Just nu i M3-nätverket
Gå till innehåll

Virusvarning som visar på samma angrepp men inte försvinner


Renfield

Rekommendera Poster

Det går inte att uppdatera Kaspersky. Det kommer upp en felmeddelande efter att jag laddade ned dem och det tog väldigt lång tid att göra det. Comodo är avstängt.

Länk till kommentar
Dela på andra webbplatser

  • Svars 91
  • Skapad
  • Senaste svar

Försök med en annan online-skanning http://www.eset.com/onlinescan/

För att inte skannern ska ta för lång tid på sig stäng av ditt antivirusprogram under tiden.

 

Avbocka alternativet "Remove found threats"

Bocka för "Scan Archives

 

Klicka på "Advanced Settings"

Bocka för:

Scan for potentially unwanted applications

Scan for potentially unsafe applications

Enable Anti-Stealth Technology

 

Tryck på Scan

 

När skanningen är klar skapas loggfilen C:\Program\Eset\Eset Online Scanner\log.txt. Öppna den i Anteckningar och klistra sedan in innehållet i ditt svar.

Länk till kommentar
Dela på andra webbplatser

Inget av online skanningssidorna har funkat och jag har gjort den här skanningen i felsäkert läge. Kanske det inte påverkar något.

scan.txt

Länk till kommentar
Dela på andra webbplatser

Hej,

postar din logg här.

Mvh

Mats H

ESETSmartInstaller@High as downloader log:

Can not open internetESETSmartInstaller@High as downloader log:

Can not open internetCan not open internetESETSmartInstaller@High as downloader log:

Can not open internetCan not open internetESETSmartInstaller@High as downloader log:

Can not open internetCan not open internetESETSmartInstaller@High as downloader log:

all ok

# version=7

# OnlineScannerApp.exe=1.0.0.1

# OnlineScanner.ocx=1.0.0.6211

# api_version=3.0.2

# EOSSerial=5afe2cbcbdce714f8c1fe447db31dbd0

# end=finished

# remove_checked=false

# archives_checked=true

# unwanted_checked=true

# unsafe_checked=true

# antistealth_checked=true

# utc_time=2010-10-02 03:11:26

# local_time=2010-10-02 05:11:26 (+0100, W. Europe Daylight Time)

# country="Sweden"

# lang=1033

# osver=5.1.2600 NT Service Pack 3

# compatibility_mode=3073 16777174 80 92 0 278144 0 0

# compatibility_mode=8192 67108863 100 0 334 334 0 0

# scanned=87311

# found=3

# cleaned=0

# scan_time=16487

C:\rld-shal.iso probably a variant of Win32/Agent.JLJQET trojan 00000000000000000000000000000000 I

C:\Documents and Settings\Thomas\Application Data\BitTorrent\Deamon (DAEMON) Tools Pro 4.30.305 32&64bit Latest.rar NSIS/TrojanDownloader.Agent.NCA trojan 00000000000000000000000000000000 I

C:\Program Files\rld-shal.iso probably a variant of Win32/Agent.JLJQET trojan 00000000000000000000000000000000 I

Länk till kommentar
Dela på andra webbplatser

Hej,

du har ju en del "crackad" programvara installerad.

Avinstallera de programmen vilka i sig, antagligen är roten till bekymren,

så kan vi, Cecilia och jag koncentrera oss på att rensa din dator på ett bra sätt,

och försöka få Windows rent.

Efter borttag av de programmen, kör en ny DDS, och sedan Combofix.

Spara ComboFix på Skrivbordet:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

 

Stäng av alla program du ser inklusive antivirusprogram och antispionprogram men lämna brandväggen på.

Hur? Se http://www.bleepingcomputer.com/forums/topic114351.html

Kör ComboFix och följ anvisningarna som visas.

Om det kommer upp en fråga om du vill installera återställningskonsolen så svara ja.

 

VIKTIGT! Klicka inte på ComboFix-fönstret med musen när den körs annars kan den hänga upp sig.

 

När den är färdig så ska en logg komma upp, klistra in den i ditt svar. Kontrollera att antivirusprogram mm är igång innan du ansluter till internet.

 

Om du får problem med att komma ut på internet:

Kontrollpanelen - Nätverksanslutningar

högerklicka på din internetanslutning och välj Reparera och/eller starta om datorn.

 

Varning! ComboFix förhindrar automatisk körning av CD, disketter och USB-enheter för att göra det lättare att rensa datorn och skydda datorn mot infektioner i framtiden. Det kan bli problem t ex om datorn har internet via ett USB-modem eller USB-nätverkskort. Säg då till i stället för att köra ComboFix.

 

Mvh

Mats H

Länk till kommentar
Dela på andra webbplatser

Precis som med virusprogrammen på nätet kommer det upp en varning när jag ska starta combofix om att jag inte har tillåtelse att öppna programmen. Är det ett virus som hindrar eller vad beror det på? Ska jag alltid starta i felsäkert läge?

Länk till kommentar
Dela på andra webbplatser

Nu var det ju länge sedan jag hade Comodo men om Comodo är inställt för högsta säkerhet måste man väl godkänna allt som ska köras. Kan du göra det eller sänka säkerheten i Comodo?

ComboFix fungerar bäst i normalt läge men visst går det att köra den i felsäkert.

Länk till kommentar
Dela på andra webbplatser

Men det är inte comodo som kommer med varningen utan windows. Jag kör det i felsäkert läge nu med.

Länk till kommentar
Dela på andra webbplatser

ComboFix 10-10-01.07 - Thomas 2010-10-02 19:34:56.1.2 - x86 NETWORK

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1485 [GMT 2:00]

Running from: c:\documents and settings\Thomas\My Documents\Hämtade filer\ComboFix.exe

AV: COMODO Antivirus *On-access scanning enabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}

AV: Lavasoft Ad-Watch Live! Antivirus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}

FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

.

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\documents and settings\Thomas\Application Data\inst.exe

c:\windows\Tasks\Acrobat Update.job

 

.

((((((((((((((((((((((((( Files Created from 2010-09-02 to 2010-10-02 )))))))))))))))))))))))))))))))

.

 

2010-10-01 22:31 . 2010-10-01 22:31 -------- d-----w- c:\program files\ESET

2010-10-01 18:55 . 2010-05-21 12:14 221568 ------w- c:\windows\system32\MpSigStub.exe

2010-09-30 19:51 . 2010-09-24 14:43 618128 ----a-w- c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll

2010-09-30 19:51 . 2010-09-24 14:42 644384 ----a-w- c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll

2010-09-29 19:26 . 2010-09-28 22:41 998400 ----a-w- c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\extensions\support@lastpass.com\platform\WINNT_x86_64-msvc\components\lpxpcom_x86_64.dll

2010-09-29 19:26 . 2010-09-28 22:41 834048 ----a-w- c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\extensions\support@lastpass.com\platform\WINNT_x86-msvc\components\lpxpcom.dll

2010-09-20 00:05 . 2010-09-20 00:05 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure

2010-09-15 18:03 . 2010-09-15 18:03 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard

2010-09-14 09:05 . 2010-09-14 09:05 -------- d-----w- c:\program files\iPod

2010-09-14 09:05 . 2010-09-14 09:05 -------- d-----w- c:\program files\iTunes

2010-09-14 08:57 . 2010-09-14 08:57 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 10.0.0.68\SetupAdmin.exe

2010-09-08 19:04 . 2008-10-27 08:04 514384 ----a-w- c:\windows\system32\XAudio2_3.dll

2010-09-08 19:03 . 2010-09-08 19:03 -------- d-----w- c:\windows\Logs

2010-09-07 18:52 . 2010-09-14 00:32 -------- d-----w- c:\program files\The Adventure Company

2010-09-07 18:29 . 2010-09-07 18:29 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Net

2010-09-07 18:29 . 2010-09-07 18:49 -------- d-----w- c:\documents and settings\Thomas\Application Data\DAEMON Tools Net

2010-09-07 18:28 . 2010-09-07 18:28 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Pro

2010-09-05 22:49 . 2010-09-05 22:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Tages

2010-09-05 09:26 . 2010-09-05 22:44 -------- d-----w- c:\documents and settings\Thomas\Application Data\Games

2010-09-04 23:04 . 2010-09-15 18:04 -------- d-----w- c:\program files\AGEIA Technologies

2010-09-04 23:04 . 2010-09-15 18:04 -------- d-----w- c:\windows\system32\AGEIA

2010-09-04 23:04 . 2010-09-04 23:04 281504 ----a-w- c:\windows\system32\drivers\atksgt.sys

2010-09-04 23:04 . 2010-09-04 23:04 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys

2010-09-04 21:58 . 2010-09-07 18:29 445936 ----a-w- c:\windows\system32\drivers\sptd.sys

2010-09-04 21:58 . 2010-09-04 21:58 -------- d-----w- c:\documents and settings\Thomas\Application Data\DAEMON Tools Pro

2010-09-04 09:00 . 2010-09-04 09:00 -------- d-----w- c:\program files\ASIO4ALL v2

2010-09-04 08:47 . 2005-11-09 13:23 14336 ----a-w- c:\windows\system32\drivers\madfu804.sys

2010-09-04 08:47 . 2005-11-09 13:20 6010 ----a-r- c:\windows\system32\drivers\ma004103.bin

2010-09-04 08:47 . 2005-11-09 15:00 32000 ----a-w- c:\windows\system32\drivers\MA763004.sys

2010-09-04 08:47 . 2005-11-09 13:26 49152 ----a-w- c:\windows\system32\MPInstFix.dll

2010-09-04 08:47 . 2005-11-09 13:29 163840 ----a-w- c:\windows\system32\mausbasi.dll

2010-09-04 08:46 . 2010-09-04 08:46 -------- d-----w- c:\program files\M-Audio MobilePre

2010-09-04 08:27 . 2009-09-02 12:29 158344 ----a-w- c:\windows\system32\drivers\MAudioMobilePre.sys

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-10-02 17:18 . 2010-04-02 20:45 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat

2010-10-02 12:13 . 2010-05-25 20:52 -------- d-----w- c:\program files\Common Files\CyberLink

2010-10-02 12:13 . 2010-05-25 20:51 -------- d-----w- c:\program files\CyberLink

2010-10-02 12:12 . 2010-05-25 21:25 53319 ----a-w- c:\documents and settings\All Users\Application Data\Temp\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\PostBuild.exe

2010-10-01 22:28 . 2010-04-21 21:26 -------- d-----w- c:\documents and settings\Thomas\Application Data\BitTorrent

2010-09-30 22:59 . 2010-06-02 23:15 -------- d-----w- c:\documents and settings\Thomas\Application Data\vlc

2010-09-30 20:49 . 2010-05-24 16:17 -------- d-----w- c:\documents and settings\Thomas\Application Data\dvdcss

2010-09-30 00:10 . 2010-04-02 21:33 -------- d-----w- c:\documents and settings\Thomas\Application Data\QuickScan

2010-09-29 09:48 . 2010-04-02 20:29 -------- d-----w- c:\program files\Microsoft Silverlight

2010-09-28 17:22 . 2010-04-02 20:45 -------- d-----w- c:\documents and settings\All Users\Application Data\COMODO

2010-09-28 17:21 . 2010-03-03 15:54 285480 ----a-w- c:\windows\system32\guard32.dll

2010-09-28 17:21 . 2010-03-03 15:54 91560 ----a-w- c:\windows\system32\drivers\inspect.sys

2010-09-28 17:21 . 2010-03-03 15:54 25240 ----a-w- c:\windows\system32\drivers\cmdhlp.sys

2010-09-28 17:21 . 2010-03-23 16:40 239240 ----a-w- c:\windows\system32\drivers\cmdGuard.sys

2010-09-28 17:21 . 2010-03-03 15:54 15592 ----a-w- c:\windows\system32\drivers\cmderd.sys

2010-09-22 20:38 . 2010-04-02 19:14 -------- d--h--w- c:\program files\InstallShield Installation Information

2010-09-14 09:06 . 2010-04-02 21:39 -------- d-----w- c:\program files\QT Lite

2010-09-14 09:05 . 2010-08-13 09:51 -------- d-----w- c:\program files\Common Files\Apple

2010-09-06 22:42 . 2010-04-02 21:44 -------- d-----w- c:\program files\Elaborate Bytes

2010-09-04 23:06 . 2010-09-04 23:06 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield

2010-09-04 23:02 . 2010-04-02 19:11 -------- d-----w- c:\program files\Common Files\InstallShield

2010-09-01 09:03 . 2010-04-21 21:26 -------- d-----w- c:\program files\BitTorrent

2010-08-29 22:05 . 2010-08-29 21:33 1515134079 ----a-w- c:\documents and settings\Thomas\Application Data\BitTorrent\Ableton Suite 8.1.1 Full Cracked\Setup.exe

2010-08-29 21:46 . 2010-08-30 18:30 29255168 ----a-w- c:\documents and settings\Thomas\Application Data\BitTorrent\Ableton Suite 8.1.1 Full Cracked\Crack\Crack\Crack\Live 8.1.1.exe

2010-08-29 21:46 . 2010-08-30 18:26 29255168 ----a-w- c:\documents and settings\Thomas\Application Data\BitTorrent\Ableton Suite 8.1.1 Full Cracked\Crack\Crack\Live 8.1.1.exe

2010-08-29 21:46 . 2010-08-29 21:33 29255168 ----a-w- c:\documents and settings\Thomas\Application Data\BitTorrent\Ableton Suite 8.1.1 Full Cracked\Crack\Live 8.1.1.exe

2010-08-29 20:47 . 2010-08-29 20:47 -------- d-----w- c:\program files\Ableton

2010-08-29 20:25 . 2010-04-30 09:30 -------- d-----w- c:\documents and settings\Thomas\Application Data\Ableton

2010-08-29 11:31 . 2010-08-29 11:31 -------- d-----w- c:\documents and settings\Thomas\Application Data\PACE Anti-Piracy

2010-08-29 11:30 . 2010-08-29 11:30 10710528 ----a-w- c:\documents and settings\All Users\Application Data\Line 6\L6TWXY\L6TWXY.DLL

2010-08-29 11:30 . 2010-08-29 11:30 1534464 ----a-w- c:\documents and settings\All Users\Application Data\Line 6\L6TWXY\data\twx\L6TWX.DLL

2010-08-29 11:30 . 2010-08-29 11:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Line 6

2010-08-29 11:30 . 2010-08-29 11:30 606208 ----a-w- c:\windows\system32\REX Shared Library.dll

2010-08-29 11:30 . 2010-08-29 11:30 2771968 ----a-w- c:\windows\system32\ReWire.dll

2010-08-29 11:30 . 2010-04-07 17:44 -------- d-----w- c:\documents and settings\Thomas\Application Data\Propellerhead Software

2010-08-29 11:29 . 2010-08-29 11:29 8192 ----a-r- c:\documents and settings\Thomas\Application Data\Microsoft\Installer\{26B46206-DF80-4DA2-AEAB-FF146320C344}\IconTmpl1.108DF49C_3AB4_4A7D_B6FD_8B6286B317FA.exe

2010-08-29 11:29 . 2010-08-29 11:29 30208 ----a-r- c:\documents and settings\Thomas\Application Data\Microsoft\Installer\{26B46206-DF80-4DA2-AEAB-FF146320C344}\IconTmpl.108DF49C_3AB4_4A7D_B6FD_8B6286B317FA.exe

2010-08-29 11:29 . 2010-08-29 11:29 14848 ----a-r- c:\documents and settings\Thomas\Application Data\Microsoft\Installer\{26B46206-DF80-4DA2-AEAB-FF146320C344}\IconTmpl4.A961A077_4BD0_4C98_86BC_EE4A98CE550D.exe

2010-08-29 11:28 . 2010-08-29 11:28 -------- d-----w- c:\program files\CodeMeter

2010-08-29 11:28 . 2010-04-29 21:56 -------- d-----w- c:\program files\Propellerhead

2010-08-25 20:27 . 2010-08-13 09:53 -------- d-----w- c:\documents and settings\Thomas\Application Data\Apple Computer

2010-08-22 12:04 . 2010-08-22 12:04 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}

2010-08-21 12:37 . 2010-08-20 20:30 -------- d-----w- c:\documents and settings\All Users\Application Data\regid.1986-12.com.adobe

2010-08-20 19:57 . 2010-04-02 16:36 25128 ----a-w- c:\documents and settings\Thomas\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-08-20 19:49 . 2010-04-24 20:37 -------- d-----w- c:\program files\Common Files\Adobe

2010-08-20 19:48 . 2010-08-20 19:48 -------- d-----w- c:\program files\Adobe Media Player

2010-08-20 19:47 . 2010-08-20 19:47 -------- d-----w- c:\program files\Common Files\Adobe AIR

2010-08-17 13:17 . 2004-08-10 11:00 58880 ----a-w- c:\windows\system32\spoolsv.exe

2010-08-14 09:35 . 2010-08-14 09:35 -------- d-----w- c:\program files\Common Files\Java

2010-08-14 09:35 . 2010-05-09 14:40 -------- d-----w- c:\program files\Java

2010-08-13 09:53 . 2010-08-13 09:52 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}

2010-08-13 09:52 . 2010-04-02 21:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer

2010-08-13 09:51 . 2010-08-13 09:51 -------- d-----w- c:\program files\Apple Software Update

2010-08-13 09:51 . 2010-08-13 09:51 -------- d-----w- c:\program files\Bonjour

2010-08-13 09:51 . 2010-08-13 09:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple

2010-08-12 12:16 . 2010-08-22 12:04 2979848 -c--a-w- c:\documents and settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}\Ad-AwareInstall.exe

2010-08-12 12:15 . 2010-05-28 10:26 15880 ----a-w- c:\windows\system32\lsdelete.exe

2010-08-12 12:15 . 2010-04-28 17:26 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys

2010-08-04 17:07 . 2010-08-04 17:07 61440 ----a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-63a08553-n\decora-sse.dll

2010-08-04 17:07 . 2010-08-04 17:07 503808 ----a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-508be564-n\msvcp71.dll

2010-08-04 17:07 . 2010-08-04 17:07 499712 ----a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-508be564-n\jmc.dll

2010-08-04 17:07 . 2010-08-04 17:07 348160 ----a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-508be564-n\msvcr71.dll

2010-08-04 17:07 . 2010-08-04 17:07 12800 ----a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-63a08553-n\decora-d3d.dll

2010-07-22 15:49 . 2004-08-10 11:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll

2010-07-22 05:57 . 2010-04-02 20:01 5120 ----a-w- c:\windows\system32\xpsp4res.dll

2010-07-17 03:00 . 2010-05-09 14:40 423656 ----a-w- c:\windows\system32\deployJava1.dll

2007-12-28 22:04 . 2010-09-15 22:23 1270409216 ----a-w- c:\program files\rld-shal.iso

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2010-05-10 102400]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]

"WorksFUD"="c:\program files\Microsoft Works\wkfud.exe" [2000-07-12 24576]

"Microsoft Works Portfolio"="c:\program files\Microsoft Works\WksSb.exe" [2000-07-12 311350]

"Microsoft Works Update Detection"="c:\program files\Microsoft Works\WkDetect.exe" [2000-08-30 28739]

"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]

"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]

"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-09-28 2500552]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]

"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]

"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-22 402432]

"M-Audio Taskbar Icon"="c:\windows\System32\M-AudioTaskBarIcon.exe" [2009-09-02 643592]

"QuickTime Task"="c:\program files\QT Lite\QTTask.exe" [2010-08-10 421888]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-01 421160]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

 

c:\documents and settings\All Users\Start Menu\Programs\Startup\

BankID Security Application.lnk - c:\program files\Personal\bin\Personal.exe [2010-4-26 939920]

P†minnelser f”r Kalendern i Microsoft Works.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2000-7-12 24633]

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\BitTorrent\\bittorrent.exe"=

"c:\\Program Files\\Samsung\\Samsung New PC Studio\\npsasvr.exe"=

"c:\\Program Files\\Samsung\\Samsung New PC Studio\\npsvsvr.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

"c:\\Program Files\\Real Alternative\\Media Player Classic\\mplayerc.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\CodeMeter\\Runtime\\bin\\CodeMeter.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

 

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-04-28 64288]

R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [2010-03-03 15592]

R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2010-03-03 25240]

S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2010-09-04 445936]

S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2010-03-23 239240]

S2 CodeMeter.exe;CodeMeter Runtime Server;c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe [2009-04-03 1680704]

S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-04-24 233472]

S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-08-12 1356952]

S3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [2009-12-18 11336]

S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-04-24 36608]

S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [2010-08-12 15008]

S3 MAUSBMOBILEPRE;Service for M-Audio MobilePre;c:\windows\system32\drivers\MAudioMobilePre.sys [2010-09-04 158344]

S3 MAUSBMP;Service for M-Audio Mobile Pre (WDM);c:\windows\system32\DRIVERS\mausbmp.sys --> c:\windows\system32\DRIVERS\mausbmp.sys [?]

S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [2010-04-24 90112]

S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [2010-04-24 14976]

S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [2010-04-24 121856]

S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

.

Contents of the 'Scheduled Tasks' folder

 

2010-10-02 c:\windows\Tasks\Ad-Aware Update (Weekly).job

- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-08-12 19:08]

 

2010-10-01 c:\windows\Tasks\AdobeAAMUpdater-1.0-EZRA-Thomas.job

- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2010-08-20 01:44]

 

2010-09-14 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 09:50]

.

.

------- Supplementary Scan -------

.

uInternet Settings,ProxyOverride = *.local

FF - ProfilePath - c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\

FF - component: c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll

FF - component: c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\extensions\support@lastpass.com\platform\WINNT_x86-msvc\components\lpxpcom.dll

FF - plugin: c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll

FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

FF - plugin: c:\program files\Personal\bin\np_prsnl.dll

FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin.dll

FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin2.dll

FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin3.dll

FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin4.dll

FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin5.dll

FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin6.dll

FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin7.dll

FF - plugin: c:\program files\Veetle\Player\npvlc.dll

FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll

FF - plugin: c:\program files\Veetle\VLCBroadcast\npvbp.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

 

---- FIREFOX POLICIES ----

c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");

.

- - - - ORPHANS REMOVED - - - -

 

HKLM-Run-NPSStartup - (no file)

 

 

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-10-02 19:38

Windows 5.1.2600 Service Pack 3 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

 

- - - - - - - > 'winlogon.exe'(668)

c:\windows\system32\Ati2evxx.dll

.

Completion time: 2010-10-02 19:39:49

ComboFix-quarantined-files.txt 2010-10-02 17:39

 

Pre-Run: 146 419 888 128 bytes free

Post-Run: 146 489 577 472 bytes free

 

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

UnsupportedDebug="do not select this" /debug

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

 

- - End Of File - - 168C206FF5518040FDC326629D44B2AB

Länk till kommentar
Dela på andra webbplatser

Hej,

kör en Combofix till.

Om det kommer upp en fråga om du vill installera återställningskonsolen så svara ja/yes.

Mvh

Mats H

Länk till kommentar
Dela på andra webbplatser

Jag stöter på en hel del problem. Trots att jag har stängt av både ad aware och comodo fick jag varning från combofix att de båda var på. Dessutom stängde datorn av sig två gånger när jag skannade datorn med combofix och jag fick ett blått felmeddelande. Detta har jag fått tidigare men då har det varit i anslutning till en av mina dvdspelare.

Här är i alla fall loggen:

ComboFix 10-10-01.07 - Thomas 2010-10-02 21:07:28.3.2 - x86 NETWORK

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1731 [GMT 2:00]

Running from: c:\documents and settings\Thomas\My Documents\Hämtade filer\ComboFix.exe

AV: COMODO Antivirus *On-access scanning enabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}

AV: Lavasoft Ad-Watch Live! Antivirus *On-access scanning enabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}

FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

.

 

((((((((((((((((((((((((( Files Created from 2010-09-02 to 2010-10-02 )))))))))))))))))))))))))))))))

.

 

2010-10-01 22:31 . 2010-10-01 22:31 -------- d-----w- c:\program files\ESET

2010-10-01 18:55 . 2010-05-21 12:14 221568 ------w- c:\windows\system32\MpSigStub.exe

2010-09-30 19:51 . 2010-09-24 14:43 618128 ----a-w- c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll

2010-09-30 19:51 . 2010-09-24 14:42 644384 ----a-w- c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll

2010-09-29 19:26 . 2010-09-28 22:41 998400 ----a-w- c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\extensions\support@lastpass.com\platform\WINNT_x86_64-msvc\components\lpxpcom_x86_64.dll

2010-09-29 19:26 . 2010-09-28 22:41 834048 ----a-w- c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\extensions\support@lastpass.com\platform\WINNT_x86-msvc\components\lpxpcom.dll

2010-09-20 00:05 . 2010-09-20 00:05 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure

2010-09-15 18:03 . 2010-09-15 18:03 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard

2010-09-14 09:05 . 2010-09-14 09:05 -------- d-----w- c:\program files\iPod

2010-09-14 09:05 . 2010-09-14 09:05 -------- d-----w- c:\program files\iTunes

2010-09-14 08:57 . 2010-09-14 08:57 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 10.0.0.68\SetupAdmin.exe

2010-09-08 19:04 . 2008-10-27 08:04 514384 ----a-w- c:\windows\system32\XAudio2_3.dll

2010-09-08 19:03 . 2010-09-08 19:03 -------- d-----w- c:\windows\Logs

2010-09-07 18:52 . 2010-09-14 00:32 -------- d-----w- c:\program files\The Adventure Company

2010-09-07 18:29 . 2010-09-07 18:29 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Net

2010-09-07 18:29 . 2010-09-07 18:49 -------- d-----w- c:\documents and settings\Thomas\Application Data\DAEMON Tools Net

2010-09-07 18:28 . 2010-09-07 18:28 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Pro

2010-09-05 22:49 . 2010-09-05 22:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Tages

2010-09-05 09:26 . 2010-09-05 22:44 -------- d-----w- c:\documents and settings\Thomas\Application Data\Games

2010-09-04 23:04 . 2010-09-15 18:04 -------- d-----w- c:\program files\AGEIA Technologies

2010-09-04 23:04 . 2010-09-15 18:04 -------- d-----w- c:\windows\system32\AGEIA

2010-09-04 23:04 . 2010-09-04 23:04 281504 ----a-w- c:\windows\system32\drivers\atksgt.sys

2010-09-04 23:04 . 2010-09-04 23:04 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys

2010-09-04 21:58 . 2010-09-07 18:29 445936 ----a-w- c:\windows\system32\drivers\sptd.sys

2010-09-04 21:58 . 2010-09-04 21:58 -------- d-----w- c:\documents and settings\Thomas\Application Data\DAEMON Tools Pro

2010-09-04 09:00 . 2010-09-04 09:00 -------- d-----w- c:\program files\ASIO4ALL v2

2010-09-04 08:47 . 2005-11-09 13:23 14336 ----a-w- c:\windows\system32\drivers\madfu804.sys

2010-09-04 08:47 . 2005-11-09 13:20 6010 ----a-r- c:\windows\system32\drivers\ma004103.bin

2010-09-04 08:47 . 2005-11-09 15:00 32000 ----a-w- c:\windows\system32\drivers\MA763004.sys

2010-09-04 08:47 . 2005-11-09 13:26 49152 ----a-w- c:\windows\system32\MPInstFix.dll

2010-09-04 08:47 . 2005-11-09 13:29 163840 ----a-w- c:\windows\system32\mausbasi.dll

2010-09-04 08:46 . 2010-09-04 08:46 -------- d-----w- c:\program files\M-Audio MobilePre

2010-09-04 08:27 . 2009-09-02 12:29 158344 ----a-w- c:\windows\system32\drivers\MAudioMobilePre.sys

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-10-02 18:45 . 2010-04-02 20:45 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat

2010-10-02 18:26 . 2010-04-21 21:26 -------- d-----w- c:\documents and settings\Thomas\Application Data\BitTorrent

2010-10-02 18:11 . 2010-06-02 23:15 -------- d-----w- c:\documents and settings\Thomas\Application Data\vlc

2010-10-02 12:13 . 2010-05-25 20:52 -------- d-----w- c:\program files\Common Files\CyberLink

2010-10-02 12:13 . 2010-05-25 20:51 -------- d-----w- c:\program files\CyberLink

2010-10-02 12:12 . 2010-05-25 21:25 53319 ----a-w- c:\documents and settings\All Users\Application Data\Temp\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\PostBuild.exe

2010-09-30 20:49 . 2010-05-24 16:17 -------- d-----w- c:\documents and settings\Thomas\Application Data\dvdcss

2010-09-30 00:10 . 2010-04-02 21:33 -------- d-----w- c:\documents and settings\Thomas\Application Data\QuickScan

2010-09-29 09:48 . 2010-04-02 20:29 -------- d-----w- c:\program files\Microsoft Silverlight

2010-09-28 17:22 . 2010-04-02 20:45 -------- d-----w- c:\documents and settings\All Users\Application Data\COMODO

2010-09-28 17:21 . 2010-03-03 15:54 285480 ----a-w- c:\windows\system32\guard32.dll

2010-09-28 17:21 . 2010-03-03 15:54 91560 ----a-w- c:\windows\system32\drivers\inspect.sys

2010-09-28 17:21 . 2010-03-03 15:54 25240 ----a-w- c:\windows\system32\drivers\cmdhlp.sys

2010-09-28 17:21 . 2010-03-23 16:40 239240 ----a-w- c:\windows\system32\drivers\cmdGuard.sys

2010-09-28 17:21 . 2010-03-03 15:54 15592 ----a-w- c:\windows\system32\drivers\cmderd.sys

2010-09-22 20:38 . 2010-04-02 19:14 -------- d--h--w- c:\program files\InstallShield Installation Information

2010-09-14 09:06 . 2010-04-02 21:39 -------- d-----w- c:\program files\QT Lite

2010-09-14 09:05 . 2010-08-13 09:51 -------- d-----w- c:\program files\Common Files\Apple

2010-09-06 22:42 . 2010-04-02 21:44 -------- d-----w- c:\program files\Elaborate Bytes

2010-09-04 23:06 . 2010-09-04 23:06 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield

2010-09-04 23:02 . 2010-04-02 19:11 -------- d-----w- c:\program files\Common Files\InstallShield

2010-09-01 09:03 . 2010-04-21 21:26 -------- d-----w- c:\program files\BitTorrent

2010-08-29 22:05 . 2010-08-29 21:33 1515134079 ----a-w- c:\documents and settings\Thomas\Application Data\BitTorrent\Ableton Suite 8.1.1 Full Cracked\Setup.exe

2010-08-29 21:46 . 2010-08-30 18:30 29255168 ----a-w- c:\documents and settings\Thomas\Application Data\BitTorrent\Ableton Suite 8.1.1 Full Cracked\Crack\Crack\Crack\Live 8.1.1.exe

2010-08-29 21:46 . 2010-08-30 18:26 29255168 ----a-w- c:\documents and settings\Thomas\Application Data\BitTorrent\Ableton Suite 8.1.1 Full Cracked\Crack\Crack\Live 8.1.1.exe

2010-08-29 21:46 . 2010-08-29 21:33 29255168 ----a-w- c:\documents and settings\Thomas\Application Data\BitTorrent\Ableton Suite 8.1.1 Full Cracked\Crack\Live 8.1.1.exe

2010-08-29 20:47 . 2010-08-29 20:47 -------- d-----w- c:\program files\Ableton

2010-08-29 20:25 . 2010-04-30 09:30 -------- d-----w- c:\documents and settings\Thomas\Application Data\Ableton

2010-08-29 11:31 . 2010-08-29 11:31 -------- d-----w- c:\documents and settings\Thomas\Application Data\PACE Anti-Piracy

2010-08-29 11:30 . 2010-08-29 11:30 10710528 ----a-w- c:\documents and settings\All Users\Application Data\Line 6\L6TWXY\L6TWXY.DLL

2010-08-29 11:30 . 2010-08-29 11:30 1534464 ----a-w- c:\documents and settings\All Users\Application Data\Line 6\L6TWXY\data\twx\L6TWX.DLL

2010-08-29 11:30 . 2010-08-29 11:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Line 6

2010-08-29 11:30 . 2010-08-29 11:30 606208 ----a-w- c:\windows\system32\REX Shared Library.dll

2010-08-29 11:30 . 2010-08-29 11:30 2771968 ----a-w- c:\windows\system32\ReWire.dll

2010-08-29 11:30 . 2010-04-07 17:44 -------- d-----w- c:\documents and settings\Thomas\Application Data\Propellerhead Software

2010-08-29 11:29 . 2010-08-29 11:29 8192 ----a-r- c:\documents and settings\Thomas\Application Data\Microsoft\Installer\{26B46206-DF80-4DA2-AEAB-FF146320C344}\IconTmpl1.108DF49C_3AB4_4A7D_B6FD_8B6286B317FA.exe

2010-08-29 11:29 . 2010-08-29 11:29 30208 ----a-r- c:\documents and settings\Thomas\Application Data\Microsoft\Installer\{26B46206-DF80-4DA2-AEAB-FF146320C344}\IconTmpl.108DF49C_3AB4_4A7D_B6FD_8B6286B317FA.exe

2010-08-29 11:29 . 2010-08-29 11:29 14848 ----a-r- c:\documents and settings\Thomas\Application Data\Microsoft\Installer\{26B46206-DF80-4DA2-AEAB-FF146320C344}\IconTmpl4.A961A077_4BD0_4C98_86BC_EE4A98CE550D.exe

2010-08-29 11:28 . 2010-08-29 11:28 -------- d-----w- c:\program files\CodeMeter

2010-08-29 11:28 . 2010-04-29 21:56 -------- d-----w- c:\program files\Propellerhead

2010-08-25 20:27 . 2010-08-13 09:53 -------- d-----w- c:\documents and settings\Thomas\Application Data\Apple Computer

2010-08-22 12:04 . 2010-08-22 12:04 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}

2010-08-21 12:37 . 2010-08-20 20:30 -------- d-----w- c:\documents and settings\All Users\Application Data\regid.1986-12.com.adobe

2010-08-20 19:57 . 2010-04-02 16:36 25128 ----a-w- c:\documents and settings\Thomas\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-08-20 19:49 . 2010-04-24 20:37 -------- d-----w- c:\program files\Common Files\Adobe

2010-08-20 19:48 . 2010-08-20 19:48 -------- d-----w- c:\program files\Adobe Media Player

2010-08-20 19:47 . 2010-08-20 19:47 -------- d-----w- c:\program files\Common Files\Adobe AIR

2010-08-17 13:17 . 2004-08-10 11:00 58880 ----a-w- c:\windows\system32\spoolsv.exe

2010-08-14 09:35 . 2010-08-14 09:35 -------- d-----w- c:\program files\Common Files\Java

2010-08-14 09:35 . 2010-05-09 14:40 -------- d-----w- c:\program files\Java

2010-08-13 09:53 . 2010-08-13 09:52 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}

2010-08-13 09:52 . 2010-04-02 21:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer

2010-08-13 09:51 . 2010-08-13 09:51 -------- d-----w- c:\program files\Apple Software Update

2010-08-13 09:51 . 2010-08-13 09:51 -------- d-----w- c:\program files\Bonjour

2010-08-13 09:51 . 2010-08-13 09:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple

2010-08-12 12:16 . 2010-08-22 12:04 2979848 -c--a-w- c:\documents and settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}\Ad-AwareInstall.exe

2010-08-12 12:15 . 2010-05-28 10:26 15880 ----a-w- c:\windows\system32\lsdelete.exe

2010-08-12 12:15 . 2010-04-28 17:26 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys

2010-08-04 17:07 . 2010-08-04 17:07 61440 ----a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-63a08553-n\decora-sse.dll

2010-08-04 17:07 . 2010-08-04 17:07 503808 ----a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-508be564-n\msvcp71.dll

2010-08-04 17:07 . 2010-08-04 17:07 499712 ----a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-508be564-n\jmc.dll

2010-08-04 17:07 . 2010-08-04 17:07 348160 ----a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-508be564-n\msvcr71.dll

2010-08-04 17:07 . 2010-08-04 17:07 12800 ----a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-63a08553-n\decora-d3d.dll

2010-07-22 15:49 . 2004-08-10 11:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll

2010-07-22 05:57 . 2010-04-02 20:01 5120 ----a-w- c:\windows\system32\xpsp4res.dll

2010-07-17 03:00 . 2010-05-09 14:40 423656 ----a-w- c:\windows\system32\deployJava1.dll

2007-12-28 22:04 . 2010-09-15 22:23 1270409216 ----a-w- c:\program files\rld-shal.iso

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2010-05-10 102400]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]

"WorksFUD"="c:\program files\Microsoft Works\wkfud.exe" [2000-07-12 24576]

"Microsoft Works Portfolio"="c:\program files\Microsoft Works\WksSb.exe" [2000-07-12 311350]

"Microsoft Works Update Detection"="c:\program files\Microsoft Works\WkDetect.exe" [2000-08-30 28739]

"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]

"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]

"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-09-28 2500552]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]

"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]

"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-22 402432]

"M-Audio Taskbar Icon"="c:\windows\System32\M-AudioTaskBarIcon.exe" [2009-09-02 643592]

"QuickTime Task"="c:\program files\QT Lite\QTTask.exe" [2010-08-10 421888]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-01 421160]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

 

c:\documents and settings\All Users\Start Menu\Programs\Startup\

BankID Security Application.lnk - c:\program files\Personal\bin\Personal.exe [2010-4-26 939920]

P†minnelser f”r Kalendern i Microsoft Works.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2000-7-12 24633]

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\BitTorrent\\bittorrent.exe"=

"c:\\Program Files\\Samsung\\Samsung New PC Studio\\npsasvr.exe"=

"c:\\Program Files\\Samsung\\Samsung New PC Studio\\npsvsvr.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

"c:\\Program Files\\Real Alternative\\Media Player Classic\\mplayerc.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\CodeMeter\\Runtime\\bin\\CodeMeter.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

 

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-04-28 64288]

R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [2010-03-03 15592]

R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2010-03-03 25240]

S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2010-03-23 239240]

S2 CodeMeter.exe;CodeMeter Runtime Server;c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe [2009-04-03 1680704]

S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-04-24 233472]

S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-08-12 1356952]

S3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [2009-12-18 11336]

S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-04-24 36608]

S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [2010-08-12 15008]

S3 MAUSBMOBILEPRE;Service for M-Audio MobilePre;c:\windows\system32\drivers\MAudioMobilePre.sys [2010-09-04 158344]

S3 MAUSBMP;Service for M-Audio Mobile Pre (WDM);c:\windows\system32\DRIVERS\mausbmp.sys --> c:\windows\system32\DRIVERS\mausbmp.sys [?]

S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [2010-04-24 90112]

S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [2010-04-24 14976]

S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [2010-04-24 121856]

S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2010-09-04 445936]

.

Contents of the 'Scheduled Tasks' folder

 

2010-10-02 c:\windows\Tasks\Ad-Aware Update (Weekly).job

- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-08-12 19:08]

 

2010-10-01 c:\windows\Tasks\AdobeAAMUpdater-1.0-EZRA-Thomas.job

- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2010-08-20 01:44]

 

2010-09-14 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 09:50]

.

.

------- Supplementary Scan -------

.

uInternet Settings,ProxyOverride = *.local

FF - ProfilePath - c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\

FF - component: c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll

FF - component: c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\extensions\support@lastpass.com\platform\WINNT_x86-msvc\components\lpxpcom.dll

FF - plugin: c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll

FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

FF - plugin: c:\program files\Personal\bin\np_prsnl.dll

FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin.dll

FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin2.dll

FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin3.dll

FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin4.dll

FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin5.dll

FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin6.dll

FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin7.dll

FF - plugin: c:\program files\Veetle\Player\npvlc.dll

FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll

FF - plugin: c:\program files\Veetle\VLCBroadcast\npvbp.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

 

---- FIREFOX POLICIES ----

c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");

.

 

**************************************************************************

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files:

 

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

 

- - - - - - - > 'winlogon.exe'(668)

c:\windows\system32\Ati2evxx.dll

 

- - - - - - - > 'explorer.exe'(528)

c:\windows\system32\WININET.dll

.

Completion time: 2010-10-02 21:13:55

ComboFix-quarantined-files.txt 2010-10-02 19:13

ComboFix2.txt 2010-10-02 17:39

 

Pre-Run: 146 468 843 520 bytes free

Post-Run: 146 454 003 712 bytes free

 

- - End Of File - - 71FEFCCED08218B93006B1711D776C87

Länk till kommentar
Dela på andra webbplatser

Hej,

Spara Rootkit Unhooker på skrivbordet.

http://www.rootkit.com/vault/DiabloNova/RKUnhookerLE.EXE

 

Dra ut internetanslutningen. Stäng av alla program du ser inklusive brandvägg, antivirusprogram och antispionprogram.

 

Dubbelklicka på Rootkit Unhooker för att starta det (i Vista och Windows 7 högerklicka och välj Kör som administratör).

Välj fliken Report och klicka på Scan

Bocka för Drivers, Stealth, Files och Code Hooks, men avbocka de andra valen.

Tryck på OK

Vänta tills skannern är klar och då väljer du File - Save Report. Spara rapporten på Skrivbordet eller på något annat ställe där du hittar igen den. Klicka på Close

 

Öppna den sparade rapporten i Anteckningar. Klistra in innehållet i ditt svar.

 

Observera att om det kommer upp en varning "Rootkit Unhooker has detected a parasite..." så ignorera den bara.

Mvh

Mats H

Länk till kommentar
Dela på andra webbplatser

Tyvärr kan jag inte öppna filen. Det kommer en varning med texten "error loading/opening driver". Jag har försökt flera gånger (och stängt av alla program) trots att jag har det i felsäkert läge (i vanligt läge kom det upp samma varning om att jag inte har tillåtelse att öppna programmet).

Länk till kommentar
Dela på andra webbplatser

Hej,

då får vi prova detta istället.

Spara TDSSKiller på Skrivbordet:

http://support.kaspersky.com/downloads/utils/tdsskiller.zip

 

Högerklicka och välj Extrahera alla. Kom ihåg var du packar upp filen.

Stäng av dina vanliga program, men du kan lämna antivirusprogram och liknande igång.

Kör programmet TDSSKiller.exe som finns i mappen där du packade upp filerna.

 

Klicka på Start Scan.

 

Om några hot hittas så välj Cure och klicka på Continue. Eventuellt behöver datorn startas om.

 

Klistra in innehållet i loggen som du hittar i C:\ med namnet TDSSKiller följt av version och tidpunkt.

Mvh

Mats H

Länk till kommentar
Dela på andra webbplatser

Det gick bättre, tack!

Här kommer rapporten:

2010/10/03 17:32:01.0181 TDSS rootkit removing tool 2.4.3.0 Sep 27 2010 15:28:54

2010/10/03 17:32:01.0181 ================================================================================

2010/10/03 17:32:01.0181 SystemInfo:

2010/10/03 17:32:01.0181

2010/10/03 17:32:01.0181 OS Version: 5.1.2600 ServicePack: 3.0

2010/10/03 17:32:01.0181 Product type: Workstation

2010/10/03 17:32:01.0181 ComputerName: EZRA

2010/10/03 17:32:01.0181 UserName: Thomas

2010/10/03 17:32:01.0181 Windows directory: C:\WINDOWS

2010/10/03 17:32:01.0181 System windows directory: C:\WINDOWS

2010/10/03 17:32:01.0181 Processor architecture: Intel x86

2010/10/03 17:32:01.0181 Number of processors: 2

2010/10/03 17:32:01.0181 Page size: 0x1000

2010/10/03 17:32:01.0181 Boot type: Normal boot

2010/10/03 17:32:01.0181 ================================================================================

2010/10/03 17:32:01.0416 Initialize success

2010/10/03 17:32:18.0818 ================================================================================

2010/10/03 17:32:18.0818 Scan started

2010/10/03 17:32:18.0818 Mode: Manual;

2010/10/03 17:32:18.0818 ================================================================================

2010/10/03 17:32:19.0115 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys

2010/10/03 17:32:19.0146 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys

2010/10/03 17:32:19.0209 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys

2010/10/03 17:32:19.0240 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys

2010/10/03 17:32:19.0334 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys

2010/10/03 17:32:19.0412 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys

2010/10/03 17:32:19.0427 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys

2010/10/03 17:32:19.0521 ati2mtag (c0b86ecb324e50f6bbd529f9d5c6b24b) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys

2010/10/03 17:32:19.0599 atksgt (70f72c50d39f5afa76c17f86223a7c4f) C:\WINDOWS\system32\DRIVERS\atksgt.sys

2010/10/03 17:32:19.0615 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys

2010/10/03 17:32:19.0662 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys

2010/10/03 17:32:19.0693 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys

2010/10/03 17:32:19.0818 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys

2010/10/03 17:32:19.0849 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys

2010/10/03 17:32:19.0880 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys

2010/10/03 17:32:19.0896 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys

2010/10/03 17:32:19.0943 cercsr6 (84853b3fd012251690570e9e7e43343f) C:\WINDOWS\system32\drivers\cercsr6.sys

2010/10/03 17:32:20.0005 cmderd (7060bae48c2c122f3041cccf9ade3bf7) C:\WINDOWS\system32\DRIVERS\cmderd.sys

2010/10/03 17:32:20.0021 cmdGuard (bbe9f023dfd2c4d2755da3fa47e4da08) C:\WINDOWS\system32\DRIVERS\cmdguard.sys

2010/10/03 17:32:20.0037 cmdHlp (111e6755acb5f236e2465e24508f6367) C:\WINDOWS\system32\DRIVERS\cmdhlp.sys

2010/10/03 17:32:20.0146 cpudrv (d01f685f8b4598d144b0cce9ff95d8d5) C:\Program Files\SystemRequirementsLab\cpudrv.sys

2010/10/03 17:32:20.0209 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys

2010/10/03 17:32:20.0255 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys

2010/10/03 17:32:20.0271 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys

2010/10/03 17:32:20.0302 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys

2010/10/03 17:32:20.0349 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys

2010/10/03 17:32:20.0380 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys

2010/10/03 17:32:20.0412 e1express (5b75bbf89d8341f424171df7ad9dc465) C:\WINDOWS\system32\DRIVERS\e1e5132.sys

2010/10/03 17:32:20.0474 ELacpi (1976fedf6d7f87135c9b7f5cb4c8c868) C:\WINDOWS\system32\DRIVERS\ELacpi.sys

2010/10/03 17:32:20.0490 ELhid (ae65c02444907966378454138b9f99f0) C:\WINDOWS\system32\DRIVERS\ELhid.sys

2010/10/03 17:32:20.0505 ELkbd (e485c3ba1daddeef3e14fea1e8fda6e1) C:\WINDOWS\system32\DRIVERS\ELkbd.sys

2010/10/03 17:32:20.0521 ELmon (0d87cb825ed6cb2ebcc147a10a42f1d6) C:\WINDOWS\system32\DRIVERS\ELmon.sys

2010/10/03 17:32:20.0537 ELmou (a4add3847b67bacab6fc851a2b60fdb3) C:\WINDOWS\system32\DRIVERS\ELmou.sys

2010/10/03 17:32:20.0583 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys

2010/10/03 17:32:20.0599 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys

2010/10/03 17:32:20.0615 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys

2010/10/03 17:32:20.0630 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys

2010/10/03 17:32:20.0662 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys

2010/10/03 17:32:20.0693 FsUsbExDisk (790a4ca68f44be35967b3df61f3e4675) C:\WINDOWS\system32\FsUsbExDisk.SYS

2010/10/03 17:32:20.0740 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys

2010/10/03 17:32:20.0771 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys

2010/10/03 17:32:20.0802 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys

2010/10/03 17:32:20.0818 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys

2010/10/03 17:32:20.0833 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys

2010/10/03 17:32:20.0880 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys

2010/10/03 17:32:20.0943 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\drivers\i8042prt.sys

2010/10/03 17:32:20.0974 iastor (9a65e42664d1534b68512caad0efe963) C:\WINDOWS\system32\DRIVERS\iaStor.sys

2010/10/03 17:32:20.0990 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys

2010/10/03 17:32:21.0036 Inspect (343ac4733c1e8b7ab6454178e4fcd4ad) C:\WINDOWS\system32\DRIVERS\inspect.sys

2010/10/03 17:32:21.0068 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys

2010/10/03 17:32:21.0083 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys

2010/10/03 17:32:21.0115 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys

2010/10/03 17:32:21.0146 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys

2010/10/03 17:32:21.0161 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys

2010/10/03 17:32:21.0193 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys

2010/10/03 17:32:21.0224 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys

2010/10/03 17:32:21.0240 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys

2010/10/03 17:32:21.0255 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys

2010/10/03 17:32:21.0271 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys

2010/10/03 17:32:21.0302 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys

2010/10/03 17:32:21.0333 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys

2010/10/03 17:32:21.0365 Lbd (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\WINDOWS\system32\DRIVERS\Lbd.sys

2010/10/03 17:32:21.0427 lirsgt (f8a7212d0864ef5e9185fb95e6623f4d) C:\WINDOWS\system32\DRIVERS\lirsgt.sys

2010/10/03 17:32:21.0458 ma763004 (f0bc9e9d3e52c721fd4d5fb59167318e) C:\WINDOWS\system32\drivers\MA763004.sys

2010/10/03 17:32:21.0505 MAUSBMOBILEPRE (9905de84749e28ebda8eb2de377681eb) C:\WINDOWS\system32\DRIVERS\MAudioMobilePre.sys

2010/10/03 17:32:21.0552 mcdbus (8fd868e32459ece2a1bb0169f513d31e) C:\WINDOWS\system32\DRIVERS\mcdbus.sys

2010/10/03 17:32:21.0614 MHNDRV (7f2f1d2815a6449d346fcccbc569fbd6) C:\WINDOWS\system32\DRIVERS\mhndrv.sys

2010/10/03 17:32:21.0630 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys

2010/10/03 17:32:21.0677 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys

2010/10/03 17:32:21.0693 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys

2010/10/03 17:32:21.0724 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys

2010/10/03 17:32:21.0739 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys

2010/10/03 17:32:21.0771 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys

2010/10/03 17:32:21.0802 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys

2010/10/03 17:32:21.0833 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys

2010/10/03 17:32:21.0880 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys

2010/10/03 17:32:21.0896 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys

2010/10/03 17:32:21.0911 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys

2010/10/03 17:32:21.0943 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys

2010/10/03 17:32:21.0958 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys

2010/10/03 17:32:22.0005 NAL (7f16ee8322ebdf3c3b2d1a69f8030fd4) C:\WINDOWS\system32\Drivers\iqvw32.sys

2010/10/03 17:32:22.0052 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys

2010/10/03 17:32:22.0083 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys

2010/10/03 17:32:22.0099 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys

2010/10/03 17:32:22.0114 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys

2010/10/03 17:32:22.0130 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys

2010/10/03 17:32:22.0146 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys

2010/10/03 17:32:22.0177 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys

2010/10/03 17:32:22.0239 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys

2010/10/03 17:32:22.0286 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys

2010/10/03 17:32:22.0317 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys

2010/10/03 17:32:22.0364 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys

2010/10/03 17:32:22.0427 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys

2010/10/03 17:32:22.0442 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys

2010/10/03 17:32:22.0458 NwlnkIpx (8b8b1be2dba4025da6786c645f77f123) C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys

2010/10/03 17:32:22.0489 NwlnkNb (56d34a67c05e94e16377c60609741ff8) C:\WINDOWS\system32\DRIVERS\nwlnknb.sys

2010/10/03 17:32:22.0521 NwlnkSpx (c0bb7d1615e1acbdc99757f6ceaf8cf0) C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys

2010/10/03 17:32:22.0536 NWRDR (36b9b950e3d2e100970a48d8bad86740) C:\WINDOWS\system32\DRIVERS\nwrdr.sys

2010/10/03 17:32:22.0552 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys

2010/10/03 17:32:22.0583 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys

2010/10/03 17:32:22.0599 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys

2010/10/03 17:32:22.0630 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys

2010/10/03 17:32:22.0661 pccsmcfd (175cc28dcf819f78caa3fbd44ad9e52a) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys

2010/10/03 17:32:22.0677 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys

2010/10/03 17:32:22.0739 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys

2010/10/03 17:32:22.0771 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys

2010/10/03 17:32:22.0802 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys

2010/10/03 17:32:22.0974 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys

2010/10/03 17:32:22.0989 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys

2010/10/03 17:32:23.0020 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys

2010/10/03 17:32:23.0052 PxHelp20 (617accada2e0a0f43ec6030bbac49513) C:\WINDOWS\system32\Drivers\PxHelp20.sys

2010/10/03 17:32:23.0161 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys

2010/10/03 17:32:23.0177 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys

2010/10/03 17:32:23.0224 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys

2010/10/03 17:32:23.0239 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys

2010/10/03 17:32:23.0270 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys

2010/10/03 17:32:23.0302 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys

2010/10/03 17:32:23.0333 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys

2010/10/03 17:32:23.0364 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys

2010/10/03 17:32:23.0395 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys

2010/10/03 17:32:23.0489 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys

2010/10/03 17:32:23.0536 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys

2010/10/03 17:32:23.0583 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys

2010/10/03 17:32:23.0677 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys

2010/10/03 17:32:23.0723 sptd (ef4e4e1775db542c767dd0c7b46db926) C:\WINDOWS\system32\Drivers\sptd.sys

2010/10/03 17:32:23.0755 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys

2010/10/03 17:32:23.0786 Srv (da852e3e0bf1cea75d756f9866241e57) C:\WINDOWS\system32\DRIVERS\srv.sys

2010/10/03 17:32:23.0833 ss_bbus (eaa66218cd39f5bb1b4853a78c67c787) C:\WINDOWS\system32\DRIVERS\ss_bbus.sys

2010/10/03 17:32:23.0864 ss_bmdfl (91765f99914ed8693d8bc76524f21581) C:\WINDOWS\system32\DRIVERS\ss_bmdfl.sys

2010/10/03 17:32:23.0895 ss_bmdm (840e7b738b03c10ee91d9b7d3d6eff15) C:\WINDOWS\system32\DRIVERS\ss_bmdm.sys

2010/10/03 17:32:23.0927 StarOpen (306521935042fc0a6988d528643619b3) C:\WINDOWS\system32\drivers\StarOpen.sys

2010/10/03 17:32:23.0958 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys

2010/10/03 17:32:23.0989 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys

2010/10/03 17:32:24.0114 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys

2010/10/03 17:32:24.0176 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys

2010/10/03 17:32:24.0223 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys

2010/10/03 17:32:24.0270 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys

2010/10/03 17:32:24.0301 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys

2010/10/03 17:32:24.0411 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys

2010/10/03 17:32:24.0458 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys

2010/10/03 17:32:24.0520 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys

2010/10/03 17:32:24.0536 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys

2010/10/03 17:32:24.0567 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys

2010/10/03 17:32:24.0583 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys

2010/10/03 17:32:24.0598 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

2010/10/03 17:32:24.0630 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys

2010/10/03 17:32:24.0645 VClone (94d73b62e458fb56c9ce60aa96d914f9) C:\WINDOWS\system32\DRIVERS\VClone.sys

2010/10/03 17:32:24.0676 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys

2010/10/03 17:32:24.0708 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys

2010/10/03 17:32:24.0754 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys

2010/10/03 17:32:24.0801 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys

2010/10/03 17:32:24.0942 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys

2010/10/03 17:32:24.0989 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys

2010/10/03 17:32:25.0020 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys

2010/10/03 17:32:25.0098 ================================================================================

2010/10/03 17:32:25.0098 Scan finished

2010/10/03 17:32:25.0098 ================================================================================

Länk till kommentar
Dela på andra webbplatser

Hej,

ingen känd TDSS infektion,

vi fortsätter med detta:

Ladda ner mbr.exe till Skrivbordet:

http://www2.gmer.net/mbr/mbr.exe

 

Start - Kör

Kopiera raden som är i rutan nedan och klistra in i Kör-fältet.

"%userprofile%\desktop\mbr.exe" -t > "C:\mbr.log"

Klistra in innehållet i mbr.log som skapas i C:\.

 

Obs! Dra ur internetanslutningen och inaktivera/stäng av antivirus- och andra säkerhetsprogram innan du kör mbr.exe.

 

Mvh

Mats H

Länk till kommentar
Dela på andra webbplatser

När jag startade programmet dök en svart ruta upp och försvann på en gång (jag har testat flera gånger med samma resultat. Därför kunde jag inte klistra in texten. Den enda fil jag hittade hade den här texten:

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

 

device: opened successfully

user: MBR read successfully

kernel: MBR read successfully

user & kernel MBR OK

Länk till kommentar
Dela på andra webbplatser

Du ska inte starta programmet på det sättet utan klicka på Start-knappen och välj Kör.

 

I rutan/fältet som kommer upp skriver du in (eller klistrar in):

"%userprofile%\desktop\mbr.exe" -t > "C:\mbr.log"
Länk till kommentar
Dela på andra webbplatser

Efter att ha sökt hittade jag en i combofix. Kan det vara den här?

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

 

device: opened successfully

user: MBR read successfully

kernel: MBR read successfully

detected MBR rootkit hooks:

\Driver\Disk -> CLASSPNP.SYS @ 0xf765bf28

\Driver\ACPI -> ACPI.sys @ 0xf75aecb8

\Driver\atapi -> atapi.sys @ 0xf74a0852

\Driver\iaStor -> iaStor.sys @ 0xf7b1cb10

IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805e710a

ParseProcedure -> ntoskrnl.exe @ 0x80578f7a

\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805e710a

ParseProcedure -> ntoskrnl.exe @ 0x80578f7a

user & kernel MBR OK

Länk till kommentar
Dela på andra webbplatser

Så:

ComboFix 10-10-02.02 - Thomas 2010-10-03 19:59:11.4.2 - x86 NETWORK

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1508 [GMT 2:00]

Running from: c:\documents and settings\Thomas\My Documents\Hämtade filer\ComboFix.exe

AV: COMODO Antivirus *On-access scanning enabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}

AV: Lavasoft Ad-Watch Live! Antivirus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}

FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

.

 

((((((((((((((((((((((((( Files Created from 2010-09-03 to 2010-10-03 )))))))))))))))))))))))))))))))

.

 

2010-10-03 17:03 . 2010-10-03 17:03 664 ----a-w- c:\windows\system32\d3d9caps.dat

2010-10-02 23:06 . 2010-10-02 23:06 -------- d-----w- c:\program files\MagicDisc

2010-10-02 23:06 . 2009-02-24 16:42 116736 ----a-w- c:\windows\system32\drivers\mcdbus.sys

2010-10-01 22:31 . 2010-10-01 22:31 -------- d-----w- c:\program files\ESET

2010-10-01 18:55 . 2010-05-21 12:14 221568 ------w- c:\windows\system32\MpSigStub.exe

2010-09-30 19:51 . 2010-09-24 14:43 618128 ----a-w- c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll

2010-09-30 19:51 . 2010-09-24 14:42 644384 ----a-w- c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll

2010-09-29 19:26 . 2010-09-28 22:41 998400 ----a-w- c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\extensions\support@lastpass.com\platform\WINNT_x86_64-msvc\components\lpxpcom_x86_64.dll

2010-09-29 19:26 . 2010-09-28 22:41 834048 ----a-w- c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\extensions\support@lastpass.com\platform\WINNT_x86-msvc\components\lpxpcom.dll

2010-09-20 00:05 . 2010-09-20 00:05 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure

2010-09-15 18:03 . 2010-09-15 18:03 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard

2010-09-14 09:05 . 2010-09-14 09:05 -------- d-----w- c:\program files\iPod

2010-09-14 09:05 . 2010-09-14 09:05 -------- d-----w- c:\program files\iTunes

2010-09-14 08:57 . 2010-09-14 08:57 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 10.0.0.68\SetupAdmin.exe

2010-09-08 19:04 . 2008-10-27 08:04 514384 ----a-w- c:\windows\system32\XAudio2_3.dll

2010-09-08 19:03 . 2010-09-08 19:03 -------- d-----w- c:\windows\Logs

2010-09-07 18:52 . 2010-09-14 00:32 -------- d-----w- c:\program files\The Adventure Company

2010-09-07 18:29 . 2010-09-07 18:29 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Net

2010-09-07 18:29 . 2010-09-07 18:49 -------- d-----w- c:\documents and settings\Thomas\Application Data\DAEMON Tools Net

2010-09-07 18:28 . 2010-09-07 18:28 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Pro

2010-09-05 22:49 . 2010-09-05 22:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Tages

2010-09-05 09:26 . 2010-09-05 22:44 -------- d-----w- c:\documents and settings\Thomas\Application Data\Games

2010-09-04 23:04 . 2010-09-15 18:04 -------- d-----w- c:\program files\AGEIA Technologies

2010-09-04 23:04 . 2010-09-15 18:04 -------- d-----w- c:\windows\system32\AGEIA

2010-09-04 23:04 . 2010-09-04 23:04 281504 ----a-w- c:\windows\system32\drivers\atksgt.sys

2010-09-04 23:04 . 2010-09-04 23:04 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys

2010-09-04 21:58 . 2010-09-07 18:29 445936 ----a-w- c:\windows\system32\drivers\sptd.sys

2010-09-04 21:58 . 2010-09-04 21:58 -------- d-----w- c:\documents and settings\Thomas\Application Data\DAEMON Tools Pro

2010-09-04 09:00 . 2010-09-04 09:00 -------- d-----w- c:\program files\ASIO4ALL v2

2010-09-04 08:47 . 2005-11-09 13:23 14336 ----a-w- c:\windows\system32\drivers\madfu804.sys

2010-09-04 08:47 . 2005-11-09 13:20 6010 ----a-r- c:\windows\system32\drivers\ma004103.bin

2010-09-04 08:47 . 2005-11-09 15:00 32000 ----a-w- c:\windows\system32\drivers\MA763004.sys

2010-09-04 08:47 . 2005-11-09 13:26 49152 ----a-w- c:\windows\system32\MPInstFix.dll

2010-09-04 08:47 . 2005-11-09 13:29 163840 ----a-w- c:\windows\system32\mausbasi.dll

2010-09-04 08:46 . 2010-09-04 08:46 -------- d-----w- c:\program files\M-Audio MobilePre

2010-09-04 08:27 . 2009-09-02 12:29 158344 ----a-w- c:\windows\system32\drivers\MAudioMobilePre.sys

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-10-03 16:39 . 2010-04-21 21:26 -------- d-----w- c:\documents and settings\Thomas\Application Data\BitTorrent

2010-10-03 16:00 . 2010-04-02 20:45 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat

2010-10-02 23:52 . 2010-06-02 23:15 -------- d-----w- c:\documents and settings\Thomas\Application Data\vlc

2010-10-02 23:13 . 2010-05-24 16:17 -------- d-----w- c:\documents and settings\Thomas\Application Data\dvdcss

2010-10-02 12:13 . 2010-05-25 20:52 -------- d-----w- c:\program files\Common Files\CyberLink

2010-10-02 12:13 . 2010-05-25 20:51 -------- d-----w- c:\program files\CyberLink

2010-10-02 12:12 . 2010-05-25 21:25 53319 ----a-w- c:\documents and settings\All Users\Application Data\Temp\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\PostBuild.exe

2010-09-30 00:10 . 2010-04-02 21:33 -------- d-----w- c:\documents and settings\Thomas\Application Data\QuickScan

2010-09-29 09:48 . 2010-04-02 20:29 -------- d-----w- c:\program files\Microsoft Silverlight

2010-09-28 17:22 . 2010-04-02 20:45 -------- d-----w- c:\documents and settings\All Users\Application Data\COMODO

2010-09-28 17:21 . 2010-03-03 15:54 285480 ----a-w- c:\windows\system32\guard32.dll

2010-09-28 17:21 . 2010-03-03 15:54 91560 ----a-w- c:\windows\system32\drivers\inspect.sys

2010-09-28 17:21 . 2010-03-03 15:54 25240 ----a-w- c:\windows\system32\drivers\cmdhlp.sys

2010-09-28 17:21 . 2010-03-23 16:40 239240 ----a-w- c:\windows\system32\drivers\cmdGuard.sys

2010-09-28 17:21 . 2010-03-03 15:54 15592 ----a-w- c:\windows\system32\drivers\cmderd.sys

2010-09-22 20:38 . 2010-04-02 19:14 -------- d--h--w- c:\program files\InstallShield Installation Information

2010-09-14 09:06 . 2010-04-02 21:39 -------- d-----w- c:\program files\QT Lite

2010-09-14 09:05 . 2010-08-13 09:51 -------- d-----w- c:\program files\Common Files\Apple

2010-09-06 22:42 . 2010-04-02 21:44 -------- d-----w- c:\program files\Elaborate Bytes

2010-09-04 23:06 . 2010-09-04 23:06 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield

2010-09-04 23:02 . 2010-04-02 19:11 -------- d-----w- c:\program files\Common Files\InstallShield

2010-09-01 09:03 . 2010-04-21 21:26 -------- d-----w- c:\program files\BitTorrent

2010-08-29 22:05 . 2010-08-29 21:33 1515134079 ----a-w- c:\documents and settings\Thomas\Application Data\BitTorrent\Ableton Suite 8.1.1 Full Cracked\Setup.exe

2010-08-29 21:46 . 2010-08-30 18:30 29255168 ----a-w- c:\documents and settings\Thomas\Application Data\BitTorrent\Ableton Suite 8.1.1 Full Cracked\Crack\Crack\Crack\Live 8.1.1.exe

2010-08-29 21:46 . 2010-08-30 18:26 29255168 ----a-w- c:\documents and settings\Thomas\Application Data\BitTorrent\Ableton Suite 8.1.1 Full Cracked\Crack\Crack\Live 8.1.1.exe

2010-08-29 21:46 . 2010-08-29 21:33 29255168 ----a-w- c:\documents and settings\Thomas\Application Data\BitTorrent\Ableton Suite 8.1.1 Full Cracked\Crack\Live 8.1.1.exe

2010-08-29 20:47 . 2010-08-29 20:47 -------- d-----w- c:\program files\Ableton

2010-08-29 20:25 . 2010-04-30 09:30 -------- d-----w- c:\documents and settings\Thomas\Application Data\Ableton

2010-08-29 11:31 . 2010-08-29 11:31 -------- d-----w- c:\documents and settings\Thomas\Application Data\PACE Anti-Piracy

2010-08-29 11:30 . 2010-08-29 11:30 10710528 ----a-w- c:\documents and settings\All Users\Application Data\Line 6\L6TWXY\L6TWXY.DLL

2010-08-29 11:30 . 2010-08-29 11:30 1534464 ----a-w- c:\documents and settings\All Users\Application Data\Line 6\L6TWXY\data\twx\L6TWX.DLL

2010-08-29 11:30 . 2010-08-29 11:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Line 6

2010-08-29 11:30 . 2010-08-29 11:30 606208 ----a-w- c:\windows\system32\REX Shared Library.dll

2010-08-29 11:30 . 2010-08-29 11:30 2771968 ----a-w- c:\windows\system32\ReWire.dll

2010-08-29 11:30 . 2010-04-07 17:44 -------- d-----w- c:\documents and settings\Thomas\Application Data\Propellerhead Software

2010-08-29 11:29 . 2010-08-29 11:29 8192 ----a-r- c:\documents and settings\Thomas\Application Data\Microsoft\Installer\{26B46206-DF80-4DA2-AEAB-FF146320C344}\IconTmpl1.108DF49C_3AB4_4A7D_B6FD_8B6286B317FA.exe

2010-08-29 11:29 . 2010-08-29 11:29 30208 ----a-r- c:\documents and settings\Thomas\Application Data\Microsoft\Installer\{26B46206-DF80-4DA2-AEAB-FF146320C344}\IconTmpl.108DF49C_3AB4_4A7D_B6FD_8B6286B317FA.exe

2010-08-29 11:29 . 2010-08-29 11:29 14848 ----a-r- c:\documents and settings\Thomas\Application Data\Microsoft\Installer\{26B46206-DF80-4DA2-AEAB-FF146320C344}\IconTmpl4.A961A077_4BD0_4C98_86BC_EE4A98CE550D.exe

2010-08-29 11:28 . 2010-08-29 11:28 -------- d-----w- c:\program files\CodeMeter

2010-08-29 11:28 . 2010-04-29 21:56 -------- d-----w- c:\program files\Propellerhead

2010-08-25 20:27 . 2010-08-13 09:53 -------- d-----w- c:\documents and settings\Thomas\Application Data\Apple Computer

2010-08-22 12:04 . 2010-08-22 12:04 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}

2010-08-21 12:37 . 2010-08-20 20:30 -------- d-----w- c:\documents and settings\All Users\Application Data\regid.1986-12.com.adobe

2010-08-20 19:57 . 2010-04-02 16:36 25128 ----a-w- c:\documents and settings\Thomas\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-08-20 19:49 . 2010-04-24 20:37 -------- d-----w- c:\program files\Common Files\Adobe

2010-08-20 19:48 . 2010-08-20 19:48 -------- d-----w- c:\program files\Adobe Media Player

2010-08-20 19:47 . 2010-08-20 19:47 -------- d-----w- c:\program files\Common Files\Adobe AIR

2010-08-17 13:17 . 2004-08-10 11:00 58880 ----a-w- c:\windows\system32\spoolsv.exe

2010-08-14 09:35 . 2010-08-14 09:35 -------- d-----w- c:\program files\Common Files\Java

2010-08-14 09:35 . 2010-05-09 14:40 -------- d-----w- c:\program files\Java

2010-08-13 09:53 . 2010-08-13 09:52 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}

2010-08-13 09:52 . 2010-04-02 21:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer

2010-08-13 09:51 . 2010-08-13 09:51 -------- d-----w- c:\program files\Apple Software Update

2010-08-13 09:51 . 2010-08-13 09:51 -------- d-----w- c:\program files\Bonjour

2010-08-13 09:51 . 2010-08-13 09:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple

2010-08-12 12:16 . 2010-08-22 12:04 2979848 -c--a-w- c:\documents and settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}\Ad-AwareInstall.exe

2010-08-12 12:15 . 2010-05-28 10:26 15880 ----a-w- c:\windows\system32\lsdelete.exe

2010-08-12 12:15 . 2010-04-28 17:26 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys

2010-08-04 17:07 . 2010-08-04 17:07 61440 ----a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-63a08553-n\decora-sse.dll

2010-08-04 17:07 . 2010-08-04 17:07 503808 ----a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-508be564-n\msvcp71.dll

2010-08-04 17:07 . 2010-08-04 17:07 499712 ----a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-508be564-n\jmc.dll

2010-08-04 17:07 . 2010-08-04 17:07 348160 ----a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-508be564-n\msvcr71.dll

2010-08-04 17:07 . 2010-08-04 17:07 12800 ----a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-63a08553-n\decora-d3d.dll

2010-07-22 15:49 . 2004-08-10 11:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll

2010-07-22 05:57 . 2010-04-02 20:01 5120 ----a-w- c:\windows\system32\xpsp4res.dll

2010-07-17 03:00 . 2010-05-09 14:40 423656 ----a-w- c:\windows\system32\deployJava1.dll

2007-12-28 22:04 . 2010-09-15 22:23 1270409216 ----a-w- c:\program files\rld-shal.iso

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2010-05-10 102400]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]

"WorksFUD"="c:\program files\Microsoft Works\wkfud.exe" [2000-07-12 24576]

"Microsoft Works Portfolio"="c:\program files\Microsoft Works\WksSb.exe" [2000-07-12 311350]

"Microsoft Works Update Detection"="c:\program files\Microsoft Works\WkDetect.exe" [2000-08-30 28739]

"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]

"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]

"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-09-28 2500552]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]

"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]

"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-22 402432]

"M-Audio Taskbar Icon"="c:\windows\System32\M-AudioTaskBarIcon.exe" [2009-09-02 643592]

"QuickTime Task"="c:\program files\QT Lite\QTTask.exe" [2010-08-10 421888]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-01 421160]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

 

c:\documents and settings\Thomas\Start Menu\Programs\Startup\

MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2010-10-3 576000]

 

c:\documents and settings\All Users\Start Menu\Programs\Startup\

BankID Security Application.lnk - c:\program files\Personal\bin\Personal.exe [2010-4-26 939920]

P†minnelser f”r Kalendern i Microsoft Works.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2000-7-12 24633]

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\BitTorrent\\bittorrent.exe"=

"c:\\Program Files\\Samsung\\Samsung New PC Studio\\npsasvr.exe"=

"c:\\Program Files\\Samsung\\Samsung New PC Studio\\npsvsvr.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

"c:\\Program Files\\Real Alternative\\Media Player Classic\\mplayerc.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\CodeMeter\\Runtime\\bin\\CodeMeter.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

 

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-04-28 64288]

R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [2010-03-03 15592]

R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2010-03-03 25240]

S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2010-03-23 239240]

S2 CodeMeter.exe;CodeMeter Runtime Server;c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe [2009-04-03 1680704]

S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-04-24 233472]

S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-08-12 1356952]

S3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [2009-12-18 11336]

S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-04-24 36608]

S3 MAUSBMOBILEPRE;Service for M-Audio MobilePre;c:\windows\system32\drivers\MAudioMobilePre.sys [2010-09-04 158344]

S3 MAUSBMP;Service for M-Audio Mobile Pre (WDM);c:\windows\system32\DRIVERS\mausbmp.sys --> c:\windows\system32\DRIVERS\mausbmp.sys [?]

S3 Normandy;Normandy SR2; [x]

S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [2010-04-24 90112]

S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [2010-04-24 14976]

S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [2010-04-24 121856]

S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2010-09-04 445936]

.

Contents of the 'Scheduled Tasks' folder

 

2010-10-03 c:\windows\Tasks\Ad-Aware Update (Weekly).job

- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-08-12 19:08]

 

2010-10-01 c:\windows\Tasks\AdobeAAMUpdater-1.0-EZRA-Thomas.job

- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2010-08-20 01:44]

 

2010-09-14 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 09:50]

.

.

------- Supplementary Scan -------

.

uInternet Settings,ProxyOverride = *.local

FF - ProfilePath - c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\

FF - component: c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll

FF - component: c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\extensions\support@lastpass.com\platform\WINNT_x86-msvc\components\lpxpcom.dll

FF - plugin: c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\mrwkk0wk.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll

FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

FF - plugin: c:\program files\Personal\bin\np_prsnl.dll

FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin.dll

FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin2.dll

FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin3.dll

FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin4.dll

FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin5.dll

FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin6.dll

FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin7.dll

FF - plugin: c:\program files\Veetle\Player\npvlc.dll

FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll

FF - plugin: c:\program files\Veetle\VLCBroadcast\npvbp.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

 

---- FIREFOX POLICIES ----

c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-10-03 20:04

Windows 5.1.2600 Service Pack 3 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

 

- - - - - - - > 'winlogon.exe'(676)

c:\windows\system32\Ati2evxx.dll

 

- - - - - - - > 'explorer.exe'(1120)

c:\windows\system32\WININET.dll

c:\program files\Common Files\Ahead\Lib\NeroSearchBar.dll

c:\program files\Common Files\Ahead\Lib\MFC71U.DLL

c:\program files\Common Files\Ahead\Lib\BCGCBPRO860un71.dll

c:\windows\system32\ieframe.dll

.

Completion time: 2010-10-03 20:06:04

ComboFix-quarantined-files.txt 2010-10-03 18:06

ComboFix2.txt 2010-10-02 19:13

ComboFix3.txt 2010-10-02 17:39

 

Pre-Run: 147 164 323 840 bytes free

Post-Run: 147 149 778 944 bytes free

 

- - End Of File - - 49D93B8C90CE5A243529466D549C5048

Länk till kommentar
Dela på andra webbplatser

Varför kommer varningen om att windows inte kan hitta eller att jag inte har behörighet att öppna programmen ni har rekommenderat mig att ladda ned? Nu funkar det bara i felsäkert läge.

Länk till kommentar
Dela på andra webbplatser

Arkiverat

Det här ämnet är nu arkiverat och är stängt för ytterligare svar.

×
×
  • Skapa nytt...