDD.sys

0xBA438000 \SystemRoot\System32\Drivers\Msfs.SYS

0xBA440000 \SystemRoot\System32\Drivers\Npfs.SYS

0xB945D000 \SystemRoot\system32\DRIVERS\rasacd.sys

0xB282D000 \SystemRoot\system32\DRIVERS\ipsec.sys

0xB27D4000 \SystemRoot\system32\DRIVERS\tcpip.sys

0xBA308000 \SystemRoot\System32\Drivers\aswTdi.SYS

0xB2786000 \SystemRoot\system32\DRIVERS\ipnat.sys

0xB275E000 \SystemRoot\system32\DRIVERS\netbt.sys

0xB273C000 \SystemRoot\System32\drivers\afd.sys

0xBA318000 \SystemRoot\system32\DRIVERS\netbios.sys

0xB2711000 \SystemRoot\system32\DRIVERS\rdbss.sys

0xB26A1000 \SystemRoot\system32\DRIVERS\mrxsmb.sys

0xBA148000 \SystemRoot\System32\Drivers\Fips.SYS

0xB267A000 \SystemRoot\System32\Drivers\aswSP.SYS

0xBA340000 \SystemRoot\System32\Drivers\Aavmker4.SYS

0xBA380000 \SystemRoot\system32\DRIVERS\usbccgp.sys

0xBA178000 \SystemRoot\system32\DRIVERS\wanarp.sys

0xBA188000 \SystemRoot\System32\Drivers\Cdfs.SYS

0xB6E70000 \SystemRoot\system32\DRIVERS\hidusb.sys

0xBA390000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS

0xBA398000 \SystemRoot\system32\DRIVERS\wacmoumonitor.sys

0xB259A000 \SystemRoot\System32\Drivers\dump_atapi.sys

0xBA600000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS

0xBF800000 \SystemRoot\System32\win32k.sys

0xB6E20000 \SystemRoot\System32\drivers\Dxapi.sys

0xBA3B0000 \SystemRoot\System32\watchdog.sys

0xBF000000 \SystemRoot\System32\drivers\dxg.sys

0xBA707000 \SystemRoot\System32\drivers\dxgthk.sys

0xBF012000 \SystemRoot\System32\nv4_disp.dll

0xBFFA0000 \SystemRoot\System32\ATMFD.DLL

0xB2376000 \SystemRoot\System32\Drivers\aswFsBlk.SYS

0xB950D000 \SystemRoot\system32\DRIVERS\fssfltr_tdi.sys

0xB235A000 \SystemRoot\system32\DRIVERS\ndisuio.sys

0xB1FEB000 \SystemRoot\System32\Drivers\aswMon2.SYS

0xB11E0000 \SystemRoot\system32\drivers\wdmaud.sys

0xB25E2000 \SystemRoot\system32\drivers\sysaudio.sys

0xB0F05000 \SystemRoot\system32\DRIVERS\mrxdav.sys

0xBA5FC000 \SystemRoot\System32\Drivers\ParVdm.SYS

0xB0EF4000 \SystemRoot\System32\Drivers\adfs.SYS

0xB0E4D000 \SystemRoot\system32\DRIVERS\srv.sys

0xB0454000 \SystemRoot\System32\Drivers\HTTP.sys

0xB1F73000 \SystemRoot\System32\Drivers\aswRdr.SYS

0xACE6C000 \SystemRoot\system32\drivers\kmixer.sys

0x7C900000 \WINDOWS\system32\ntdll.dll

 

Processes (total 50):

0 System Idle Process

4 System

448 C:\WINDOWS\system32\smss.exe

672 csrss.exe

696 C:\WINDOWS\system32\winlogon.exe

744 C:\WINDOWS\system32\services.exe

756 C:\WINDOWS\system32\lsass.exe

932 C:\WINDOWS\system32\svchost.exe

1004 svchost.exe

1120 C:\WINDOWS\system32\svchost.exe

1192 C:\WINDOWS\system32\svchost.exe

1348 svchost.exe

1468 svchost.exe

1532 C:\Program\Lavasoft\Ad-Aware\AAWService.exe

1660 C:\WINDOWS\explorer.exe

1768 C:\Program\Alwil Software\Avast5\AvastSvc.exe

1892 C:\WINDOWS\RTHDCPL.exe

1920 C:\Program\Creative\Volume Panel\VolPanlu.exe

1928 C:\WINDOWS\system32\Ctxfihlp.exe

1936 C:\Program\Delade filer\Java\Java Update\jusched.exe

2024 C:\Program\iTunes\iTunesHelper.exe

2032 C:\Program\ALWILS~1\Avast5\AvastUI.exe

128 C:\WINDOWS\system32\ctfmon.exe

144 C:\Program\Windows Desktop Search\WindowsSearch.exe

1216 C:\WINDOWS\system32\spoolsv.exe

1336 C:\Program\Creative\Shared Files\CTAudSvc.exe

1876 C:\WINDOWS\system32\CTxfispi.exe

1544 svchost.exe

1076 C:\Program\Delade filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe

2056 C:\Program\Bonjour\mDNSResponder.exe

2080 C:\WINDOWS\system32\CTSVCCDA.EXE

2188 C:\Program\Java\jre6\bin\jqs.exe

2292 C:\WINDOWS\system32\nvsvc32.exe

2376 C:\WINDOWS\system32\HPZipm12.exe

2412 C:\Program\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

2644 C:\WINDOWS\system32\svchost.exe

2692 C:\WINDOWS\system32\Wacom_Tablet.exe

2740 C:\WINDOWS\system32\searchindexer.exe

2840 C:\WINDOWS\system32\WTablet\Wacom_TabletUser.exe

3000 C:\WINDOWS\system32\Wacom_Tablet.exe

3300 unsecapp.exe

3380 C:\Program\iPod\bin\iPodService.exe

3456 wmiprvse.exe

3784 alg.exe

220 C:\WINDOWS\system32\nvcplui.exe

3792 C:\WINDOWS\system32\svchost.exe

1948 C:\Program\Internet Explorer\iexplore.exe

812 C:\Program\Internet Explorer\iexplore.exe

2996 C:\Program\Lavasoft\Ad-Aware\AAWService.exe

1036 C:\Documents and Settings\Anvädaren\Skrivbord\MBRCheck.exe

 

\\.\C: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS)

\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)

 

PhysicalDrive1 Model Number: ST3250824AS, Rev: 3.AAE

PhysicalDrive0 Model Number: ST3250824AS, Rev: 3.AAE

 

Size Device Name MBR Status

--------------------------------------------

232 GB \\.\PhysicalDrive1 MBR Code Faked!

SHA1: 73D0B9F01FD4F36F44A5EDC33E3160FB277FCB92

232 GB \\.\PhysicalDrive0 Windows XP MBR code detected

SHA1: EEC098E77D0529BD75F64F7B26552C1BA4417B73

 

 

Found non-standard or infected MBR.

Enter 'Y' and hit ENTER for more options, or 'N' to exit:

 

Done!

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

ComboFix 10-08-10.07 - Anvädaren 2010-08-15 11:44:12.9.2 - x86

Microsoft Windows XP Home Edition 5.1.2600.3.1252.46.1053.18.2047.1591 [GMT 2:00]

Körs från: c:\documents and settings\Anvädaren\Skrivbord\ComboFix.exe

.

 

(((((((((((((((((((((((( Filer Skapade från 2010-07-15 till 2010-08-15 ))))))))))))))))))))))))))))))

.

 

2010-08-12 05:08 . 2010-08-15 09:40 -------- d-----w- c:\documents and settings\LocalService\Application Data\WTablet

2010-08-11 10:06 . 2007-02-15 14:11 11440 ----a-w- c:\windows\system32\drivers\WacomVKHid.sys

2010-08-11 10:06 . 2008-07-11 09:16 13352 ----a-w- c:\windows\system32\drivers\wacomvhid.sys

2010-08-11 10:06 . 2007-02-16 09:12 11312 ----a-w- c:\windows\system32\drivers\wacommousefilter.sys

2010-08-11 10:05 . 2010-08-11 10:05 -------- d-----w- c:\windows\system32\WTablet

2010-08-11 10:05 . 2009-03-26 15:15 2789672 ----a-w- c:\windows\system32\Wacom_Tablet.exe

2010-08-11 10:05 . 2009-03-26 14:40 213288 ----a-w- c:\windows\system32\Wacom_Tablet.dll

2010-08-11 10:05 . 2009-03-26 14:10 172840 ----a-w- c:\windows\system32\Wintab32.dll

2010-08-11 10:05 . 2010-08-11 10:06 -------- d-----w- c:\program\Tablet

2010-08-03 17:34 . 2010-08-03 17:34 16968 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys

2010-08-03 17:33 . 2010-08-03 17:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Hitman Pro

2010-08-03 17:33 . 2010-08-03 17:33 -------- d-----w- c:\program\Hitman Pro 3.5

2010-08-03 06:03 . 2010-08-11 09:59 664 ----a-w- c:\windows\system32\d3d9caps.dat

2010-08-02 14:53 . 2010-08-02 14:53 0 ----a-w- c:\windows\nsreg.dat

2010-08-02 06:31 . 2010-08-02 07:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy

2010-08-02 06:31 . 2010-08-02 06:37 -------- d-----w- c:\program\Spybot - Search & Destroy

2010-08-02 06:16 . 2010-08-02 06:16 -------- d-----w- c:\program\Delade filer\Java

2010-08-02 06:16 . 2010-07-17 03:00 423656 ----a-w- c:\windows\system32\deployJava1.dll

2010-07-29 12:03 . 2010-07-29 12:03 -------- d-----r- c:\documents and settings\NetworkService\Favoriter

2010-07-24 11:09 . 2010-07-12 08:56 2979280 -c--a-w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}\Ad-AwareInstall.exe

2010-07-24 11:01 . 2010-07-24 11:09 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}

2010-07-23 11:53 . 2010-07-23 11:53 -------- d-----w- c:\program\Alwil Software

2010-07-23 11:53 . 2010-07-23 11:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software

2010-07-21 16:58 . 2010-07-21 16:58 -------- d-----w- c:\windows\system32\wbem\Repository

2010-07-19 20:22 . 2010-07-12 08:55 15880 ----a-w- c:\windows\system32\lsdelete.exe

2010-07-19 19:41 . 2010-07-19 19:47 -------- d-----w- c:\windows\SxsCaPendDel

2010-07-19 19:16 . 2010-07-19 19:16 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-08-14 14:41 . 2009-10-30 09:38 -------- d-----w- c:\program\BitComet

2010-08-11 09:35 . 2009-12-02 17:24 -------- d-----w- c:\program\TabletPlugins

2010-08-02 07:06 . 2009-11-18 12:17 67072 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT

2010-08-02 06:19 . 2009-11-03 19:43 -------- d-----w- c:\program\HP

2010-08-02 06:17 . 2009-11-03 19:51 -------- d-----w- c:\program\Delade filer\HP

2010-08-02 06:15 . 2009-10-26 08:11 -------- d-----w- c:\program\Java

2010-07-20 08:30 . 2009-12-31 16:55 -------- d-----w- c:\program\Malwarebytes' Anti-Malware

2010-07-20 04:41 . 2009-10-28 17:21 -------- d-----w- c:\program\Norman

2010-07-19 20:04 . 2009-10-31 07:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft

2010-07-12 08:55 . 2010-03-25 06:40 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys

2010-06-23 20:49 . 2008-04-15 12:00 92094 ----a-w- c:\windows\system32\perfc01D.dat

2010-06-23 20:49 . 2008-04-15 12:00 463742 ----a-w- c:\windows\system32\perfh01D.dat

2010-06-16 19:25 . 2010-06-16 19:25 -------- d-----w- c:\program\iTunes

2010-06-16 19:25 . 2010-06-16 19:25 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}

2010-06-16 19:25 . 2010-06-16 19:25 -------- d-----w- c:\program\iPod

2010-06-16 19:25 . 2009-10-31 08:10 -------- d-----w- c:\program\Delade filer\Apple

2010-06-16 19:23 . 2009-10-31 12:17 -------- d-----w- c:\program\QuickTime

2010-06-16 19:21 . 2010-06-16 19:21 -------- d-----w- c:\program\Bonjour

2010-06-16 19:16 . 2009-10-28 18:30 -------- d-----w- c:\program\VideoLAN

2010-06-16 19:16 . 2010-06-16 19:16 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe

2010-06-14 14:31 . 2009-10-22 12:23 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe

2010-05-23 06:12 . 2009-11-10 06:59 8 ----a-w- c:\windows\system32\nvModes.dat

.

 

((((((((((((((((((((((((((((( SnapShot@2010-07-20_11.40.15 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-07-11 22:02 . 2009-07-11 22:02 51008 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90rus.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90kor.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90jpn.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90ita.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90fra.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 61760 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esp.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esn.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 53568 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 63296 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90deu.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90cht.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 35648 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90chs.dll

+ 2009-07-11 22:05 . 2009-07-11 22:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll

+ 2009-07-11 22:05 . 2009-07-11 22:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll

+ 2010-08-15 09:41 . 2010-08-15 09:41 16384 c:\windows\temp\Perflib_Perfdata_740.dat

+ 2010-07-24 11:22 . 2010-07-12 08:55 64288 c:\windows\system32\DRVSTORE\lbd_9C578CA880A99903668A8694DEFB21244E9C4C62\Lbd.sys

+ 2009-11-18 11:52 . 2008-10-06 09:53 15656 c:\windows\system32\drivers\wacmoumonitor.sys

+ 2001-09-06 19:55 . 2001-09-06 17:55 12160 c:\windows\system32\drivers\mouhid.sys

- 2001-09-06 19:55 . 2001-09-06 18:55 12160 c:\windows\system32\drivers\mouhid.sys

+ 2008-04-14 21:03 . 2008-04-14 19:03 23296 c:\windows\system32\drivers\mouclass.sys

- 2008-04-14 21:03 . 2008-04-14 20:03 23296 c:\windows\system32\drivers\mouclass.sys

- 2001-09-06 19:55 . 2001-09-06 18:55 12160 c:\windows\system32\dllcache\mouhid.sys

+ 2001-09-06 19:55 . 2001-09-06 17:55 12160 c:\windows\system32\dllcache\mouhid.sys

- 2008-04-14 21:03 . 2008-04-14 20:03 23296 c:\windows\system32\dllcache\mouclass.sys

+ 2008-04-14 21:03 . 2008-04-14 19:03 23296 c:\windows\system32\dllcache\mouclass.sys

+ 2009-07-11 22:02 . 2009-07-11 22:02 653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll

+ 2009-07-11 22:05 . 2009-07-11 22:05 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll

- 2009-07-11 23:02 . 2009-07-11 23:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll

+ 2010-08-11 10:05 . 2009-03-26 15:16 186664 c:\windows\system32\WTablet\Wacom_TabletUser.exe

+ 2009-11-13 14:56 . 2010-07-21 17:13 144476 c:\windows\system32\Restore\rstrlog.dat

+ 2010-07-24 05:44 . 2010-07-24 05:44 231888 c:\windows\system32\Macromed\Flash\FlashUtil10h_Plugin.exe

+ 2010-08-02 06:16 . 2010-07-17 03:00 153376 c:\windows\system32\javaws.exe

+ 2010-08-02 06:16 . 2010-07-17 03:00 145184 c:\windows\system32\javaw.exe

- 2009-10-26 08:38 . 2009-07-25 04:23 145184 c:\windows\system32\javaw.exe

+ 2010-08-02 06:15 . 2010-07-17 03:00 145184 c:\windows\system32\java.exe

- 2009-10-26 08:38 . 2009-07-25 04:23 145184 c:\windows\system32\java.exe

+ 2010-07-23 11:53 . 2010-07-23 11:53 219648 c:\windows\Installer\a68730.msi

+ 2010-08-02 06:16 . 2010-08-02 06:16 180224 c:\windows\Installer\1ca14.msi

+ 2009-07-11 22:02 . 2009-07-11 22:02 3780424 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 3765048 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90.dll

+ 2010-07-24 05:44 . 2010-07-24 05:44 5612496 c:\windows\system32\Macromed\Flash\NPSWF32.dll

+ 2009-10-22 14:15 . 2010-08-02 06:26 3488384 c:\windows\system32\FNTCACHE.DAT

+ 2010-07-24 11:09 . 2010-07-24 11:09 1866752 c:\windows\Installer\1b4db.msi

+ 2010-06-20 08:01 . 2010-06-20 08:01 8040960 c:\windows\Installer\145356.msp

.

(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Not* Tomma poster & legitima standardposter visas inte.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SpybotSD TeaTimer"="c:\program\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe" [2009-07-31 468408]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 16132608]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-06 8523776]

"nwiz"="nwiz.exe" [2007-11-06 1626112]

"VolPanel"="c:\program\Creative\Volume Panel\VolPanlu.exe" [2008-08-06 233576]

"CTxfiHlp"="CTXFIHLP.EXE" [2009-06-03 25600]

"SunJavaUpdateSched"="c:\program\Delade filer\Java\Java Update\jusched.exe" [2010-05-14 248552]

"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

"AdobeCS4ServiceManager"="c:\program\Delade filer\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]

"Adobe Reader Speed Launcher"="c:\program\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]

"Adobe ARM"="c:\program\Delade filer\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

"QuickTime Task"="c:\program\QuickTime\qttask.exe" [2010-03-17 421888]

"iTunesHelper"="c:\program\iTunes\iTunesHelper.exe" [2010-04-28 142120]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]

 

c:\documents and settings\All Users\Start-meny\Program\Autostart\

Adobe Gamma Loader.lnk - c:\program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe [2009-10-30 110592]

Windows Search.lnk - c:\program\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ lsdelete

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program\\Delade filer\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=

"c:\\Program\\BitComet\\BitComet.exe"=

"c:\\Program\\Spotify\\spotify.exe"=

"c:\\Program\\Warcraft II BNE\\Warcraft II BNE.exe"=

"c:\\Program\\Malwarebytes' Anti-Malware\\mbam.exe"=

"c:\\Program\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program\\Windows Live\\Sync\\WindowsLiveSync.exe"=

"c:\\Program\\DC++\\DCPlusPlus.exe"=

"c:\\Program\\Bonjour\\mDNSResponder.exe"=

"c:\\Program\\iTunes\\iTunes.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"5353:TCP"= 5353:TCP:Adobe CSI CS4

"7303:TCP"= 7303:TCP:BitComet 7303 TCP

"7303:UDP"= 7303:UDP:BitComet 7303 UDP

 

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-03-25 64288]

R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program\Lavasoft\Ad-Aware\AAWService.exe [2010-07-12 1355416]

R2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2010-08-11 2789672]

R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\l151x86.sys [2009-10-23 39424]

R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [2009-06-04 171032]

R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [2009-06-04 1324056]

R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [2009-06-04 72728]

R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2009-11-18 15656]

S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program\Delade filer\Creative Labs Shared\Service\CTAELicensing.exe [2009-10-23 79360]

S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [2009-06-04 171032]

S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [2009-06-04 1324056]

S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [2009-06-04 72728]

S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program\Lavasoft\Ad-Aware\kernexplorer.sys [2010-08-12 15008]

S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2009-12-02 691696]

.

Innehållet i mappen 'Schemalagda aktiviteter':

 

2010-08-15 c:\windows\Tasks\Ad-Aware Update (Weekly).job

- c:\program\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-07-12 20:13]

 

2010-07-30 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program\Apple Software Update\SoftwareUpdate.exe [2007-08-29 11:34]

 

2010-08-15 c:\windows\Tasks\User_Feed_Synchronization-{8549F50F-53DC-4CE4-A61C-F9C05D34D743}.job

- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]

.

.

------- Extra genomsökning -------

.

uStart Page = hxxp://www.google.se/

mWindow Title = Erhållen av Wermlandsdata

uInternet Settings,ProxyOverride = <local>

IE: &D&ownload &with BitComet - c:\program\BitComet\BitComet.exe/AddLink.htm

IE: &D&ownload all video with BitComet - c:\program\BitComet\BitComet.exe/AddVideo.htm

IE: &D&ownload all with BitComet - c:\program\BitComet\BitComet.exe/AddAllLink.htm

DPF: {6CCE3920-3183-4B3D-808A-B12EB769DE12} - hxxp://www.commandondemand.com/eval/cod/cabs/cssweb.cab

DPF: {E6BB2089-163F-466B-812A-748096614DFD} - hxxp://cainternetsecurity.net/scanner/cascanner.cab

FF - ProfilePath - c:\documents and settings\Anvädaren\Application Data\Mozilla\Firefox\Profiles\40amxa4k.default\

FF - plugin: c:\program\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll

FF - plugin: c:\program\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll

FF - plugin: c:\program\Windows Live\Photo Gallery\NPWLPG.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

 

---- FIREFOX POLICY ----

c:\program\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);

c:\program\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);

c:\program\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);

c:\program\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);

c:\program\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net'>http://www.gmer.net

Rootkit scan 2010-08-15 11:52

Windows 5.1.2600 Service Pack 3 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

CTxfiHlp = CTXFIHLP.EXE?

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

 

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

 

device: opened successfully

user: MBR read successfully

called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys >>UNKNOWN [0x8A874A17]<<

kernel: MBR read successfully

detected MBR rootkit hooks:

\Driver\Disk -> CLASSPNP.SYS @ 0xba0ecf28

\Driver\ACPI -> ACPI.sys @ 0xb9f7fcb8

\Driver\atapi -> atapi.sys @ 0xb9f37852

IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8

ParseProcedure -> ntkrnlpa.exe @ 0x805827e8

\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8

ParseProcedure -> ntkrnlpa.exe @ 0x805827e8

NDIS: Atheros L1 Gigabit Ethernet 10/100/1000Base-T Controller -> SendCompleteHandler -> NDIS.sys @ 0xb9e30bb0

PacketIndicateHandler -> NDIS.sys @ 0xb9e1fa0d

SendHandler -> NDIS.sys @ 0xb9e33b40

user & kernel MBR OK

 

**************************************************************************

.

--------------------- LÅSTA REGISTERNYCKLAR ---------------------

 

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•6~*]

"D140211900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

.

--------------------- DLLer som "laddats" under processer som körs ---------------------

 

- - - - - - - > 'winlogon.exe'(516)

c:\program\Delade filer\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

.

Sluttid: 2010-08-15 11:55:29

ComboFix-quarantined-files.txt 2010-08-15 09:55

ComboFix2.txt 2010-08-07 08:20

ComboFix3.txt 2010-08-04 18:04

ComboFix4.txt 2010-07-22 17:27

ComboFix5.txt 2010-08-15 09:30

 

Före genomsökningen: 18 040 676 352 byte ledigt

Efter genomsökningen: 18 035 429 376 byte ledigt

 

Current=9 Default=9 Failed=8 LastKnownGood=10 Sets=1,2,3,4,5,6,7,8,9,10

- - End Of File - - C9A9F1EC510773AA5BFF87189B7558C8

Länk till kommentar
Dela på andra webbplatser

Det blir väldigt tidsödande det här när det dröjer så länge mellan gångerna. Det är också så att datorn inte bör användas till annat än rensning och särskilt bör inga program installeras. Enligt loggen har något Tablet-program installerats i augusti.

 

ComboFix-programmet är 5 dagar gammalt redan.

 

\\.\C: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS)

\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)

232 GB \\.\PhysicalDrive1 MBR Code Faked!

SHA1: 73D0B9F01FD4F36F44A5EDC33E3160FB277FCB92

232 GB \\.\PhysicalDrive0 Windows XP MBR code detected

SHA1: EEC098E77D0529BD75F64F7B26552C1BA4417B73

Är det så att BIOS startar från hårddisken med D:? D: innehåller en standard MBR men inte C:.

 

Om datorn startas från C: måste jag undersöka hur dess MBR ser ut egentligen för att veta om den är infekterad.

 

Kör MBRCheck.

Vänta tills texten "Enter 'Y' and hit ENTER for more options, or 'N' to exit:" visas. Tryck Y följt av Enter.

Texten "Enter your choice:" visas. Tryck 1 följt av Enter.

Tryck 1 och Enter för att göra en dump av MBR på C:.

 

Därefter kommer en fråga om i vilken mapp dumpfilen ska skapas och vad den ska heta. Du kan t ex skriva in C:\mbrastro.txt följt av Enter.

 

När det är klart tryck på Enter. En loggfil skapas på Skrivbordet som heter MBRCheckxxxxxx.txt där xxxxxx är klockslaget för körningen. Klistra in dess innehåll i ditt svar.

 

Dumpfilen C:\mbrastro.txt ska du bifoga till ditt svar.

Länk till kommentar
Dela på andra webbplatser

Japp vi ska försöka skynda på oss här från vårt håll. :)

 

Japp han va illa tvungen att installera en tablet för att han skulle jobba hemmifrån någon dag där.

 

Ja de är nåt skumt med de där, datorn vart inlämnad en gång och då vart de att Windows startarde på D: men han skulle ändra de till C: och sa att de skulle vara fixat. (Att de va Windows filer på D: som inte användes och som han skulle ta bort.)

 

 

 

MBRCheck, version 1.2.3

© 2010, AD

 

Command-line:

Windows Version: Windows XP Home Edition

Windows Information: Service Pack 3 (build 2600)

Logical Drives Mask: 0x000007fc

 

Kernel Drivers (total 135):

0x804D7000 \WINDOWS\system32\ntkrnlpa.exe

0x806E4000 \WINDOWS\system32\hal.dll

0x8A6DC000 \WINDOWS\system32\KDCOM.DLL

0xBA4BC000 \WINDOWS\system32\BOOTVID.dll

0xB9F79000 ACPI.sys

0xBA5A8000 \WINDOWS\system32\DRIVERS\WMILIB.SYS

0xB9F68000 pci.sys

0xBA0A8000 isapnp.sys

0xBA5AA000 avgarkt.sys

0xBA670000 pciide.sys

0xBA328000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS

0xBA0B8000 MountMgr.sys

0xB9F49000 ftdisk.sys

0xBA330000 PartMgr.sys

0xBA0C8000 VolSnap.sys

0xB9F31000 atapi.sys

0xBA0D8000 disk.sys

0xBA0E8000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS

0xB9F11000 fltMgr.sys

0xB9EFF000 sr.sys

0xBA0F8000 Lbd.sys

0xBA108000 PxHelp20.sys

0xB9EE8000 KSecDD.sys

0xB9ED5000 WudfPf.sys

0xB9E48000 Ntfs.sys

0xB9E1B000 NDIS.sys

0xB9E01000 Mup.sys

0xBA208000 \SystemRoot\system32\DRIVERS\intelppm.sys

0xB96A3000 \SystemRoot\system32\DRIVERS\nv4_mini.sys

0xB968F000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS

0xB9667000 \SystemRoot\system32\DRIVERS\HDAudBus.sys

0xBA218000 \SystemRoot\system32\DRIVERS\l151x86.sys

0xBA3B8000 \SystemRoot\system32\DRIVERS\usbuhci.sys

0xB9643000 \SystemRoot\system32\DRIVERS\USBPORT.SYS

0xBA3C0000 \SystemRoot\system32\DRIVERS\usbehci.sys

0xB95C4000 \SystemRoot\system32\drivers\ctaud2k.sys

0xB95A0000 \SystemRoot\system32\drivers\portcls.sys

0xBA228000 \SystemRoot\system32\drivers\drmk.sys

0xB957D000 \SystemRoot\system32\drivers\ks.sys

0xB9548000 \SystemRoot\system32\drivers\ctoss2k.sys

0xBA3C8000 \SystemRoot\system32\drivers\ctprxy2k.sys

0xBA238000 \SystemRoot\system32\DRIVERS\serial.sys

0xBA568000 \SystemRoot\system32\DRIVERS\serenum.sys

0xB9534000 \SystemRoot\system32\DRIVERS\parport.sys

0xBA5C2000 \SystemRoot\system32\DRIVERS\ASACPI.sys

0xBA248000 \SystemRoot\system32\DRIVERS\cdrom.sys

0xBA258000 \SystemRoot\system32\DRIVERS\redbook.sys

0xBA3D8000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys

0xBA268000 \SystemRoot\system32\DRIVERS\imapi.sys

0xBA5C4000 \SystemRoot\system32\DRIVERS\wacomvhid.sys

0xBA278000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS

0xBA3E0000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS

0xBA5C6000 \SystemRoot\system32\DRIVERS\WacomVKHid.sys

0xBA772000 \SystemRoot\system32\DRIVERS\audstub.sys

0xBA288000 \SystemRoot\system32\DRIVERS\rasl2tp.sys

0xBA57C000 \SystemRoot\system32\DRIVERS\ndistapi.sys

0xB951D000 \SystemRoot\system32\DRIVERS\ndiswan.sys

0xBA298000 \SystemRoot\system32\DRIVERS\raspppoe.sys

0xBA2A8000 \SystemRoot\system32\DRIVERS\raspptp.sys

0xBA3E8000 \SystemRoot\system32\DRIVERS\TDI.SYS

0xB9444000 \SystemRoot\system32\DRIVERS\psched.sys

0xBA2B8000 \SystemRoot\system32\DRIVERS\msgpc.sys

0xBA3F0000 \SystemRoot\system32\DRIVERS\ptilink.sys

0xBA3F8000 \SystemRoot\system32\DRIVERS\raspti.sys

0xBA2C8000 \SystemRoot\system32\DRIVERS\termdd.sys

0xBA400000 \SystemRoot\system32\DRIVERS\kbdclass.sys

0xBA408000 \SystemRoot\system32\DRIVERS\mouclass.sys

0xBA5C8000 \SystemRoot\system32\DRIVERS\swenum.sys

0xB93E6000 \SystemRoot\system32\DRIVERS\update.sys

0xBA588000 \SystemRoot\system32\DRIVERS\mssmbios.sys

0xBA5A0000 \SystemRoot\system32\DRIVERS\mouhid.sys

0xBA418000 \SystemRoot\system32\DRIVERS\wacommousefilter.sys

0xB9DD9000 \SystemRoot\system32\DRIVERS\kbdhid.sys

0xBA308000 \SystemRoot\System32\Drivers\NDProxy.SYS

0xB6E68000 \SystemRoot\system32\drivers\RtkHDAud.sys

0xBA158000 \SystemRoot\system32\DRIVERS\usbhub.sys

0xBA5E6000 \SystemRoot\system32\DRIVERS\USBD.SYS

0xB2ADD000 \SystemRoot\system32\drivers\ha20x2k.sys

0xB2AAD000 \SystemRoot\system32\drivers\emupia2k.sys

0xB2A84000 \SystemRoot\system32\drivers\ctsfm2k.sys

0xB29E8000 \SystemRoot\system32\drivers\ctac32k.sys

0xB29D3000 \SystemRoot\System32\drivers\CTHWIUT.SYS

0xB29A7000 \SystemRoot\System32\drivers\CT20XUT.SYS

0xB2860000 \SystemRoot\System32\drivers\CTEXFIFX.SYS

0xBA5F6000 \SystemRoot\System32\Drivers\Fs_Rec.SYS

0xBA7CE000 \SystemRoot\System32\Drivers\Null.SYS

0xBA5F8000 \SystemRoot\System32\Drivers\Beep.SYS

0xBA7D0000 \SystemRoot\System32\DRIVERS\AvgArCln.sys

0xBA460000 \SystemRoot\System32\drivers\vga.sys

0xBA5FA000 \SystemRoot\System32\Drivers\mnmdd.SYS

0xBA5FC000 \SystemRoot\System32\DRIVERS\RDPCDD.sys

0xBA468000 \SystemRoot\System32\Drivers\Msfs.SYS

0xBA470000 \SystemRoot\System32\Drivers\Npfs.SYS

0xB72C6000 \SystemRoot\system32\DRIVERS\rasacd.sys

0xB282D000 \SystemRoot\system32\DRIVERS\ipsec.sys

0xB27D4000 \SystemRoot\system32\DRIVERS\tcpip.sys

0xBA178000 \SystemRoot\System32\Drivers\aswTdi.SYS

0xB2786000 \SystemRoot\system32\DRIVERS\ipnat.sys

0xB275E000 \SystemRoot\system32\DRIVERS\netbt.sys

0xB273C000 \SystemRoot\System32\drivers\afd.sys

0xBA188000 \SystemRoot\system32\DRIVERS\netbios.sys

0xB2711000 \SystemRoot\system32\DRIVERS\rdbss.sys

0xB26A1000 \SystemRoot\system32\DRIVERS\mrxsmb.sys

0xBA198000 \SystemRoot\System32\Drivers\Fips.SYS

0xB267A000 \SystemRoot\System32\Drivers\aswSP.SYS

0xBA3A0000 \SystemRoot\System32\Drivers\Aavmker4.SYS

0xBA3D0000 \SystemRoot\system32\DRIVERS\usbccgp.sys

0xBA1B8000 \SystemRoot\system32\DRIVERS\wanarp.sys

0xBA1C8000 \SystemRoot\System32\Drivers\Cdfs.SYS

0xB6E18000 \SystemRoot\system32\DRIVERS\hidusb.sys

0xBA420000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS

0xBA428000 \SystemRoot\system32\DRIVERS\wacmoumonitor.sys

0xB259A000 \SystemRoot\System32\Drivers\dump_atapi.sys

0xBA61A000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS

0xBF800000 \SystemRoot\System32\win32k.sys

0xBA590000 \SystemRoot\System32\drivers\Dxapi.sys

0xBA458000 \SystemRoot\System32\watchdog.sys

0xBF000000 \SystemRoot\System32\drivers\dxg.sys

0xBA779000 \SystemRoot\System32\drivers\dxgthk.sys

0xBF012000 \SystemRoot\System32\nv4_disp.dll

0xBFFA0000 \SystemRoot\System32\ATMFD.DLL

0xB2372000 \SystemRoot\System32\Drivers\aswFsBlk.SYS

0xB25C2000 \SystemRoot\system32\DRIVERS\fssfltr_tdi.sys

0xB225A000 \SystemRoot\system32\DRIVERS\ndisuio.sys

0xB1FEB000 \SystemRoot\System32\Drivers\aswMon2.SYS

0xB11E0000 \SystemRoot\system32\drivers\wdmaud.sys

0xB209A000 \SystemRoot\system32\drivers\sysaudio.sys

0xB0FA5000 \SystemRoot\system32\DRIVERS\mrxdav.sys

0xBA60A000 \SystemRoot\System32\Drivers\ParVdm.SYS

0xB0F94000 \SystemRoot\System32\Drivers\adfs.SYS

0xB0E4D000 \SystemRoot\system32\DRIVERS\srv.sys

0xB02BF000 \SystemRoot\System32\Drivers\HTTP.sys

0xB1F7B000 \SystemRoot\System32\Drivers\aswRdr.SYS

0xAD0A6000 \SystemRoot\system32\drivers\kmixer.sys

0x7C900000 \WINDOWS\system32\ntdll.dll

 

Processes (total 48):

0 System Idle Process

4 System

448 C:\WINDOWS\system32\smss.exe

672 csrss.exe

696 C:\WINDOWS\system32\winlogon.exe

744 C:\WINDOWS\system32\services.exe

756 C:\WINDOWS\system32\lsass.exe

932 C:\WINDOWS\system32\svchost.exe

1008 svchost.exe

1124 C:\WINDOWS\system32\svchost.exe

1192 C:\WINDOWS\system32\svchost.exe

1396 svchost.exe

1432 svchost.exe

1624 C:\WINDOWS\explorer.exe

1744 C:\Program\Alwil Software\Avast5\AvastSvc.exe

1848 C:\WINDOWS\RTHDCPL.exe

1872 C:\Program\Creative\Volume Panel\VolPanlu.exe

1880 C:\WINDOWS\system32\Ctxfihlp.exe

1888 C:\Program\Delade filer\Java\Java Update\jusched.exe

2000 C:\Program\iTunes\iTunesHelper.exe

2012 C:\Program\ALWILS~1\Avast5\AvastUI.exe

2040 C:\Program\Windows Desktop Search\WindowsSearch.exe

1100 C:\WINDOWS\system32\spoolsv.exe

1336 C:\Program\Creative\Shared Files\CTAudSvc.exe

1936 C:\WINDOWS\system32\CTxfispi.exe

1276 svchost.exe

1464 C:\Program\Delade filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe

1136 C:\Program\Bonjour\mDNSResponder.exe

2080 C:\WINDOWS\system32\CTSVCCDA.EXE

2188 C:\Program\Java\jre6\bin\jqs.exe

2240 C:\WINDOWS\system32\nvsvc32.exe

2304 C:\WINDOWS\system32\HPZipm12.exe

2336 C:\Program\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

2460 C:\WINDOWS\system32\svchost.exe

2556 C:\WINDOWS\system32\Wacom_Tablet.exe

2744 C:\WINDOWS\system32\searchindexer.exe

2788 C:\WINDOWS\system32\WTablet\Wacom_TabletUser.exe

2900 C:\WINDOWS\system32\Wacom_Tablet.exe

3308 C:\Program\iPod\bin\iPodService.exe

3744 alg.exe

3480 C:\Program\Internet Explorer\iexplore.exe

2656 C:\Program\Internet Explorer\iexplore.exe

2156 C:\WINDOWS\system32\ctfmon.exe

228 C:\WINDOWS\system32\searchprotocolhost.exe

1108 searchfilterhost.exe

408 C:\Program\Windows Live\Messenger\msnmsgr.exe

3188 C:\Program\Windows Live\Contacts\wlcomm.exe

772 C:\Documents and Settings\Anvädaren\Skrivbord\MBRCheck.exe

 

\\.\C: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS)

\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)

 

PhysicalDrive1 Model Number: ST3250824AS, Rev: 3.AAE

PhysicalDrive0 Model Number: ST3250824AS, Rev: 3.AAE

 

Size Device Name MBR Status

--------------------------------------------

232 GB \\.\PhysicalDrive1 MBR Code Faked!

SHA1: 73D0B9F01FD4F36F44A5EDC33E3160FB277FCB92

232 GB \\.\PhysicalDrive0 Windows XP MBR code detected

SHA1: EEC098E77D0529BD75F64F7B26552C1BA4417B73

 

 

Found non-standard or infected MBR.

Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Options:

[1] Dump the MBR of a physical disk to file.

[2] Restore the MBR of a physical disk with a standard boot code.

[3] Exit.

 

Enter your choice: Enter the physical disk number to dump (0-99, -1 to exit): 1Dumping \\.\PhysicalDisk1...

Enter filename to dump to: C:\mbrastro.txtDumped successfully!

 

Enter the physical disk number to dump (0-99, -1 to exit):

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Själva dump filen blev nog nåt knas med men vi lyckas inte fixa de riktigt heller tror jag men jag skickar med det som blev för säkerhetsskull. Vi följde anvisningarna såklart, men efter åt att när vi kommit till punkten att vi skulle döpa filen så kom de upp att de va dump successfully, men att man skulle välja fysisk disk igen (1 till 99).

mbrastro.txt

Länk till kommentar
Dela på andra webbplatser

Det ser ut som att ni lyckades få till dmp-filen i alla fall. :)

 

Då är det säkert så att det är MBR på D: som används numera och den är ju helt normal.

 

1.

Spara TDSSKiller på Skrivbordet:

http://support.kaspersky.com/downloads/utils/tdsskiller.zip

 

Högerklicka och välj Extrahera alla. Se till att uppackningen sker till Skrivbordet. Alternativt så kan du använda ditt eget program för att packa upp zip-filer, se bara till att filen tdsskiller.exe hamnar på Skrivbordet.

 

Stäng av så många program som möjligt.

 

Start - Kör

Kopiera raden som är i rutan

"%userprofile%\skrivbord\TDSSKiller.exe" -l rapport.txt

Öppna filen "rapport" som skapades i C:\ eller på Skrivbordet och klistra in innehållet i ditt svar.

 

2.

Spara mbr.exe på Skrivbordet:

http://www2.gmer.net/mbr/mbr.exe

Dra ur internetanslutningen och inaktivera/stäng av antivirus- och andra säkerhetsprogram.

Kör mbr.exe.

Klistra in innehållet i mbr.log som skapas på Skrivbordet.

 

Kör sedan mbr.exe på detta alternativa vis:

Start - Kör

Kopiera raden som är i rutan

"%userprofile%\skrivbord\mbr.exe" -t > ""%userprofile%\skrivbord\mbrt.txt"

Klistra in innehållet i mbrt.txt som skapades på skrivbordet.

Länk till kommentar
Dela på andra webbplatser

Ahaa de va ju bra, den såg nämligen rätt knepigt ut, från vårat perspektiv iaf. :)

 

Dom där raderna, ska man klistra in dom i loggarna som dyker upp eller vad? :) Eller i programmen nånstans?

 

 

EDIT; nej nu tror jag att jag fatta, bara klistra in i kör förmodar jag, doh! :)

Länk till kommentar
Dela på andra webbplatser

2010/08/18 08:21:00.0281 TDSS rootkit removing tool 2.4.1.2 Aug 16 2010 09:46:23

2010/08/18 08:21:00.0281 ================================================================================

2010/08/18 08:21:00.0281 SystemInfo:

2010/08/18 08:21:00.0281

2010/08/18 08:21:00.0281 OS Version: 5.1.2600 ServicePack: 3.0

2010/08/18 08:21:00.0281 Product type: Workstation

2010/08/18 08:21:00.0281 ComputerName: ANV-242AF29E931

2010/08/18 08:21:00.0281 UserName: Anvädaren

2010/08/18 08:21:00.0281 Windows directory: C:\WINDOWS

2010/08/18 08:21:00.0281 System windows directory: C:\WINDOWS

2010/08/18 08:21:00.0281 Processor architecture: Intel x86

2010/08/18 08:21:00.0281 Number of processors: 2

2010/08/18 08:21:00.0281 Page size: 0x1000

2010/08/18 08:21:00.0281 Boot type: Normal boot

2010/08/18 08:21:00.0281 ================================================================================

2010/08/18 08:21:00.0671 Initialize success

2010/08/18 08:21:45.0625 ================================================================================

2010/08/18 08:21:45.0625 Scan started

2010/08/18 08:21:45.0625 Mode: Manual;

2010/08/18 08:21:45.0625 ================================================================================

2010/08/18 08:21:46.0312 Aavmker4 (467f062f76e07512ecc1f5f60aab2988) C:\WINDOWS\system32\drivers\Aavmker4.sys

2010/08/18 08:21:46.0609 ACPI (48547e29772befe3c554ff5e4855bf51) C:\WINDOWS\system32\DRIVERS\ACPI.sys

2010/08/18 08:21:46.0640 ACPIEC (decedc736cef3c0fff6e981b31e73a61) C:\WINDOWS\system32\drivers\ACPIEC.sys

2010/08/18 08:21:46.0671 adfs (6d7f09cd92a9fef3a8efce66231fdd79) C:\WINDOWS\system32\drivers\adfs.sys

2010/08/18 08:21:46.0703 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys

2010/08/18 08:21:46.0750 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys

2010/08/18 08:21:46.0906 aswFsBlk (0c0b08847f2f24baa7bd43d8f2c6c8b0) C:\WINDOWS\system32\drivers\aswFsBlk.sys

2010/08/18 08:21:46.0937 aswMon2 (aa504fa592c9ed79174cb06b8ae340aa) C:\WINDOWS\system32\drivers\aswMon2.sys

2010/08/18 08:21:46.0968 aswRdr (f385ffd39165453fda96736aa3edfd9d) C:\WINDOWS\system32\drivers\aswRdr.sys

2010/08/18 08:21:47.0000 aswSP (45adea26bf613a54fed64ecdd12e58a7) C:\WINDOWS\system32\drivers\aswSP.sys

2010/08/18 08:21:47.0015 aswTdi (c4ee975c87176f1900662d2874233c7f) C:\WINDOWS\system32\drivers\aswTdi.sys

2010/08/18 08:21:47.0046 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys

2010/08/18 08:21:47.0109 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys

2010/08/18 08:21:47.0140 AtcL001 (cf63c4060f86350feb84555aef80ef6d) C:\WINDOWS\system32\DRIVERS\l151x86.sys

2010/08/18 08:21:47.0171 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys

2010/08/18 08:21:47.0218 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys

2010/08/18 08:21:47.0343 AVG Anti-Rootkit (e8054a423e5d2bdae6062bab6da159c4) C:\WINDOWS\system32\DRIVERS\avgarkt.sys

2010/08/18 08:21:47.0406 AvgArCln (ec08d1625f5c6cf2a57b79eb35186f8c) C:\WINDOWS\system32\DRIVERS\AvgArCln.sys

2010/08/18 08:21:47.0437 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys

2010/08/18 08:21:47.0593 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys

2010/08/18 08:21:47.0640 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys

2010/08/18 08:21:47.0671 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys

2010/08/18 08:21:47.0703 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys

2010/08/18 08:21:47.0812 CT20XUT (134cdd242af1ae9961f065fba3508a7b) C:\WINDOWS\system32\drivers\CT20XUT.SYS

2010/08/18 08:21:47.0828 CT20XUT.SYS (134cdd242af1ae9961f065fba3508a7b) C:\WINDOWS\System32\drivers\CT20XUT.SYS

2010/08/18 08:21:47.0875 ctac32k (93439baf09ce3c6d4ce55da5b07d1b6a) C:\WINDOWS\system32\drivers\ctac32k.sys

2010/08/18 08:21:47.0906 ctaud2k (6ab74512f09d673452d63ddec9014db5) C:\WINDOWS\system32\drivers\ctaud2k.sys

2010/08/18 08:21:47.0953 ctdvda2k (788db5d99b2ca44ff61d8ed7b3c67c2e) C:\WINDOWS\system32\drivers\ctdvda2k.sys

2010/08/18 08:21:48.0015 CTEXFIFX (3a9ad039d94be8d955ad0b2cb207378d) C:\WINDOWS\system32\drivers\CTEXFIFX.SYS

2010/08/18 08:21:48.0125 CTEXFIFX.SYS (3a9ad039d94be8d955ad0b2cb207378d) C:\WINDOWS\System32\drivers\CTEXFIFX.SYS

2010/08/18 08:21:48.0140 CTHWIUT (4602ad8c8e1b285e1a23a957f487da86) C:\WINDOWS\system32\drivers\CTHWIUT.SYS

2010/08/18 08:21:48.0156 CTHWIUT.SYS (4602ad8c8e1b285e1a23a957f487da86) C:\WINDOWS\System32\drivers\CTHWIUT.SYS

2010/08/18 08:21:48.0171 ctprxy2k (d42b84671f2193330215d3c375a2e948) C:\WINDOWS\system32\drivers\ctprxy2k.sys

2010/08/18 08:21:48.0203 ctsfm2k (974cfcbe3206367bec1d527d9dade998) C:\WINDOWS\system32\drivers\ctsfm2k.sys

2010/08/18 08:21:48.0265 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys

2010/08/18 08:21:48.0312 dmboot (80008bd0c19d97b0b3f4d1d9cbf190a8) C:\WINDOWS\system32\drivers\dmboot.sys

2010/08/18 08:21:48.0390 dmio (41862731f82be80f0cfba5d0da36b683) C:\WINDOWS\system32\drivers\dmio.sys

2010/08/18 08:21:48.0453 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys

2010/08/18 08:21:48.0500 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys

2010/08/18 08:21:48.0531 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys

2010/08/18 08:21:48.0562 emupia (04afe5c11777e33178ec11e1fac47b07) C:\WINDOWS\system32\drivers\emupia2k.sys

2010/08/18 08:21:48.0625 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys

2010/08/18 08:21:48.0671 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys

2010/08/18 08:21:48.0703 Fips (b66ddb75642f6722468707840c67a394) C:\WINDOWS\system32\drivers\Fips.sys

2010/08/18 08:21:48.0734 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys

2010/08/18 08:21:48.0796 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys

2010/08/18 08:21:48.0843 fssfltr (c6ee3a87fe609d3e1db9dbd072a248de) C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys

2010/08/18 08:21:48.0875 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys

2010/08/18 08:21:48.0937 Ftdisk (45fc410cfe68ff036ad232a141e69c19) C:\WINDOWS\system32\DRIVERS\ftdisk.sys

2010/08/18 08:21:48.0984 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys

2010/08/18 08:21:49.0015 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys

2010/08/18 08:21:49.0078 ha20x2k (41fce1833d8f659acc56cb0ee43b2ced) C:\WINDOWS\system32\drivers\ha20x2k.sys

2010/08/18 08:21:49.0109 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys

2010/08/18 08:21:49.0140 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys

2010/08/18 08:21:49.0203 HPZid412 (9f1d80908658eb7f1bf70809e0b51470) C:\WINDOWS\system32\DRIVERS\HPZid412.sys

2010/08/18 08:21:49.0218 HPZipr12 (f7e3e9d50f9cd3de28085a8fdaa0a1c3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys

2010/08/18 08:21:49.0234 HPZius12 (cf1b7951b4ec8d13f3c93b74bb2b461b) C:\WINDOWS\system32\DRIVERS\HPZius12.sys

2010/08/18 08:21:49.0296 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys

2010/08/18 08:21:49.0359 i8042prt (82e56cd09b2ce1edec3fba9111c7ee3a) C:\WINDOWS\system32\DRIVERS\i8042prt.sys

2010/08/18 08:21:49.0406 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys

2010/08/18 08:21:49.0593 IntcAzAudAddService (e37589414437a60797e94c0f57c546db) C:\WINDOWS\system32\drivers\RtkHDAud.sys

2010/08/18 08:21:49.0640 intelppm (02431778e84a525d29929d14bab71d53) C:\WINDOWS\system32\DRIVERS\intelppm.sys

2010/08/18 08:21:49.0703 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys

2010/08/18 08:21:49.0734 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys

2010/08/18 08:21:49.0765 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys

2010/08/18 08:21:49.0812 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys

2010/08/18 08:21:49.0859 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys

2010/08/18 08:21:49.0906 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys

2010/08/18 08:21:49.0953 isapnp (48f97c77daf8811598cfae21368eacb6) C:\WINDOWS\system32\DRIVERS\isapnp.sys

2010/08/18 08:21:49.0984 Kbdclass (d655ca94c8e2e0223c1bc28bcd95723a) C:\WINDOWS\system32\DRIVERS\kbdclass.sys

2010/08/18 08:21:50.0000 kbdhid (e1e28876fe7602b0a1d040354de35c06) C:\WINDOWS\system32\DRIVERS\kbdhid.sys

2010/08/18 08:21:50.0031 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys

2010/08/18 08:21:50.0078 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys

2010/08/18 08:21:50.0171 Lavasoft Kernexplorer (32da3fde01f1bb080c2e69521dd8881e) C:\Program\Lavasoft\Ad-Aware\KernExplorer.sys

2010/08/18 08:21:50.0218 Lbd (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\WINDOWS\system32\DRIVERS\Lbd.sys

2010/08/18 08:21:50.0250 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys

2010/08/18 08:21:50.0296 Modem (42ce19726d9c410dff75d3ff1cc79db2) C:\WINDOWS\system32\drivers\Modem.sys

2010/08/18 08:21:50.0328 Mouclass (e0c4c36573bcf0c0d2a1578caa791f7d) C:\WINDOWS\system32\DRIVERS\mouclass.sys

2010/08/18 08:21:50.0359 mouhid (98e474ecf11f1db62fb072157a95ea83) C:\WINDOWS\system32\DRIVERS\mouhid.sys

2010/08/18 08:21:50.0390 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys

2010/08/18 08:21:50.0437 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys

2010/08/18 08:21:50.0515 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys

2010/08/18 08:21:50.0531 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys

2010/08/18 08:21:50.0578 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys

2010/08/18 08:21:50.0593 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys

2010/08/18 08:21:50.0609 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys

2010/08/18 08:21:50.0671 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys

2010/08/18 08:21:50.0687 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS\system32\DRIVERS\ASACPI.sys

2010/08/18 08:21:50.0734 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys

2010/08/18 08:21:50.0781 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys

2010/08/18 08:21:50.0828 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys

2010/08/18 08:21:50.0859 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys

2010/08/18 08:21:50.0890 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys

2010/08/18 08:21:50.0906 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys

2010/08/18 08:21:50.0953 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys

2010/08/18 08:21:51.0000 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys

2010/08/18 08:21:51.0078 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys

2010/08/18 08:21:51.0125 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys

2010/08/18 08:21:51.0156 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys

2010/08/18 08:21:51.0390 nv (3712d332633b853101ab786380c969ec) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys

2010/08/18 08:21:51.0578 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys

2010/08/18 08:21:51.0593 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys

2010/08/18 08:21:51.0640 ossrv (11b3328d84ed6c11baf4f4f115459ab6) C:\WINDOWS\system32\drivers\ctoss2k.sys

2010/08/18 08:21:51.0671 Parport (19e28ed86e7244d76fda792c2810188e) C:\WINDOWS\system32\DRIVERS\parport.sys

2010/08/18 08:21:51.0703 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys

2010/08/18 08:21:51.0718 ParVdm (5cf71e14a108c492c1fb07543d579af5) C:\WINDOWS\system32\drivers\ParVdm.sys

2010/08/18 08:21:51.0781 PCI (8a185f0112cf5b42ff1aaff31b8b3091) C:\WINDOWS\system32\DRIVERS\pci.sys

2010/08/18 08:21:51.0828 PCIIde (239de4275ee40fdf9912761467025244) C:\WINDOWS\system32\DRIVERS\pciide.sys

2010/08/18 08:21:51.0859 Pcmcia (904053aa6e251c77cf85371ce644cfd7) C:\WINDOWS\system32\drivers\Pcmcia.sys

2010/08/18 08:21:51.0984 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys

2010/08/18 08:21:52.0000 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys

2010/08/18 08:21:52.0015 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys

2010/08/18 08:21:52.0062 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys

2010/08/18 08:21:52.0140 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys

2010/08/18 08:21:52.0171 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys

2010/08/18 08:21:52.0187 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys

2010/08/18 08:21:52.0218 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys

2010/08/18 08:21:52.0265 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys

2010/08/18 08:21:52.0296 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys

2010/08/18 08:21:52.0343 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys

2010/08/18 08:21:52.0390 redbook (97130d37842819fa39fd5f1e90a5d676) C:\WINDOWS\system32\DRIVERS\redbook.sys

2010/08/18 08:21:52.0484 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys

2010/08/18 08:21:52.0531 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys

2010/08/18 08:21:52.0593 Serial (f7d35464062edc08909e568bcd8ae77d) C:\WINDOWS\system32\DRIVERS\serial.sys

2010/08/18 08:21:52.0640 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys

2010/08/18 08:21:52.0703 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys

2010/08/18 08:21:52.0750 sptd (cdddec541bc3c96f91ecb48759673505) C:\WINDOWS\System32\Drivers\sptd.sys

2010/08/18 08:21:52.0812 sr (1193ef00869f6367367e6e7cb96be325) C:\WINDOWS\system32\DRIVERS\sr.sys

2010/08/18 08:21:52.0859 Srv (89220b427890aa1dffd1a02648ae51c3) C:\WINDOWS\system32\DRIVERS\srv.sys

2010/08/18 08:21:52.0906 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys

2010/08/18 08:21:52.0953 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys

2010/08/18 08:21:53.0015 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys

2010/08/18 08:21:53.0093 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys

2010/08/18 08:21:53.0140 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys

2010/08/18 08:21:53.0156 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys

2010/08/18 08:21:53.0203 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys

2010/08/18 08:21:53.0250 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys

2010/08/18 08:21:53.0312 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys

2010/08/18 08:21:53.0359 USBAAPL (e8c1b9ebac65288e1b51e8a987d98af6) C:\WINDOWS\system32\Drivers\usbaapl.sys

2010/08/18 08:21:53.0375 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys

2010/08/18 08:21:53.0421 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys

2010/08/18 08:21:53.0453 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys

2010/08/18 08:21:53.0500 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys

2010/08/18 08:21:53.0531 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys

2010/08/18 08:21:53.0562 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

2010/08/18 08:21:53.0578 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys

2010/08/18 08:21:53.0625 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys

2010/08/18 08:21:53.0671 VolSnap (57187ec04878147e1f4f2d9224b12205) C:\WINDOWS\system32\drivers\VolSnap.sys

2010/08/18 08:21:53.0718 wacmoumonitor (9a03558c37e919b9d6a50864aea0a168) C:\WINDOWS\system32\DRIVERS\wacmoumonitor.sys

2010/08/18 08:21:53.0750 wacommousefilter (427a8bc96f16c40df81c2d2f4edd32dd) C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys

2010/08/18 08:21:53.0781 wacomvhid (6843fd7db708b14ea4d8092abb464244) C:\WINDOWS\system32\DRIVERS\wacomvhid.sys

2010/08/18 08:21:53.0796 WacomVKHid (889459833432b161cb99cfdf84a1a9bb) C:\WINDOWS\system32\DRIVERS\WacomVKHid.sys

2010/08/18 08:21:53.0828 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys

2010/08/18 08:21:53.0875 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys

2010/08/18 08:21:53.0937 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys

2010/08/18 08:21:54.0015 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys

2010/08/18 08:21:54.0078 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys

2010/08/18 08:21:54.0125 ================================================================================

2010/08/18 08:21:54.0125 Scan finished

2010/08/18 08:21:54.0125 ================================================================================

2010/08/18 08:22:50.0968 Deinitialize success

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

 

device: opened successfully

user: MBR read successfully

kernel: MBR read successfully

user & kernel MBR OK

Länk till kommentar
Dela på andra webbplatser

Kör mbr.exe på detta alternativa vis:

Start - Kör

Kopiera raden som är i rutan nedan och klistra in i Kör-fältet.

 

"%userprofile%\skrivbord\mbr.exe" -t > ""%userprofile%\skrivbord\mbrt.txt"

 

Klistra in innehållet i mbrt.txt som skapades på skrivbordet.

 

Tillägg:

Ta bort den ComboFix du har och ladda ner en ny som du kör. Kör även DDS. Klistra in loggarna från båda programmen (men inte Attach.txt).

Länk till kommentar
Dela på andra webbplatser

Fårse vad detta visar;

 

 

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net'>http://www.gmer.net'>http://www.gmer.net

 

device: opened successfully

user: MBR read successfully

called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys >>UNKNOWN [0x8A86BA17]<<

kernel: MBR read successfully

user & kernel MBR OK

 

 

 

 

 

 

 

 

 

 

 

ComboFix 10-08-17.04 - Anvädaren 2010-08-19 8:17.10.2 - x86

Microsoft Windows XP Home Edition 5.1.2600.3.1252.46.1053.18.2047.1626 [GMT 2:00]

Körs från: c:\documents and settings\Anvädaren\Skrivbord\ComboFix.exe

.

 

(((((((((((((((((((((((( Filer Skapade från 2010-07-19 till 2010-08-19 ))))))))))))))))))))))))))))))

.

 

2010-08-12 05:08 . 2010-08-19 05:58 -------- d-----w- c:\documents and settings\LocalService\Application Data\WTablet

2010-08-11 10:06 . 2007-02-15 14:11 11440 ----a-w- c:\windows\system32\drivers\WacomVKHid.sys

2010-08-11 10:06 . 2008-07-11 09:16 13352 ----a-w- c:\windows\system32\drivers\wacomvhid.sys

2010-08-11 10:06 . 2007-02-16 09:12 11312 ----a-w- c:\windows\system32\drivers\wacommousefilter.sys

2010-08-11 10:05 . 2010-08-11 10:05 -------- d-----w- c:\windows\system32\WTablet

2010-08-11 10:05 . 2009-03-26 15:15 2789672 ----a-w- c:\windows\system32\Wacom_Tablet.exe

2010-08-11 10:05 . 2009-03-26 14:40 213288 ----a-w- c:\windows\system32\Wacom_Tablet.dll

2010-08-11 10:05 . 2009-03-26 14:10 172840 ----a-w- c:\windows\system32\Wintab32.dll

2010-08-11 10:05 . 2010-08-11 10:06 -------- d-----w- c:\program\Tablet

2010-08-03 17:34 . 2010-08-03 17:34 16968 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys

2010-08-03 17:33 . 2010-08-03 17:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Hitman Pro

2010-08-03 17:33 . 2010-08-03 17:33 -------- d-----w- c:\program\Hitman Pro 3.5

2010-08-03 06:03 . 2010-08-11 09:59 664 ----a-w- c:\windows\system32\d3d9caps.dat

2010-08-02 14:53 . 2010-08-02 14:53 0 ----a-w- c:\windows\nsreg.dat

2010-08-02 06:31 . 2010-08-02 07:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy

2010-08-02 06:31 . 2010-08-02 06:37 -------- d-----w- c:\program\Spybot - Search & Destroy

2010-08-02 06:16 . 2010-08-02 06:16 -------- d-----w- c:\program\Delade filer\Java

2010-08-02 06:16 . 2010-07-17 03:00 423656 ----a-w- c:\windows\system32\deployJava1.dll

2010-07-29 12:03 . 2010-07-29 12:03 -------- d-----r- c:\documents and settings\NetworkService\Favoriter

2010-07-24 11:09 . 2010-07-12 08:56 2979280 -c--a-w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}\Ad-AwareInstall.exe

2010-07-24 11:01 . 2010-07-24 11:09 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}

2010-07-23 11:53 . 2010-08-19 05:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software

2010-07-23 11:53 . 2010-07-23 11:53 -------- d-----w- c:\program\Alwil Software

2010-07-21 16:58 . 2010-07-21 16:58 -------- d-----w- c:\windows\system32\wbem\Repository

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-08-18 12:18 . 2009-10-30 09:38 -------- d-----w- c:\program\BitComet

2010-08-11 09:35 . 2009-12-02 17:24 -------- d-----w- c:\program\TabletPlugins

2010-08-02 07:06 . 2009-11-18 12:17 67072 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT

2010-08-02 06:19 . 2009-11-03 19:43 -------- d-----w- c:\program\HP

2010-08-02 06:17 . 2009-11-03 19:51 -------- d-----w- c:\program\Delade filer\HP

2010-08-02 06:15 . 2009-10-26 08:11 -------- d-----w- c:\program\Java

2010-07-20 08:30 . 2009-12-31 16:55 -------- d-----w- c:\program\Malwarebytes' Anti-Malware

2010-07-20 04:41 . 2009-10-28 17:21 -------- d-----w- c:\program\Norman

2010-07-19 20:04 . 2009-10-31 07:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft

2010-07-12 08:55 . 2010-03-25 06:40 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys

2010-07-12 08:55 . 2010-07-19 20:22 15880 ----a-w- c:\windows\system32\lsdelete.exe

2010-06-23 20:49 . 2008-04-15 12:00 92094 ----a-w- c:\windows\system32\perfc01D.dat

2010-06-23 20:49 . 2008-04-15 12:00 463742 ----a-w- c:\windows\system32\perfh01D.dat

2010-06-16 19:16 . 2010-06-16 19:16 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe

2010-06-14 14:31 . 2009-10-22 12:23 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe

2010-05-23 06:12 . 2009-11-10 06:59 8 ----a-w- c:\windows\system32\nvModes.dat

.

 

((((((((((((((((((((((((((((( SnapShot@2010-07-20_11.40.15 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-07-11 22:02 . 2009-07-11 22:02 51008 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90rus.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90kor.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90jpn.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90ita.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90fra.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 61760 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esp.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esn.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 53568 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 63296 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90deu.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90cht.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 35648 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90chs.dll

+ 2009-07-11 22:05 . 2009-07-11 22:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll

+ 2009-07-11 22:05 . 2009-07-11 22:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll

+ 2010-08-19 06:14 . 2010-08-19 06:14 16384 c:\windows\temp\Perflib_Perfdata_760.dat

+ 2010-07-24 11:22 . 2010-07-12 08:55 64288 c:\windows\system32\DRVSTORE\lbd_9C578CA880A99903668A8694DEFB21244E9C4C62\Lbd.sys

+ 2009-11-18 11:52 . 2008-10-06 09:53 15656 c:\windows\system32\drivers\wacmoumonitor.sys

+ 2001-09-06 19:55 . 2001-09-06 17:55 12160 c:\windows\system32\drivers\mouhid.sys

- 2001-09-06 19:55 . 2001-09-06 18:55 12160 c:\windows\system32\drivers\mouhid.sys

+ 2008-04-14 21:03 . 2008-04-14 19:03 23296 c:\windows\system32\drivers\mouclass.sys

- 2008-04-14 21:03 . 2008-04-14 20:03 23296 c:\windows\system32\drivers\mouclass.sys

- 2001-09-06 19:55 . 2001-09-06 18:55 12160 c:\windows\system32\dllcache\mouhid.sys

+ 2001-09-06 19:55 . 2001-09-06 17:55 12160 c:\windows\system32\dllcache\mouhid.sys

- 2008-04-14 21:03 . 2008-04-14 20:03 23296 c:\windows\system32\dllcache\mouclass.sys

+ 2008-04-14 21:03 . 2008-04-14 19:03 23296 c:\windows\system32\dllcache\mouclass.sys

+ 2009-07-11 22:02 . 2009-07-11 22:02 653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll

+ 2009-07-11 22:05 . 2009-07-11 22:05 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll

- 2009-07-11 23:02 . 2009-07-11 23:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll

+ 2010-08-11 10:05 . 2009-03-26 15:16 186664 c:\windows\system32\WTablet\Wacom_TabletUser.exe

+ 2009-11-13 14:56 . 2010-07-21 17:13 144476 c:\windows\system32\Restore\rstrlog.dat

+ 2010-07-24 05:44 . 2010-07-24 05:44 231888 c:\windows\system32\Macromed\Flash\FlashUtil10h_Plugin.exe

+ 2010-08-02 06:16 . 2010-07-17 03:00 153376 c:\windows\system32\javaws.exe

+ 2010-08-02 06:16 . 2010-07-17 03:00 145184 c:\windows\system32\javaw.exe

- 2009-10-26 08:38 . 2009-07-25 04:23 145184 c:\windows\system32\javaw.exe

+ 2010-08-02 06:15 . 2010-07-17 03:00 145184 c:\windows\system32\java.exe

- 2009-10-26 08:38 . 2009-07-25 04:23 145184 c:\windows\system32\java.exe

+ 2010-07-23 11:53 . 2010-07-23 11:53 219648 c:\windows\Installer\a68730.msi

+ 2010-08-02 06:16 . 2010-08-02 06:16 180224 c:\windows\Installer\1ca14.msi

+ 2009-07-11 22:02 . 2009-07-11 22:02 3780424 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 3765048 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90.dll

+ 2010-07-24 05:44 . 2010-07-24 05:44 5612496 c:\windows\system32\Macromed\Flash\NPSWF32.dll

+ 2009-10-22 14:15 . 2010-08-02 06:26 3488384 c:\windows\system32\FNTCACHE.DAT

+ 2010-07-24 11:09 . 2010-07-24 11:09 1866752 c:\windows\Installer\1b4db.msi

+ 2010-06-20 08:01 . 2010-06-20 08:01 8040960 c:\windows\Installer\145356.msp

.

(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Not* Tomma poster & legitima standardposter visas inte.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SpybotSD TeaTimer"="c:\program\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe" [2009-07-31 468408]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 16132608]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-06 8523776]

"nwiz"="nwiz.exe" [2007-11-06 1626112]

"VolPanel"="c:\program\Creative\Volume Panel\VolPanlu.exe" [2008-08-06 233576]

"CTxfiHlp"="CTXFIHLP.EXE" [2009-06-03 25600]

"SunJavaUpdateSched"="c:\program\Delade filer\Java\Java Update\jusched.exe" [2010-05-14 248552]

"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

"AdobeCS4ServiceManager"="c:\program\Delade filer\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]

"Adobe Reader Speed Launcher"="c:\program\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]

"Adobe ARM"="c:\program\Delade filer\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

"QuickTime Task"="c:\program\QuickTime\qttask.exe" [2010-03-17 421888]

"iTunesHelper"="c:\program\iTunes\iTunesHelper.exe" [2010-04-28 142120]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]

 

c:\documents and settings\All Users\Start-meny\Program\Autostart\

Adobe Gamma Loader.lnk - c:\program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe [2009-10-30 110592]

Windows Search.lnk - c:\program\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ lsdelete

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program\\Delade filer\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=

"c:\\Program\\BitComet\\BitComet.exe"=

"c:\\Program\\Spotify\\spotify.exe"=

"c:\\Program\\Warcraft II BNE\\Warcraft II BNE.exe"=

"c:\\Program\\Malwarebytes' Anti-Malware\\mbam.exe"=

"c:\\Program\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program\\Windows Live\\Sync\\WindowsLiveSync.exe"=

"c:\\Program\\DC++\\DCPlusPlus.exe"=

"c:\\Program\\Bonjour\\mDNSResponder.exe"=

"c:\\Program\\iTunes\\iTunes.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"5353:TCP"= 5353:TCP:Adobe CSI CS4

"7303:TCP"= 7303:TCP:BitComet 7303 TCP

"7303:UDP"= 7303:UDP:BitComet 7303 UDP

 

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-03-25 64288]

R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program\Lavasoft\Ad-Aware\AAWService.exe [2010-07-12 1355416]

R2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2010-08-11 2789672]

R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\l151x86.sys [2009-10-23 39424]

R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [2009-06-04 171032]

R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [2009-06-04 1324056]

R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [2009-06-04 72728]

R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2009-11-18 15656]

S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program\Delade filer\Creative Labs Shared\Service\CTAELicensing.exe [2009-10-23 79360]

S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [2009-06-04 171032]

S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [2009-06-04 1324056]

S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [2009-06-04 72728]

S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program\Lavasoft\Ad-Aware\kernexplorer.sys [2010-08-12 15008]

S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2009-12-02 691696]

.

Innehållet i mappen 'Schemalagda aktiviteter':

 

2010-08-19 c:\windows\Tasks\Ad-Aware Update (Weekly).job

- c:\program\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-07-12 20:13]

 

2010-07-30 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program\Apple Software Update\SoftwareUpdate.exe [2007-08-29 11:34]

 

2010-08-19 c:\windows\Tasks\User_Feed_Synchronization-{8549F50F-53DC-4CE4-A61C-F9C05D34D743}.job

- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]

.

.

------- Extra genomsökning -------

.

uStart Page = hxxp://www.google.se/

mWindow Title = Erhållen av Wermlandsdata

uInternet Settings,ProxyOverride = <local>

IE: &D&ownload &with BitComet - c:\program\BitComet\BitComet.exe/AddLink.htm

IE: &D&ownload all video with BitComet - c:\program\BitComet\BitComet.exe/AddVideo.htm

IE: &D&ownload all with BitComet - c:\program\BitComet\BitComet.exe/AddAllLink.htm

DPF: {6CCE3920-3183-4B3D-808A-B12EB769DE12} - hxxp://www.commandondemand.com/eval/cod/cabs/cssweb.cab

DPF: {E6BB2089-163F-466B-812A-748096614DFD} - hxxp://cainternetsecurity.net/scanner/cascanner.cab

FF - ProfilePath - c:\documents and settings\Anvädaren\Application Data\Mozilla\Firefox\Profiles\40amxa4k.default\

FF - plugin: c:\program\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll

FF - plugin: c:\program\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll

FF - plugin: c:\program\Windows Live\Photo Gallery\NPWLPG.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

 

---- FIREFOX POLICY ----

c:\program\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);

c:\program\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);

c:\program\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);

c:\program\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);

c:\program\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-08-19 08:26

Windows 5.1.2600 Service Pack 3 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

CTxfiHlp = CTXFIHLP.EXE?

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

 

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

 

device: opened successfully

user: MBR read successfully

called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys >>UNKNOWN [0x8A872A17]<<

kernel: MBR read successfully

detected MBR rootkit hooks:

\Driver\Disk -> CLASSPNP.SYS @ 0xba0ecf28

\Driver\ACPI -> ACPI.sys @ 0xb9f7fcb8

\Driver\atapi -> atapi.sys @ 0xb9f37852

IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8

ParseProcedure -> ntkrnlpa.exe @ 0x805827e8

\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8

ParseProcedure -> ntkrnlpa.exe @ 0x805827e8

NDIS: Atheros L1 Gigabit Ethernet 10/100/1000Base-T Controller -> SendCompleteHandler -> NDIS.sys @ 0xb9e30bb0

PacketIndicateHandler -> NDIS.sys @ 0xb9e1fa0d

SendHandler -> NDIS.sys @ 0xb9e33b40

user & kernel MBR OK

 

**************************************************************************

.

--------------------- LÅSTA REGISTERNYCKLAR ---------------------

 

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•6~*]

"D140211900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

.

--------------------- DLLer som "laddats" under processer som körs ---------------------

 

- - - - - - - > 'winlogon.exe'(516)

c:\program\Delade filer\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

.

Sluttid: 2010-08-19 08:29:28

ComboFix-quarantined-files.txt 2010-08-19 06:29

ComboFix2.txt 2010-08-15 09:55

ComboFix3.txt 2010-08-07 08:20

ComboFix4.txt 2010-08-04 18:04

ComboFix5.txt 2010-08-19 06:09

 

Före genomsökningen: 15 261 237 248 byte ledigt

Efter genomsökningen: 15 247 314 944 byte ledigt

 

Current=9 Default=9 Failed=8 LastKnownGood=10 Sets=1,2,3,4,5,6,7,8,9,10

- - End Of File - - 19FF6F09D4385252C436B9E92A1E4327

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

DDS (Ver_10-03-17.01) - NTFSx86

Run by Anv„daren at 7:52:52,59 on 2010-08-19

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21

Microsoft Windows XP Home Edition 5.1.2600.3.1252.46.1053.18.2047.1423 [GMT 2:00]

 

AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

 

============== Running Processes ===============

 

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup

svchost.exe

svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Program\Alwil Software\Avast5\AvastSvc.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\CTXFIHLP.EXE

C:\Program\Delade filer\Java\Java Update\jusched.exe

C:\Program\iTunes\iTunesHelper.exe

C:\Program\ALWILS~1\Avast5\avastUI.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program\Creative\Shared Files\CTAudSvc.exe

C:\WINDOWS\SYSTEM32\CTXFISPI.EXE

svchost.exe

C:\Program\Delade filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program\Bonjour\mDNSResponder.exe

C:\WINDOWS\system32\CTsvcCDA.exe

C:\Program\Java\jre6\bin\jqs.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\HPZipm12.exe

C:\Program\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\WINDOWS\system32\Wacom_Tablet.exe

C:\WINDOWS\system32\SearchIndexer.exe

C:\WINDOWS\system32\Wacom_Tablet.exe

C:\Program\iPod\bin\iPodService.exe

C:\WINDOWS\system32\SearchProtocolHost.exe

C:\Documents and Settings\Anvädaren\Skrivbord\dds.scr

 

============== Pseudo HJT Report ===============

 

uStart Page = hxxp://www.google.se/

mWindow Title = Erhållen av Wermlandsdata

uInternet Settings,ProxyOverride = <local>

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program\delade filer\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program\bitcomet\tools\BitCometBHO_1.3.7.16.dll

BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program\avg\avg9\avgssie.dll

BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program\spybot - search & destroy\SDHelper.dll

BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll

BHO: Windows Live inloggningshjälpen: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program\delade filer\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program\java\jre6\bin\jp2ssv.dll

BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program\windows live\toolbar\wltcore.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program\windows live\toolbar\wltcore.dll

TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File

uRun: [spybotSD TeaTimer] c:\program\spybot - search & destroy\TeaTimer.exe

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

uRunOnce: [shockwave Updater] c:\windows\system32\adobe\shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; Creative AutoUpdate v1.40.01)" -"http://www.blip.se/rsbitch/bitch_v3.asp"

mRun: [RTHDCPL] RTHDCPL.EXE

mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

mRun: [nwiz] nwiz.exe /install

mRun: [VolPanel] "c:\program\creative\volume panel\VolPanlu.exe" /r

mRun: [CTxfiHlp] CTXFIHLP.EXE

mRun: [sunJavaUpdateSched] "c:\program\delade filer\java\java update\jusched.exe"

mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe

mRun: [AdobeCS4ServiceManager] "c:\program\delade filer\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin

mRun: [Adobe Reader Speed Launcher] "c:\program\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [Adobe ARM] "c:\program\delade filer\adobe\arm\1.0\AdobeARM.exe"

mRun: [QuickTime Task] "c:\program\quicktime\qttask.exe" -atboottime

mRun: [iTunesHelper] "c:\program\itunes\iTunesHelper.exe"

mRun: [avast5] c:\program\alwils~1\avast5\avastUI.exe /nogui

dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE

StartupFolder: c:\docume~1\alluse~1\start-~1\program\autost~1\adobeg~1.lnk - c:\program\delade filer\adobe\calibration\Adobe Gamma Loader.exe

StartupFolder: c:\docume~1\alluse~1\start-~1\program\autost~1\window~1.lnk - c:\program\windows desktop search\WindowsSearch.exe

IE: &D&ownload &with BitComet - c:\program\bitcomet\BitComet.exe/AddLink.htm

IE: &D&ownload all video with BitComet - c:\program\bitcomet\BitComet.exe/AddVideo.htm

IE: &D&ownload all with BitComet - c:\program\bitcomet\BitComet.exe/AddAllLink.htm

IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program\bitcomet\tools\BitCometBHO_1.3.7.16.dll/206

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program\messenger\msmsgs.exe

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program\windows live\writer\WriterBrowserExtension.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\program\micros~2\office11\REFIEBAR.DLL

IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program\spybot - search & destroy\SDHelper.dll

DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} - hxxp://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab

DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab

DPF: {6CCE3920-3183-4B3D-808A-B12EB769DE12} - hxxp://www.commandondemand.com/eval/cod/cabs/cssweb.cab

DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1256545002890

DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

DPF: {E6BB2089-163F-466B-812A-748096614DFD} - hxxp://cainternetsecurity.net/scanner/cascanner.cab

DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15109/CTPID.cab

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program\windows desktop search\MSNLNamespaceMgr.dll

 

================= FIREFOX ===================

 

FF - ProfilePath - c:\docume~1\anvdar~1\applic~1\mozilla\firefox\profiles\40amxa4k.default\

FF - plugin: c:\documents and settings\anvã¤daren\lokala instã¤llningar\application data\unity\webplayer\loader\npUnity3D32.dll

FF - plugin: c:\program\java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program\mpcstar\codecs\real\browser\plugins\nppl3260.dll

FF - plugin: c:\program\mpcstar\codecs\real\browser\plugins\nprpjplug.dll

FF - plugin: c:\program\windows live\photo gallery\NPWLPG.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

FF - HiddenExtension: Java Console: No Registry Reference - c:\program\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

 

---- FIREFOX POLICIES ----

c:\program\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.visited_color", "#551A8B");

c:\program\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);

c:\program\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);

c:\program\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);

c:\program\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);

c:\program\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);

c:\program\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);

c:\program\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);

c:\program\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);

c:\program\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);

c:\program\mozilla firefox\greprefs\all.js - pref("html5.enable", false);

c:\program\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);

c:\program\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

c:\program\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);

c:\program\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");

c:\program\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");

c:\program\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.videoFeeds.handler", "ask");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

 

============= SERVICES / DRIVERS ===============

 

R0 AVG Anti-Rootkit;AVG Anti-Rootkit;c:\windows\system32\drivers\avgarkt.sys [2007-1-31 5632]

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-3-25 64288]

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-8-16 165456]

R1 AvgArCln;Avg Anti-Rootkit Clean Driver;c:\windows\system32\drivers\AvgArCln.sys [2009-12-27 3968]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-8-16 17744]

R2 avast! Antivirus;avast! Antivirus;c:\program\alwil software\avast5\AvastSvc.exe [2010-8-16 40384]

R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-10-26 54752]

R2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2010-8-11 2789672]

R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\l151x86.sys [2009-10-23 39424]

R3 avast! Mail Scanner;avast! Mail Scanner;c:\program\alwil software\avast5\AvastSvc.exe [2010-8-16 40384]

R3 avast! Web Scanner;avast! Web Scanner;c:\program\alwil software\avast5\AvastSvc.exe [2010-8-16 40384]

R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [2009-6-4 171032]

R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [2009-6-4 1324056]

R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [2009-6-4 72728]

R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2009-11-18 15656]

S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program\lavasoft\ad-aware\AAWService.exe [2010-7-12 1355416]

S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program\delade filer\creative labs shared\service\CTAELicensing.exe [2009-10-23 79360]

S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [2009-6-4 171032]

S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [2009-6-4 1324056]

S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [2009-6-4 72728]

S3 fsssvc;Tjänsten Windows Live Family Safety;c:\program\windows live\family safety\fsssvc.exe [2009-8-5 704864]

S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program\lavasoft\ad-aware\kernexplorer.sys [2010-8-12 15008]

 

=============== Created Last 30 ================

 

2010-08-16 06:28:38 38848 ----a-w- c:\windows\avastSS.scr

2010-08-11 10:09:47 0 d-----w- c:\docume~1\anvdar~1\applic~1\WTablet

2010-08-11 10:06:19 1651768 ----a-w- c:\windows\system32\WacomTablet.znc

2010-08-11 10:06:17 6561064 ----a-w- c:\windows\system32\WacomTablet.cpl

2010-08-11 10:06:14 11440 ----a-w- c:\windows\system32\drivers\WacomVKHid.sys

2010-08-11 10:06:04 13352 ----a-w- c:\windows\system32\drivers\wacomvhid.sys

2010-08-11 10:06:04 11312 ----a-w- c:\windows\system32\drivers\wacommousefilter.sys

2010-08-11 10:05:56 0 d-----w- c:\windows\system32\WTablet

2010-08-11 10:05:53 2789672 ----a-w- c:\windows\system32\Wacom_Tablet.exe

2010-08-11 10:05:53 213288 ----a-w- c:\windows\system32\Wacom_Tablet.dll

2010-08-11 10:05:53 172840 ----a-w- c:\windows\system32\Wintab32.dll

2010-08-11 10:05:52 0 d-----w- c:\program\Tablet

2010-08-07 08:03:20 98816 ----a-w- c:\windows\sed.exe

2010-08-07 08:03:20 77312 ----a-w- c:\windows\MBR.exe

2010-08-07 08:03:20 256512 ----a-w- c:\windows\PEV.exe

2010-08-07 08:03:20 161792 ----a-w- c:\windows\SWREG.exe

2010-08-03 17:34:03 16968 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys

2010-08-03 17:33:25 0 d-----w- c:\docume~1\alluse~1\applic~1\Hitman Pro

2010-08-03 17:33:24 0 d-----w- c:\program\Hitman Pro 3.5

2010-08-03 06:03:40 664 ----a-w- c:\windows\system32\d3d9caps.dat

2010-08-02 06:31:11 0 d-----w- c:\program\Spybot - Search & Destroy

2010-08-02 06:31:11 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy

2010-08-02 06:16:00 423656 ----a-w- c:\windows\system32\deployJava1.dll

2010-07-24 11:01:25 0 dc-h--w- c:\docume~1\alluse~1\applic~1\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}

2010-07-23 11:53:17 0 d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software

2010-07-21 16:58:40 0 d-----w- c:\windows\system32\wbem\Repository

2010-07-20 17:22:06 12845056 ----a-w- c:\documents and settings\anvädaren\ntuser.dat

2010-07-20 17:06:13 164 ----a-w- c:\documents and settings\anvädaren\defogger_reenable

2010-07-20 11:20:18 0 d-sha-r- C:\cmdcons

 

==================== Find3M ====================

 

2010-08-02 07:06:46 67072 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT

2010-07-12 08:55:39 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys

2010-07-12 08:55:38 15880 ----a-w- c:\windows\system32\lsdelete.exe

2010-06-23 20:49:32 92094 ----a-w- c:\windows\system32\perfc01D.dat

2010-06-23 20:49:32 463742 ----a-w- c:\windows\system32\perfh01D.dat

2006-06-23 06:48:54 32768 ----a-r- c:\windows\inf\UpdateUSB.exe

2009-12-31 15:26:12 16384 --sha-w- c:\windows\system32\config\systemprofile\ietldcache\index.dat

 

============= FINISH: 7:53:56,12 ===============

Länk till kommentar
Dela på andra webbplatser

Avinstallera AVG Anti-Rootkit Free utifall att det är det som påverkar loggarna. Starta sedan om datorn och kör ComboFix igen. Klistra in loggen och starta om datorn.

 

Spara Rootkit Unhooker på skrivbordet.

http://www.rootkit.com/vault/DiabloNova/RKUnhookerLE.EXE

Dubbelklicka på programmet för att starta det (i Vista och Windows 7 högerklicka och välj Kör som administratör).

Välj fliken Report och klicka på Scan

Bocka för Drivers, Stealth och avbocka de andra valen.

Tryck på OK

Vänta tills skannern är klar och då väljer du File - Save Report. Spara rapporten på Skrivbordet eller på något annat ställe där du hittar igen den. Klicka på Close

 

Öppna den sparade rapporten i Anteckningar. Klistra in innehållet i ditt svar.

 

Notera om det kommer upp en varning "Rootkit Unhooker has detected a parasite..." så ignorera den bara.

Länk till kommentar
Dela på andra webbplatser

Dagens dos;

 

 

ComboFix 10-08-17.04 - Anvädaren 2010-08-20 16:10:46.11.2 - x86

Microsoft Windows XP Home Edition 5.1.2600.3.1252.46.1053.18.2047.1651 [GMT 2:00]

Körs från: c:\documents and settings\Anvädaren\Skrivbord\ComboFix.exe

.

 

(((((((((((((((((((((((( Filer Skapade från 2010-07-20 till 2010-08-20 ))))))))))))))))))))))))))))))

.

 

2010-08-12 05:08 . 2010-08-19 05:58 -------- d-----w- c:\documents and settings\LocalService\Application Data\WTablet

2010-08-11 10:06 . 2007-02-15 14:11 11440 ----a-w- c:\windows\system32\drivers\WacomVKHid.sys

2010-08-11 10:06 . 2008-07-11 09:16 13352 ----a-w- c:\windows\system32\drivers\wacomvhid.sys

2010-08-11 10:06 . 2007-02-16 09:12 11312 ----a-w- c:\windows\system32\drivers\wacommousefilter.sys

2010-08-11 10:05 . 2010-08-11 10:05 -------- d-----w- c:\windows\system32\WTablet

2010-08-11 10:05 . 2009-03-26 15:15 2789672 ----a-w- c:\windows\system32\Wacom_Tablet.exe

2010-08-11 10:05 . 2009-03-26 14:40 213288 ----a-w- c:\windows\system32\Wacom_Tablet.dll

2010-08-11 10:05 . 2009-03-26 14:10 172840 ----a-w- c:\windows\system32\Wintab32.dll

2010-08-11 10:05 . 2010-08-11 10:06 -------- d-----w- c:\program\Tablet

2010-08-03 17:34 . 2010-08-03 17:34 16968 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys

2010-08-03 17:33 . 2010-08-03 17:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Hitman Pro

2010-08-03 17:33 . 2010-08-03 17:33 -------- d-----w- c:\program\Hitman Pro 3.5

2010-08-03 06:03 . 2010-08-11 09:59 664 ----a-w- c:\windows\system32\d3d9caps.dat

2010-08-02 14:53 . 2010-08-02 14:53 0 ----a-w- c:\windows\nsreg.dat

2010-08-02 06:31 . 2010-08-02 07:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy

2010-08-02 06:31 . 2010-08-02 06:37 -------- d-----w- c:\program\Spybot - Search & Destroy

2010-08-02 06:16 . 2010-08-02 06:16 -------- d-----w- c:\program\Delade filer\Java

2010-08-02 06:16 . 2010-07-17 03:00 423656 ----a-w- c:\windows\system32\deployJava1.dll

2010-07-29 12:03 . 2010-07-29 12:03 -------- d-----r- c:\documents and settings\NetworkService\Favoriter

2010-07-24 11:09 . 2010-07-12 08:56 2979280 -c--a-w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}\Ad-AwareInstall.exe

2010-07-24 11:01 . 2010-07-24 11:09 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}

2010-07-23 11:53 . 2010-08-19 19:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software

2010-07-23 11:53 . 2010-07-23 11:53 -------- d-----w- c:\program\Alwil Software

2010-07-21 16:58 . 2010-07-21 16:58 -------- d-----w- c:\windows\system32\wbem\Repository

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-08-18 12:18 . 2009-10-30 09:38 -------- d-----w- c:\program\BitComet

2010-08-11 09:35 . 2009-12-02 17:24 -------- d-----w- c:\program\TabletPlugins

2010-08-02 07:06 . 2009-11-18 12:17 67072 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT

2010-08-02 06:19 . 2009-11-03 19:43 -------- d-----w- c:\program\HP

2010-08-02 06:17 . 2009-11-03 19:51 -------- d-----w- c:\program\Delade filer\HP

2010-08-02 06:15 . 2009-10-26 08:11 -------- d-----w- c:\program\Java

2010-07-20 08:30 . 2009-12-31 16:55 -------- d-----w- c:\program\Malwarebytes' Anti-Malware

2010-07-20 04:41 . 2009-10-28 17:21 -------- d-----w- c:\program\Norman

2010-07-19 20:04 . 2009-10-31 07:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft

2010-07-12 08:55 . 2010-03-25 06:40 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys

2010-07-12 08:55 . 2010-07-19 20:22 15880 ----a-w- c:\windows\system32\lsdelete.exe

2010-06-23 20:49 . 2008-04-15 12:00 92094 ----a-w- c:\windows\system32\perfc01D.dat

2010-06-23 20:49 . 2008-04-15 12:00 463742 ----a-w- c:\windows\system32\perfh01D.dat

2010-06-16 19:16 . 2010-06-16 19:16 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe

2010-06-14 14:31 . 2009-10-22 12:23 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe

2010-05-23 06:12 . 2009-11-10 06:59 8 ----a-w- c:\windows\system32\nvModes.dat

.

 

((((((((((((((((((((((((((((( SnapShot@2010-07-20_11.40.15 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-07-11 22:02 . 2009-07-11 22:02 51008 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90rus.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90kor.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90jpn.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90ita.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90fra.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 61760 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esp.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esn.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 53568 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 63296 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90deu.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90cht.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 35648 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90chs.dll

+ 2009-07-11 22:05 . 2009-07-11 22:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll

+ 2009-07-11 22:05 . 2009-07-11 22:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll

+ 2010-08-20 14:07 . 2010-08-20 14:07 16384 c:\windows\temp\Perflib_Perfdata_728.dat

+ 2010-07-24 11:22 . 2010-07-12 08:55 64288 c:\windows\system32\DRVSTORE\lbd_9C578CA880A99903668A8694DEFB21244E9C4C62\Lbd.sys

+ 2009-11-18 11:52 . 2008-10-06 09:53 15656 c:\windows\system32\drivers\wacmoumonitor.sys

+ 2001-09-06 19:55 . 2001-09-06 17:55 12160 c:\windows\system32\drivers\mouhid.sys

- 2001-09-06 19:55 . 2001-09-06 18:55 12160 c:\windows\system32\drivers\mouhid.sys

+ 2008-04-14 21:03 . 2008-04-14 19:03 23296 c:\windows\system32\drivers\mouclass.sys

- 2008-04-14 21:03 . 2008-04-14 20:03 23296 c:\windows\system32\drivers\mouclass.sys

- 2001-09-06 19:55 . 2001-09-06 18:55 12160 c:\windows\system32\dllcache\mouhid.sys

+ 2001-09-06 19:55 . 2001-09-06 17:55 12160 c:\windows\system32\dllcache\mouhid.sys

- 2008-04-14 21:03 . 2008-04-14 20:03 23296 c:\windows\system32\dllcache\mouclass.sys

+ 2008-04-14 21:03 . 2008-04-14 19:03 23296 c:\windows\system32\dllcache\mouclass.sys

+ 2009-07-11 22:02 . 2009-07-11 22:02 653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll

+ 2009-07-11 22:05 . 2009-07-11 22:05 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll

- 2009-07-11 23:02 . 2009-07-11 23:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll

+ 2010-08-11 10:05 . 2009-03-26 15:16 186664 c:\windows\system32\WTablet\Wacom_TabletUser.exe

+ 2009-11-13 14:56 . 2010-07-21 17:13 144476 c:\windows\system32\Restore\rstrlog.dat

+ 2010-07-24 05:44 . 2010-07-24 05:44 231888 c:\windows\system32\Macromed\Flash\FlashUtil10h_Plugin.exe

+ 2010-08-02 06:16 . 2010-07-17 03:00 153376 c:\windows\system32\javaws.exe

+ 2010-08-02 06:16 . 2010-07-17 03:00 145184 c:\windows\system32\javaw.exe

- 2009-10-26 08:38 . 2009-07-25 04:23 145184 c:\windows\system32\javaw.exe

+ 2010-08-02 06:15 . 2010-07-17 03:00 145184 c:\windows\system32\java.exe

- 2009-10-26 08:38 . 2009-07-25 04:23 145184 c:\windows\system32\java.exe

+ 2010-07-23 11:53 . 2010-07-23 11:53 219648 c:\windows\Installer\a68730.msi

+ 2010-08-02 06:16 . 2010-08-02 06:16 180224 c:\windows\Installer\1ca14.msi

+ 2009-07-11 22:02 . 2009-07-11 22:02 3780424 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll

+ 2009-07-11 22:02 . 2009-07-11 22:02 3765048 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90.dll

+ 2010-07-24 05:44 . 2010-07-24 05:44 5612496 c:\windows\system32\Macromed\Flash\NPSWF32.dll

+ 2009-10-22 14:15 . 2010-08-02 06:26 3488384 c:\windows\system32\FNTCACHE.DAT

+ 2010-07-24 11:09 . 2010-07-24 11:09 1866752 c:\windows\Installer\1b4db.msi

+ 2010-06-20 08:01 . 2010-06-20 08:01 8040960 c:\windows\Installer\145356.msp

.

(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Not* Tomma poster & legitima standardposter visas inte.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SpybotSD TeaTimer"="c:\program\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe" [2009-07-31 468408]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 16132608]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-06 8523776]

"nwiz"="nwiz.exe" [2007-11-06 1626112]

"VolPanel"="c:\program\Creative\Volume Panel\VolPanlu.exe" [2008-08-06 233576]

"CTxfiHlp"="CTXFIHLP.EXE" [2009-06-03 25600]

"SunJavaUpdateSched"="c:\program\Delade filer\Java\Java Update\jusched.exe" [2010-05-14 248552]

"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

"AdobeCS4ServiceManager"="c:\program\Delade filer\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]

"Adobe Reader Speed Launcher"="c:\program\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]

"Adobe ARM"="c:\program\Delade filer\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

"QuickTime Task"="c:\program\QuickTime\qttask.exe" [2010-03-17 421888]

"iTunesHelper"="c:\program\iTunes\iTunesHelper.exe" [2010-04-28 142120]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]

 

c:\documents and settings\All Users\Start-meny\Program\Autostart\

Adobe Gamma Loader.lnk - c:\program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe [2009-10-30 110592]

Windows Search.lnk - c:\program\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ lsdelete

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program\\Delade filer\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=

"c:\\Program\\BitComet\\BitComet.exe"=

"c:\\Program\\Spotify\\spotify.exe"=

"c:\\Program\\Warcraft II BNE\\Warcraft II BNE.exe"=

"c:\\Program\\Malwarebytes' Anti-Malware\\mbam.exe"=

"c:\\Program\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program\\Windows Live\\Sync\\WindowsLiveSync.exe"=

"c:\\Program\\DC++\\DCPlusPlus.exe"=

"c:\\Program\\Bonjour\\mDNSResponder.exe"=

"c:\\Program\\iTunes\\iTunes.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"5353:TCP"= 5353:TCP:Adobe CSI CS4

"7303:TCP"= 7303:TCP:BitComet 7303 TCP

"7303:UDP"= 7303:UDP:BitComet 7303 UDP

 

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-03-25 64288]

R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program\Lavasoft\Ad-Aware\AAWService.exe [2010-07-12 1355416]

R2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2010-08-11 2789672]

R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\l151x86.sys [2009-10-23 39424]

R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [2009-06-04 171032]

R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [2009-06-04 1324056]

R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [2009-06-04 72728]

R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2009-11-18 15656]

S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program\Delade filer\Creative Labs Shared\Service\CTAELicensing.exe [2009-10-23 79360]

S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [2009-06-04 171032]

S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [2009-06-04 1324056]

S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [2009-06-04 72728]

S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program\Lavasoft\Ad-Aware\kernexplorer.sys [2010-08-12 15008]

S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2009-12-02 691696]

.

Innehållet i mappen 'Schemalagda aktiviteter':

 

2010-08-20 c:\windows\Tasks\Ad-Aware Update (Weekly).job

- c:\program\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-07-12 20:13]

 

2010-07-30 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program\Apple Software Update\SoftwareUpdate.exe [2007-08-29 11:34]

 

2010-08-20 c:\windows\Tasks\User_Feed_Synchronization-{8549F50F-53DC-4CE4-A61C-F9C05D34D743}.job

- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]

.

.

------- Extra genomsökning -------

.

uStart Page = hxxp://www.google.se/

mWindow Title = Erhållen av Wermlandsdata

uInternet Settings,ProxyOverride = <local>

IE: &D&ownload &with BitComet - c:\program\BitComet\BitComet.exe/AddLink.htm

IE: &D&ownload all video with BitComet - c:\program\BitComet\BitComet.exe/AddVideo.htm

IE: &D&ownload all with BitComet - c:\program\BitComet\BitComet.exe/AddAllLink.htm

DPF: {6CCE3920-3183-4B3D-808A-B12EB769DE12} - hxxp://www.commandondemand.com/eval/cod/cabs/cssweb.cab

DPF: {E6BB2089-163F-466B-812A-748096614DFD} - hxxp://cainternetsecurity.net/scanner/cascanner.cab

FF - ProfilePath - c:\documents and settings\Anvädaren\Application Data\Mozilla\Firefox\Profiles\40amxa4k.default\

FF - plugin: c:\program\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll

FF - plugin: c:\program\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll

FF - plugin: c:\program\Windows Live\Photo Gallery\NPWLPG.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

 

---- FIREFOX POLICY ----

c:\program\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);

c:\program\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);

c:\program\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);

c:\program\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);

c:\program\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net'>http://www.gmer.net

Rootkit scan 2010-08-20 16:19

Windows 5.1.2600 Service Pack 3 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

CTxfiHlp = CTXFIHLP.EXE?

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

 

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

 

device: opened successfully

user: MBR read successfully

called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys >>UNKNOWN [0x8A86AA17]<<

kernel: MBR read successfully

detected MBR rootkit hooks:

\Driver\Disk -> CLASSPNP.SYS @ 0xba0ecf28

\Driver\ACPI -> ACPI.sys @ 0xb9f7fcb8

\Driver\atapi -> atapi.sys @ 0xb9f37852

IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8

ParseProcedure -> ntkrnlpa.exe @ 0x805827e8

\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8

ParseProcedure -> ntkrnlpa.exe @ 0x805827e8

NDIS: Atheros L1 Gigabit Ethernet 10/100/1000Base-T Controller -> SendCompleteHandler -> NDIS.sys @ 0xb9e30bb0

PacketIndicateHandler -> NDIS.sys @ 0xb9e1fa0d

SendHandler -> NDIS.sys @ 0xb9e33b40

user & kernel MBR OK

 

**************************************************************************

.

--------------------- LÅSTA REGISTERNYCKLAR ---------------------

 

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•6~*]

"D140211900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

.

--------------------- DLLer som "laddats" under processer som körs ---------------------

 

- - - - - - - > 'winlogon.exe'(516)

c:\program\Delade filer\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

.

Sluttid: 2010-08-20 16:22:32

ComboFix-quarantined-files.txt 2010-08-20 14:22

ComboFix2.txt 2010-08-19 06:29

ComboFix3.txt 2010-08-15 09:55

ComboFix4.txt 2010-08-07 08:20

ComboFix5.txt 2010-08-20 14:02

 

Före genomsökningen: 15 355 138 048 byte ledigt

Efter genomsökningen: 15 341 051 904 byte ledigt

 

Current=9 Default=9 Failed=8 LastKnownGood=10 Sets=1,2,3,4,5,6,7,8,9,10

- - End Of File - - 72CD3C880C023E83089F9529097BFFF9

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

RkU Version: 3.8.388.590, Type LE (SR2)

==============================================

OS Name: Windows XP

Version 5.1.2600 (Service Pack 3)

Number of processors #2

==============================================

>Drivers

==============================================

0xB96A3000 C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 7430144 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Miniport Driver, Version 169.06 )

0xBF012000 C:\WINDOWS\System32\nv4_disp.dll 5771264 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Display driver, Version 169.06 )

0xB6E90000 C:\WINDOWS\system32\drivers\RtkHDAud.sys 4546560 bytes (Realtek Semiconductor Corp., Realtek® High Definition Audio Function Driver)

0x804D7000 C:\WINDOWS\system32\ntkrnlpa.exe 2150400 bytes (Microsoft Corporation, NT:s kernel och system)

0x804D7000 PnpManager 2150400 bytes

0x804D7000 RAW 2150400 bytes

0x804D7000 WMIxWDM 2150400 bytes

0xBF800000 Win32k 1851392 bytes

0xBF800000 C:\WINDOWS\System32\win32k.sys 1851392 bytes (Microsoft Corporation, Win32-drivrutin för flera användare)

0xB2860000 C:\WINDOWS\System32\drivers\CTEXFIFX.SYS 1339392 bytes (Creative Technology Ltd., Creative XFi Effects)

0xB2ADD000 C:\WINDOWS\system32\drivers\ha20x2k.sys 1191936 bytes (Creative Technology Ltd, Creative 20X HAL (WDM))

0xB29E8000 C:\WINDOWS\system32\drivers\ctac32k.sys 638976 bytes (Creative Technology Ltd, Creative AC3 SW Decoder Device Driver (WDM))

0xB9E48000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver)

0xB95C4000 C:\WINDOWS\system32\drivers\ctaud2k.sys 520192 bytes (Creative Technology Ltd, Creative WDM Audio Device Driver)

0xB26A1000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr)

0xB93E6000 C:\WINDOWS\system32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver)

0xB27D4000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver)

0xB1C59000 C:\WINDOWS\system32\DRIVERS\srv.sys 356352 bytes (Microsoft Corporation, Server driver)

0xBFFA0000 C:\WINDOWS\System32\ATMFD.DLL 286720 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver)

0xB1538000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack)

0xB9548000 C:\WINDOWS\system32\drivers\ctoss2k.sys 217088 bytes (Creative Technology Ltd., Creative OS Services Driver (WDM))

0xB2AAD000 C:\WINDOWS\system32\drivers\emupia2k.sys 196608 bytes (Creative Technology Ltd, E-mu Plug-in Architecture Driver (WDM))

0xB9F79000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI-drivrutin för NT)

0xB1E01000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)

0xB9E1B000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver)

0xB29A7000 C:\WINDOWS\System32\drivers\CT20XUT.SYS 180224 bytes (Creative Technology Ltd., Creative 20X Utility Effects)

0xAE985000 C:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer)

0xB2711000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)

0xB2A84000 C:\WINDOWS\system32\drivers\ctsfm2k.sys 167936 bytes (Creative Technology Ltd, SoundFont® Manager (WDM))

0xB9667000 C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 163840 bytes (Windows ® Server 2003 DDK provider, High Definition Audio Bus Driver v1.0a)

0xB2784000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver)

0xB275E000 C:\WINDOWS\system32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator)

0xB95A0000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))

0xB9643000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)

0xB957D000 C:\WINDOWS\system32\drivers\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library)

0xB273C000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)

0x806E4000 ACPI_HAL 134400 bytes

0x806E4000 C:\WINDOWS\system32\hal.dll 134400 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)

0xB9F11000 fltMgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)

0xB9F49000 ftdisk.sys 126976 bytes (Microsoft Corporation, Drivrutin för FT Disk)

0xB9E01000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver)

0xB9F31000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver)

0xB2661000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes

0xB9EE8000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)

0xB951D000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))

0xB29D3000 C:\WINDOWS\System32\drivers\CTHWIUT.SYS 86016 bytes (Creative Technology Ltd., Creative Utility Effects)

0xB1FEC000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper)

0xB9534000 C:\WINDOWS\system32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Drivrutin för parallellport)

0xB968F000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver)

0xB282D000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver)

0xB9ED5000 WudfPf.sys 77824 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver)

0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver)

0xB9EFF000 sr.sys 73728 bytes (Microsoft Corporation, Filterdrivrutin för Systemåterställning)

0xB1DA0000 C:\WINDOWS\System32\Drivers\adfs.SYS 69632 bytes (Adobe Systems, Inc., Adobe Drive File System Driver)

0xB9F68000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI-uppräknare)

0xB9444000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler)

0xBA1A8000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver)

0xBA248000 C:\WINDOWS\system32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver)

0xBA238000 C:\WINDOWS\system32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Seriell drivrutin)

0xBA228000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)

0xBA0F8000 Lbd.sys 61440 bytes (Lavasoft AB, Boot Driver)

0xBA258000 C:\WINDOWS\system32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Drivrutin för Redbook-ljudfilter)

0xB23D1000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter)

0xBA158000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB)

0xBA218000 C:\WINDOWS\system32\DRIVERS\l151x86.sys 57344 bytes (Atheros Communications Inc., Atheros L1 Gigabit Ethernet 10/100/1000Base-T Driver)

0xBA0E8000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll)

0xBA288000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)

0xBA0C8000 VolSnap.sys 53248 bytes (Microsoft Corporation, Drivrutin för ögonblicksbilder av volymer)

0xB22F1000 C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys 49152 bytes (Microsoft Corporation, Family Safety Filter Driver (TDI))

0xBA2A8000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)

0xBA188000 C:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, Drivrutin för FIPS-krypto)

0xBA268000 C:\WINDOWS\system32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver)

0xBA0B8000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager)

0xBA298000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)

0xBA208000 C:\WINDOWS\system32\DRIVERS\intelppm.sys 40960 bytes (Microsoft Corporation, Drivrutin för processor)

0xBA0A8000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bussdrivrutin)

0xBA308000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy)

0xBA108000 PxHelp20.sys 40960 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)

0xBA2C8000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver)

0xBA0D8000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver)

0xBA278000 C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS 36864 bytes (Microsoft Corporation, Hid Class Library)

0xBA2B8000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier)

0xBA178000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver)

0xB083A000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)

0xB950D000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)

0xBA3D0000 C:\WINDOWS\system32\drivers\ctprxy2k.sys 32768 bytes (Creative Technology Ltd, Creative Proxy Device Driver (WDM))

0xBA468000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver)

0xBA480000 C:\WINDOWS\system32\DRIVERS\usbccgp.sys 32768 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver)

0xBA3C8000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)

0xBA490000 C:\WINDOWS\system32\DRIVERS\wacmoumonitor.sys 32768 bytes (Wacom Technology, Wacom HID Mouse Monitor Filter Driver)

0xBA420000 C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys 32768 bytes (Wacom Technology, Wacom Mouse Filter Driver)

0xBA3E8000 C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)

0xBA408000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 28672 bytes (Microsoft Corporation, Tangentbordsklassdrivrutin)

0xBA328000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)

0xBA488000 C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 28672 bytes (Microsoft Corporation, USB Mass Storage Class Driver)

0xBA3E0000 C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter)

0xBA410000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Musklassdrivrutin)

0xBA3C0000 C:\WINDOWS\system32\DRIVERS\usbuhci.sys 24576 bytes (Microsoft Corporation, UHCI USB Miniport Driver)

0xBA458000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)

0xBA460000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver)

0xBA330000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager)

0xBA3F8000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library)

0xBA400000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver)

0xBA3F0000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper)

0xBA4B0000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver)

0xB9DDD000 C:\WINDOWS\system32\DRIVERS\kbdhid.sys 16384 bytes (Microsoft Corporation, Filterdrivrutin för HID-mus)

0xBA588000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver)

0xB27C4000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver)

0xBA568000 C:\WINDOWS\system32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator)

0xBA4BC000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver)

0xBA58C000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver)

0xB9461000 C:\WINDOWS\system32\DRIVERS\hidusb.sys 12288 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices)

0xBA59C000 C:\WINDOWS\system32\DRIVERS\mouhid.sys 12288 bytes (Microsoft Corporation, Filterdrivrutin för HID-mus)

0xBA57C000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)

0xB6E78000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver)

0xBA5BE000 C:\WINDOWS\system32\DRIVERS\ASACPI.sys 8192 bytes (-, ATK0110 ACPI Utility)

0xBA5F8000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver)

0xBA616000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes

0xBA5F6000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver)

0xBA5FA000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator)

0xBA64E000 C:\WINDOWS\System32\Drivers\ParVdm.SYS 8192 bytes (Microsoft Corporation, Parallellportsdrivrutin för VDM)

0xBA5FC000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport)

0xBA5C4000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)

0xBA5E4000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)

0xBA5C0000 C:\WINDOWS\system32\DRIVERS\wacomvhid.sys 8192 bytes (Wacom Technology, Virtual Hid Device)

0xBA5C2000 C:\WINDOWS\system32\DRIVERS\WacomVKHid.sys 8192 bytes (Wacom Technology, Virtual Hid Device)

0xBA5A8000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll)

0x8A802000 C:\WINDOWS\system32\KDCOM.DLL 7040 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)

0xBA76D000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver)

0xBA758000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk)

0xBA7BC000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver)

0xBA670000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE-bussdrivrutin)

!!!!!!!!!!!Hidden driver: 0x8A862A17 ?_empty_? 1513 bytes

==============================================

>Stealth

==============================================

0xB9F31000 WARNING: suspicious driver modification [atapi.sys::0x8A862A17]

Länk till kommentar
Dela på andra webbplatser

!!!!!!!!!!!Hidden driver: 0x8A862A17 ?_empty_? 1513 bytes

==============================================

>Stealth

==============================================

0xB9F31000 WARNING: suspicious driver modification [atapi.sys::0x8A862A17]

Där har vi problemet.

 

Ta bort den ComboFix du har och ladda ner en ny. http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Kör på vanligt sätt.

Om du inte har börjat med ComboFix vore det bra om det kunde undersökas lite mer först. Säg till.

Länk till kommentar
Dela på andra webbplatser

Då får du ta fram mer information om vad som händer i datorn så att de som programmerar rensningsprogram, som t ex RootRepeal, kan utöka programmen så att de klarar av även den smitta du har råkat ut för. Det är inte så många som har råkat ut för den typ av infektion som du har.

 

Mycket viktigt att instruktionen följs exakt för att det ska bli det resultat de vill ha. Jag klistrar in det på engelska först och sedan översätter jag.

1. Download the tool, and save it to your Desktop.

http://ad13.geekstogo.com/TDLCheck.exe'>http://ad13.geekstogo.com/TDLCheck.exe

2. Disable all resident Antivirus protection.

3. Start your Internet browser, and go to Google. If you use a browser that's NOT Internet Explorer, then please ALSO start that and go to Google.

4. Run the tool from your desktop, and wait until you see the "Press any key to continue..." message.

5. Right click on the title bar (where the program name and path is written).

6. From the menu, choose Edit -> Select All.

7. Hit the Enter key on your keyboard to copy selected text.

8. Open a new Notepad document, paste the text, and then save it to your desktop as TDLCheck.txt

 

The tool should create a folder on your desktop called "dumpfiles". Please ZIP that folder, and upload it here, along with the contents of "TDLCheck.txt".

1. Spara programmet TDLCheck på Skrivbordet:

http://ad13.geekstogo.com/TDLCheck.exe

 

2. Stäng av alla program du ser inklusive antivirusprogram.

 

3. Starta Internet Explorer och surfa till http://www.google.com

Om du har någon annan webbläsare, Firefox, Chrome, Opera, Safari, så starta den och surfa till samma sida.

 

4. Starta TDLCheck. Vänta tills du ser texten "Press any key to continue..." eller om den kommer på svenska, dvs tryck någon tangent för att fortsätta eller något liknande. Tryck inte på någon tangent än.

 

5. Högerklicka på titelraden, dvs högst upp i fönsterkanten där det står TDLCheck mm

 

6. I menyn som kommer upp välj Redigera - Markera allt

 

7. Tryck på Enter-tangenten på Skrivbordet för att göra en kopia av fönsterinnehållet.

 

8. Öppna Anteckningar. Klistra in fönsterinnehållet, t ex genom att välja Redigera - Klistra in. Spara på Skrivbordet (Arkiv - Spara) med namnet TDLCheck.txt.

Gör TDLCheck-fönstret aktivt och tryck på någon tangent för att avsluta det.

 

9. På skrivbordet ska du ha fått en mapp som heter "dumpfiles". Zippa den mappen, fråga om du inte vet hur.

 

10. Ladda upp TDLCheck.txt och den zippade mappen på http://www.woofiles.com/

Klistra in länkar här eller skicka i PM.

 

Fråga om det är något oklart.

Länk till kommentar
Dela på andra webbplatser

Arkiverat

Det här ämnet är nu arkiverat och är stängt för ytterligare svar.

×
×
  • Skapa nytt...