Just nu i M3-nätverket
Gå till innehåll

Kan inte komma in på Windows Update mm. Virus?


leineri

Rekommendera Poster

Du behöver inte känna dig korkad, det är så lätt att man har olika benämningar på sånt som finns i Windows.

 

GMER visar en hel del så mbr.exe behöver du inte köra för närvarande.

 

Kopiera alla rader i rutan:

Killall::
Rootkit::
C:\WINDOWS\system32\tehwfq.dll
C:\WINDOWS\system32\qfcgjevx
C:\WINDOWS\system32\drivers\qfcgjevx
Driver::
obgutsro 
Netsvc::
obgutsro 
Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9777:TCP"=-
FCopy::
c:\windows\ServicePackFiles\i386\atapi.sys|c:\windows\system32\drivers\atapi.sys

och klistra in i Anteckningar. Kontrollera att det ser exakt likadant ut, t ex när det gäller radbrytningar.

Spara filen på Skrivbordet med namnet CFScript.

 

Förbered datorn på samma sätt som tidigare för ComboFix.

Dra CFScript med musen och släpp den ovanpå ComboFix-ikonen på Skrivbordet så startar programmet på ett särskilt sätt.

Klistra in loggen som kommer ut.

 

Starta om datorn och kör Gmer och klistra in dess logg.

Länk till kommentar
Dela på andra webbplatser

  • Svars 85
  • Skapad
  • Senaste svar

Det kom upp en ruta som sa att ComboFix var för gammalt och köärdes i någon form av reducerat läge. Här är loggen:

 

ComboFix 10-12-14.07 - Mikael Pettersson 2010-12-21 20:08:46.7.1 - x86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.46.1053.18.1535.1196 [GMT 1:00]

Körs från: c:\documents and settings\Mikael Pettersson\Skrivbord\ComboFix.exe

Använda kommandoväxlar :: c:\documents and settings\Mikael Pettersson\Skrivbord\CFScript.txt

.

- REDUCERAD FUNKTIONALITETSMOD -

.

 

((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))

.

 

.

--------------- FCopy ---------------

 

c:\windows\ServicePackFiles\i386\atapi.sys --> c:\windows\system32\drivers\atapi.sys

.

(((((((((((((((((((((((( Filer Skapade från 2010-11-21 till 2010-12-21 ))))))))))))))))))))))))))))))

.

 

Inga nya filer har skapats under denna tid.

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-11-12 17:53 . 2010-08-22 12:34 472808 ----a-w- c:\windows\system32\deployJava1.dll

2010-11-12 15:34 . 2007-05-12 15:02 73728 ----a-w- c:\windows\system32\javacpl.cpl

.

 

------- Sigcheck -------

 

[7] 2004-08-04 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\ERDNT\cache\atapi.sys

[7] 2004-08-04 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\ServicePackFiles\i386\atapi.sys

[7] 2004-08-04 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\atapi.sys

[-] 2004-08-04 05:59 . !HASH: COULD NOT OPEN FILE !!!!! . 95360 . . [------] . . c:\windows\system32\drivers\atapi.sys

[7] 2002-08-29 . 95B858761A00E1D4F81F79A0DA019ACA . 86912 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\atapi.sys

[-] 2002-01-30 . 48BC2767CEEC6E8B0E15B0289F18232E . 86912 . . [5.1.2600.28] . . c:\windows\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys

.

(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Not* Tomma poster & legitima standardposter visas inte.

REGEDIT4

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"diagent"="c:\program\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 135264]

"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]

"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-12-07 196608]

"QuickTime Task"="c:\program\QuickTime\qttask.exe" [2005-09-17 98304]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"SRUUninstall"="c:\windows\system32\msiexec.exe" [2005-03-21 78848]

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start-meny^Program^Autostart^Adobe Gamma Loader.lnk]

path=c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Autostart\Adobe Gamma Loader.lnk

backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start-meny^Program^Autostart^Adobe Reader Speed Launch.lnk]

path=c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Autostart\Adobe Reader Speed Launch.lnk

backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start-meny^Program^Autostart^Microsoft Office.lnk]

path=c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Autostart\Microsoft Office.lnk

backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start-meny^Program^Autostart^SmartTrust CSP Certificate Utility.lnk]

path=c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Autostart\SmartTrust CSP Certificate Utility.lnk

backup=c:\windows\pss\SmartTrust CSP Certificate Utility.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start-meny^Program^Autostart^WordQCRS.lnk]

path=c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Autostart\WordQCRS.lnk

backup=c:\windows\pss\WordQCRS.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^Mikael Pettersson^Start-meny^Program^Autostart^No-IP DUC.lnk]

path=c:\documents and settings\Mikael Pettersson\Start-meny\Program\Autostart\No-IP DUC.lnk

backup=c:\windows\pss\No-IP DUC.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellTouch]

2002-01-16 22:49 163840 ----a-w- c:\windows\MMKeybd.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

2005-09-17 21:28 98304 ----a-w- c:\program\QuickTime\qttask.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegKillElbyCheck]

2002-11-02 06:33 45056 ----a-w- c:\program\Elaborate Bytes\DVD Region Killer\ElbyCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegKillTray]

2002-11-27 21:11 49152 ----a-w- c:\program\Elaborate Bytes\DVD Region Killer\RegKillTray.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tweak UI]

2003-03-25 04:49 106544 ----a-r- c:\windows\system32\tweakui.cpl

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]

2006-03-30 14:45 313472 ----a-w- c:\program\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USIUDF_Eject_Monitor]

2004-05-28 03:50 81920 ------w- c:\program\Delade filer\Ulead Systems\DVD\USISrv.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WordQ carat flag]

2004-02-06 05:00 24576 ----a-w- c:\program\WordQ\WordQcrs.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program\\Messenger\\msmsgs.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"26263:TCP"= 26263:TCP:BitComet 26263 TCP

"26263:UDP"= 26263:UDP:BitComet 26263 UDP

 

R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [2005-10-25 160640]

R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [2005-10-25 5248]

R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [2004-10-25 155136]

R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [2004-10-25 5248]

R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [2003-05-07 11264]

R1 ATMhelpr;ATMhelpr;c:\windows\system32\drivers\ATMHELPR.SYS [2003-03-22 4064]

R2 Nhksrv;Netropa NHK Server;c:\windows\Nhksrv.exe [2002-11-12 28672]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program\Delade filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-03-11 109616]

R3 Msikbd2k;DellTouch;c:\windows\system32\drivers\Msikbd2k.sys [2002-11-12 6656]

R3 RegKill;RegKill;c:\windows\system32\drivers\RegKill.sys [2002-11-27 6400]

S0 ElbyVCD;ElbyVCD;c:\windows\system32\DRIVERS\ElbyVCD.sys --> c:\windows\system32\DRIVERS\ElbyVCD.sys [?]

S2 Ca533av;Icatch(IV) Video Camera Device;c:\windows\system32\drivers\Ca533av.sys [2010-06-21 515803]

S2 obgutsro;Universal Update;c:\windows\system32\svchost.exe -k netsvcs [2002-07-01 14336]

S3 Amps2prt;A4Tech PS/2 Port Mouse Driver;c:\windows\system32\drivers\Amps2prt.sys [2004-01-12 9728]

S3 Axtmvflt;Axesstel USB Filter Service;c:\windows\system32\drivers\Axtmvflt.sys [2010-06-03 3456]

S3 Axtmvmdm;Axesstel USB Modem;c:\windows\system32\drivers\Axtmvmdm.sys [2010-06-03 40064]

S3 Axtmvprt;Axesstel Diagnostic Port;c:\windows\system32\drivers\Axtmvprt.sys [2010-06-03 38784]

S3 QCEmerald;Logitech QuickCam Web;c:\windows\system32\drivers\OVCE.sys [2003-01-17 31872]

S3 TodosScReader;Driver for Todos Argosmini Usb;c:\windows\system32\drivers\amusb.sys [2003-04-23 82464]

.

.

------- Extra genomsökning -------

.

uStart Page = hxxp://ccp.crystone.net/

IE: Download all links using BitComet - c:\program\BitComet\BitComet.exe/AddAllLink.htm

IE: Download all videos using BitComet - c:\program\BitComet\BitComet.exe/AddVideo.htm

IE: Download link using &BitComet - c:\program\BitComet\BitComet.exe/AddLink.htm

IE: E&xportera till Microsoft Excel - c:\program\MICROS~2\Office10\EXCEL.EXE/3000

IE: {{641F4F4E-6C91-4159-869E-9F5CE6F0F64E} - c:\program\MultiPoker\MultiPoker.exe

IE: {{B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - c:\program\PartyGaming\PartyCasino\RunCasino.exe

IE: {{EFFF8D47-D060-4108-B761-E8EC86622E56} - c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Absolute Poker\Absolute Poker.lnk

DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-12-21 20:12

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\obgutsro]

"ServiceDll"="c:\windows\system32\tehwfq.dll"

.

--------------------- DLLer som "laddats" under processer som körs ---------------------

 

- - - - - - - > 'explorer.exe'(1304)

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

.

------------------------ Andra processer som körs ------------------------

.

c:\windows\System32\SCardSvr.exe

c:\windows\System32\Ati2evxx.exe

c:\windows\System32\CTsvcCDA.exe

c:\program\Java\jre6\bin\jqs.exe

c:\program\Delade filer\Ulead Systems\DVD\ULCDRSvr.exe

c:\windows\system32\wdfmgr.exe

c:\windows\System32\MsPMSPSv.exe

.

**************************************************************************

.

Sluttid: 2010-12-21 20:19:05 - datorn startades om.

ComboFix-quarantined-files.txt 2010-12-21 19:18

ComboFix2.txt 2010-12-18 19:45

ComboFix3.txt 2010-12-18 15:00

ComboFix4.txt 2010-12-17 17:48

ComboFix5.txt 2010-12-21 19:08

 

Före genomsökningen: 94 710 833 152 byte ledigt

Efter genomsökningen: 94 718 074 880 byte ledigt

 

- - End Of File - - BAF483C87E8ADA000904C7FA17658F49

 

 

 

Länk till kommentar
Dela på andra webbplatser

Ta bort den ComboFix du har och hämta senaste versionen med hjälp av samma länk som tidigare. Kör om enligt inlägg 51.

Länk till kommentar
Dela på andra webbplatser

Har du möjlighet att ladda ner filen på en annan dator och föra över den med hjälp av USB-minne, extern hårddisk, CD etc?

Länk till kommentar
Dela på andra webbplatser

Ja, det skulle vara om jag kan göra det ifrån biblioteket i så fall.. Hoppas de har cd brännare på deras datorer bara.

 

Men nu verkar det (peppar peppar) som om det kan vara 10e gången gillt! Ännu tickar nedladdningen på som den ska.. återkommer med resultatet.

Länk till kommentar
Dela på andra webbplatser

Jjippi, det gick!

Här är CombiFix loggen:

 

ComboFix 10-12-23.01 - Mikael Pettersson 2010-12-23 19:29:42.8.1 - x86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.46.1053.18.1535.1181 [GMT 1:00]

Körs från: c:\documents and settings\Mikael Pettersson\Skrivbord\ComboFix.exe

Använda kommandoväxlar :: c:\documents and settings\Mikael Pettersson\Skrivbord\CFScript.txt

* Skapade en ny återställningspunkt

.

 

((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))

.

 

.

--------------- FCopy ---------------

 

c:\windows\ServicePackFiles\i386\atapi.sys --> c:\windows\system32\drivers\atapi.sys

.

((((((((((((((((((((((((((((((((((((((( Drivrutiner/Tjänster )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Legacy_OBGUTSRO

-------\Service_obgutsro

 

 

(((((((((((((((((((((((( Filer Skapade från 2010-11-23 till 2010-12-23 ))))))))))))))))))))))))))))))

.

 

2010-12-22 18:44 . 2010-12-22 18:44 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\ArcSoft

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-11-12 17:53 . 2010-08-22 12:34 472808 ----a-w- c:\windows\system32\deployJava1.dll

2010-11-12 15:34 . 2007-05-12 15:02 73728 ----a-w- c:\windows\system32\javacpl.cpl

.

 

------- Sigcheck -------

 

[7] 2004-08-04 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\ERDNT\cache\atapi.sys

[7] 2004-08-04 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\ServicePackFiles\i386\atapi.sys

[7] 2004-08-04 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\atapi.sys

[-] 2004-08-04 05:59 . !HASH: COULD NOT OPEN FILE !!!!! . 95360 . . [------] . . c:\windows\system32\drivers\atapi.sys

[7] 2002-08-29 . 95B858761A00E1D4F81F79A0DA019ACA . 86912 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\atapi.sys

[-] 2002-01-30 . 48BC2767CEEC6E8B0E15B0289F18232E . 86912 . . [5.1.2600.28] . . c:\windows\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys

.

(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Not* Tomma poster & legitima standardposter visas inte.

REGEDIT4

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"diagent"="c:\program\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 135264]

"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]

"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-12-07 196608]

"QuickTime Task"="c:\program\QuickTime\qttask.exe" [2005-09-17 98304]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"SRUUninstall"="c:\windows\system32\msiexec.exe" [2005-03-21 78848]

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start-meny^Program^Autostart^Adobe Gamma Loader.lnk]

path=c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Autostart\Adobe Gamma Loader.lnk

backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start-meny^Program^Autostart^Adobe Reader Speed Launch.lnk]

path=c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Autostart\Adobe Reader Speed Launch.lnk

backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start-meny^Program^Autostart^Microsoft Office.lnk]

path=c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Autostart\Microsoft Office.lnk

backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start-meny^Program^Autostart^SmartTrust CSP Certificate Utility.lnk]

path=c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Autostart\SmartTrust CSP Certificate Utility.lnk

backup=c:\windows\pss\SmartTrust CSP Certificate Utility.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start-meny^Program^Autostart^WordQCRS.lnk]

path=c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Autostart\WordQCRS.lnk

backup=c:\windows\pss\WordQCRS.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^Mikael Pettersson^Start-meny^Program^Autostart^No-IP DUC.lnk]

path=c:\documents and settings\Mikael Pettersson\Start-meny\Program\Autostart\No-IP DUC.lnk

backup=c:\windows\pss\No-IP DUC.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellTouch]

2002-01-16 22:49 163840 ----a-w- c:\windows\MMKeybd.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

2005-09-17 21:28 98304 ----a-w- c:\program\QuickTime\qttask.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegKillElbyCheck]

2002-11-02 06:33 45056 ----a-w- c:\program\Elaborate Bytes\DVD Region Killer\ElbyCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegKillTray]

2002-11-27 21:11 49152 ----a-w- c:\program\Elaborate Bytes\DVD Region Killer\RegKillTray.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tweak UI]

2003-03-25 04:49 106544 ----a-r- c:\windows\system32\tweakui.cpl

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]

2006-03-30 14:45 313472 ----a-w- c:\program\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USIUDF_Eject_Monitor]

2004-05-28 03:50 81920 ------w- c:\program\Delade filer\Ulead Systems\DVD\USISrv.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WordQ carat flag]

2004-02-06 05:00 24576 ----a-w- c:\program\WordQ\WordQcrs.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program\\Messenger\\msmsgs.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"26263:TCP"= 26263:TCP:BitComet 26263 TCP

"26263:UDP"= 26263:UDP:BitComet 26263 UDP

 

R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [2005-10-25 160640]

R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [2005-10-25 5248]

R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [2004-10-25 155136]

R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [2004-10-25 5248]

R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [2003-05-07 11264]

R1 ATMhelpr;ATMhelpr;c:\windows\system32\drivers\ATMHELPR.SYS [2003-03-22 4064]

R2 Nhksrv;Netropa NHK Server;c:\windows\Nhksrv.exe [2002-11-12 28672]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program\Delade filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-03-11 109616]

R3 Msikbd2k;DellTouch;c:\windows\system32\drivers\Msikbd2k.sys [2002-11-12 6656]

R3 RegKill;RegKill;c:\windows\system32\drivers\RegKill.sys [2002-11-27 6400]

S0 ElbyVCD;ElbyVCD;c:\windows\system32\DRIVERS\ElbyVCD.sys --> c:\windows\system32\DRIVERS\ElbyVCD.sys [?]

S2 Ca533av;Icatch(IV) Video Camera Device;c:\windows\system32\drivers\Ca533av.sys [2010-06-21 515803]

S3 Amps2prt;A4Tech PS/2 Port Mouse Driver;c:\windows\system32\drivers\Amps2prt.sys [2004-01-12 9728]

S3 Axtmvflt;Axesstel USB Filter Service;c:\windows\system32\drivers\Axtmvflt.sys [2010-06-03 3456]

S3 Axtmvmdm;Axesstel USB Modem;c:\windows\system32\drivers\Axtmvmdm.sys [2010-06-03 40064]

S3 Axtmvprt;Axesstel Diagnostic Port;c:\windows\system32\drivers\Axtmvprt.sys [2010-06-03 38784]

S3 QCEmerald;Logitech QuickCam Web;c:\windows\system32\drivers\OVCE.sys [2003-01-17 31872]

S3 TodosScReader;Driver for Todos Argosmini Usb;c:\windows\system32\drivers\amusb.sys [2003-04-23 82464]

.

.

------- Extra genomsökning -------

.

uStart Page = hxxp://ccp.crystone.net/

IE: Download all links using BitComet - c:\program\BitComet\BitComet.exe/AddAllLink.htm

IE: Download all videos using BitComet - c:\program\BitComet\BitComet.exe/AddVideo.htm

IE: Download link using &BitComet - c:\program\BitComet\BitComet.exe/AddLink.htm

IE: E&xportera till Microsoft Excel - c:\program\MICROS~2\Office10\EXCEL.EXE/3000

IE: {{641F4F4E-6C91-4159-869E-9F5CE6F0F64E} - c:\program\MultiPoker\MultiPoker.exe

IE: {{B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - c:\program\PartyGaming\PartyCasino\RunCasino.exe

IE: {{EFFF8D47-D060-4108-B761-E8EC86622E56} - c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Absolute Poker\Absolute Poker.lnk

DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-12-23 19:37

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

--------------------- DLLer som "laddats" under processer som körs ---------------------

 

- - - - - - - > 'explorer.exe'(352)

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

.

------------------------ Andra processer som körs ------------------------

.

c:\windows\System32\SCardSvr.exe

c:\windows\System32\Ati2evxx.exe

c:\windows\System32\CTsvcCDA.exe

c:\program\Java\jre6\bin\jqs.exe

c:\program\Delade filer\Ulead Systems\DVD\ULCDRSvr.exe

c:\windows\system32\wdfmgr.exe

c:\windows\System32\MsPMSPSv.exe

c:\windows\system32\wscntfy.exe

.

**************************************************************************

.

Sluttid: 2010-12-23 19:44:48 - datorn startades om.

ComboFix-quarantined-files.txt 2010-12-23 18:44

ComboFix2.txt 2010-12-21 19:19

ComboFix3.txt 2010-12-18 19:45

ComboFix4.txt 2010-12-18 15:00

ComboFix5.txt 2010-12-23 18:26

 

Före genomsökningen: 94 264 258 560 byte ledigt

Efter genomsökningen: 94 284 058 624 byte ledigt

 

- - End Of File - - 2B7331BEECDE1CFF38E632633036EF71

 

 

 

Länk till kommentar
Dela på andra webbplatser

..och här är GMER loggen:

 

GMER 1.0.15.15530 - http://www.gmer.net

Rootkit scan 2010-12-23 21:16:01

Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 IC35L120AVVA07-0 rev.VA6OA51A

Running: qe99thuy.exe; Driver: C:\DOCUME~1\MIKAEL~1\LOKALA~1\Temp\pxtdapod.sys

 

 

---- System - GMER 1.0.15 ----

 

SSDT d347bus.sys (PnP BIOS Extension/ ) ZwClose [0xF7576818]

SSDT 8A1113A0 ZwConnectPort

SSDT d347bus.sys (PnP BIOS Extension/ ) ZwCreateKey [0xF75767D0]

SSDT d347bus.sys (PnP BIOS Extension/ ) ZwCreatePagingFile [0xF756AA20]

SSDT d347bus.sys (PnP BIOS Extension/ ) ZwEnumerateKey [0xF756B2A8]

SSDT d347bus.sys (PnP BIOS Extension/ ) ZwEnumerateValueKey [0xF7576910]

SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwOpenFile [0xF7590B40]

SSDT d347bus.sys (PnP BIOS Extension/ ) ZwOpenKey [0xF7576794]

SSDT d347bus.sys (PnP BIOS Extension/ ) ZwQueryKey [0xF756B2C8]

SSDT d347bus.sys (PnP BIOS Extension/ ) ZwQueryValueKey [0xF7576866]

SSDT d347bus.sys (PnP BIOS Extension/ ) ZwSetSystemPowerState [0xF75760B0]

 

---- Kernel code sections - GMER 1.0.15 ----

 

.text ntoskrnl.exe!_abnormal_termination + 168 804E27C4 2 Bytes [A8, B2] {TEST AL, 0xb2}

.text ntoskrnl.exe!_abnormal_termination + 16B 804E27C7 1 Byte [F7]

.text ntoskrnl.exe!_abnormal_termination + 170 804E27CC 2 Bytes [10, 69]

.text ntoskrnl.exe!_abnormal_termination + 173 804E27CF 1 Byte [F7]

.text ntoskrnl.exe!_abnormal_termination + 2CC 804E2928 2 Bytes [C8, B2]

.text ...

? C:\DOCUME~1\MIKAEL~1\LOKALA~1\Temp\mbr.sys Det går inte att hitta filen. !

 

---- Devices - GMER 1.0.15 ----

 

Device Ntfs.sys (NT File System Driver/Microsoft Corporation)

Device 8A409C10

Device Udfs.SYS (UDF File System Driver/Microsoft Corporation)

Device 898BCC00

 

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 ATMhelpr.SYS (Windows NT Font Driver Helper/Adobe Systems Incorporated)

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 ATMhelpr.SYS (Windows NT Font Driver Helper/Adobe Systems Incorporated)

AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

 

Device \Driver\Cdrom \Device\CdRom0 89F172B8

Device \FileSystem\Rdbss \Device\FsWrap 89F86DF0

Device \Driver\atapi \Device\Ide\IdePort0 89DF6438

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 89DF6438

Device \Driver\atapi \Device\Ide\IdePort1 89DF6438

Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c 89DF6438

Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 89DF6438

Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 89DF6438

Device \Driver\Cdrom \Device\CdRom1 89F172B8

Device \Driver\Cdrom \Device\CdRom2 89F172B8

Device \Driver\Cdrom \Device\CdRom3 89F172B8

Device \Driver\Cdrom \Device\CdRom4 89F172B8

Device \FileSystem\Srv \Device\LanmanServer 89E70940

 

AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

 

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89F7F520

Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)

Device 89F7F520

Device \FileSystem\Npfs \Device\NamedPipe 8995D6E8

Device \FileSystem\Msfs \Device\Mailslot 898E3968

Device \Driver\d347prt \Device\Scsi\d347prt1Port2Path0Target0Lun0 89FB23D0

Device \Driver\a347scsi \Device\Scsi\a347scsi1 89FB4F00

Device \Driver\imagedrv \Device\Scsi\imagedrv1 89DF76A8

Device \Driver\d347prt \Device\Scsi\d347prt1Port2Path0Target1Lun0 89FB23D0

Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 89FB4F00

Device \Driver\d347prt \Device\Scsi\d347prt1 89FB23D0

Device \Driver\imagedrv \Device\Scsi\imagedrv1Port4Path0Target0Lun0 89DF76A8

Device A864DC8A

Device 89A0D638

 

AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

 

Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer 898CBE88

Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer 898CBE88

Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer 898CBE88

Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer 898CBE88

Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer 898CBE88

Device \FileSystem\Cdfs \Cdfs 89E786F8

 

---- Modules - GMER 1.0.15 ----

 

Module _________ F7453000-F746B000 (98304 bytes)

 

---- Registry - GMER 1.0.15 ----

 

Reg HKLM\SYSTEM\CurrentControlSet\Services\a347scsi\Config\jdgg40

Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}@DisplayName Alcohol 120%

Reg HKLM\SOFTWARE\Classes\Installer\Products\32418F9EE1126B64A90E8365B85CFCF6@ProductName Alcohol 120%

 

---- EOF - GMER 1.0.15 ----

 

 

 

Länk till kommentar
Dela på andra webbplatser

Kontroll av att de skadliga filerna inte kommer tillbaka:

Starta om datorn och kör ComboFix utan CFScript men för övrigt på samma sätt som tidigare.

 

Starta om datorn och kör Gmer.

 

Klistra in loggarna från båda programmen.

 

God Jul!

Länk till kommentar
Dela på andra webbplatser

Ja fick problem då jag skulle köra GMER. Den låser sig helatiden och jag måste dra ur kontakten för att kunna starta om datori. Vet ej varför. Sosta gången så var det en röd rad där det stod typ:

Service ..system32\svchost.exe (***hidden***)

Vet ej om det är viktigt, men jag kan inte minnas att någon rad varit skriven med röd text förut. Ska fortsätta att försöka. Kanske ger sig tillslut detta med.

Här är ComboFix loggen:

 

ComboFix 10-12-23.01 - Mikael Pettersson 2010-12-24 13:10:16.9.1 - x86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.46.1053.18.1535.1186 [GMT 1:00]

Körs från: c:\documents and settings\Mikael Pettersson\Skrivbord\ComboFix.exe

.

 

(((((((((((((((((((((((( Filer Skapade från 2010-11-24 till 2010-12-24 ))))))))))))))))))))))))))))))

.

 

2010-12-22 18:44 . 2010-12-22 18:44 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\ArcSoft

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-11-12 17:53 . 2010-08-22 12:34 472808 ----a-w- c:\windows\system32\deployJava1.dll

2010-11-12 15:34 . 2007-05-12 15:02 73728 ----a-w- c:\windows\system32\javacpl.cpl

.

 

------- Sigcheck -------

 

[7] 2004-08-04 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\ERDNT\cache\atapi.sys

[7] 2004-08-04 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\ServicePackFiles\i386\atapi.sys

[7] 2004-08-04 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\atapi.sys

[-] 2004-08-04 05:59 . !HASH: COULD NOT OPEN FILE !!!!! . 95360 . . [------] . . c:\windows\system32\drivers\atapi.sys

[7] 2002-08-29 . 95B858761A00E1D4F81F79A0DA019ACA . 86912 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\atapi.sys

[-] 2002-01-30 . 48BC2767CEEC6E8B0E15B0289F18232E . 86912 . . [5.1.2600.28] . . c:\windows\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys

.

((((((((((((((((((((((((((((( SnapShot@2010-12-15_17.59.05 )))))))))))))))))))))))))))))))))))))))))

.

+ 2010-12-24 12:03 . 2010-12-24 12:03 16384 c:\windows\temp\Perflib_Perfdata_714.dat

+ 2005-05-26 02:16 . 2009-08-06 17:24 44768 c:\windows\system32\wups2.dll

+ 2004-08-12 10:07 . 2009-08-06 17:24 35552 c:\windows\system32\wups.dll

+ 2004-08-12 10:07 . 2009-08-06 17:24 35552 c:\windows\system32\dllcache\wups.dll

+ 2010-12-18 19:20 . 2010-11-12 17:53 157472 c:\windows\system32\javaws.exe

+ 2010-12-18 19:27 . 2010-11-12 17:53 145184 c:\windows\system32\javaw.exe

- 2010-08-22 12:34 . 2010-08-22 12:34 145184 c:\windows\system32\javaw.exe

+ 2010-12-18 19:27 . 2010-11-12 17:53 145184 c:\windows\system32\java.exe

- 2010-08-22 12:34 . 2010-08-22 12:34 145184 c:\windows\system32\java.exe

+ 2010-12-18 19:20 . 2010-12-18 19:20 180224 c:\windows\Installer\fd58ba.msi

.

(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Not* Tomma poster & legitima standardposter visas inte.

REGEDIT4

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"diagent"="c:\program\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 135264]

"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]

"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-12-07 196608]

"QuickTime Task"="c:\program\QuickTime\qttask.exe" [2005-09-17 98304]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"SRUUninstall"="c:\windows\system32\msiexec.exe" [2005-03-21 78848]

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start-meny^Program^Autostart^Adobe Gamma Loader.lnk]

path=c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Autostart\Adobe Gamma Loader.lnk

backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start-meny^Program^Autostart^Adobe Reader Speed Launch.lnk]

path=c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Autostart\Adobe Reader Speed Launch.lnk

backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start-meny^Program^Autostart^Microsoft Office.lnk]

path=c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Autostart\Microsoft Office.lnk

backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start-meny^Program^Autostart^SmartTrust CSP Certificate Utility.lnk]

path=c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Autostart\SmartTrust CSP Certificate Utility.lnk

backup=c:\windows\pss\SmartTrust CSP Certificate Utility.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start-meny^Program^Autostart^WordQCRS.lnk]

path=c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Autostart\WordQCRS.lnk

backup=c:\windows\pss\WordQCRS.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^Mikael Pettersson^Start-meny^Program^Autostart^No-IP DUC.lnk]

path=c:\documents and settings\Mikael Pettersson\Start-meny\Program\Autostart\No-IP DUC.lnk

backup=c:\windows\pss\No-IP DUC.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellTouch]

2002-01-16 22:49 163840 ----a-w- c:\windows\MMKeybd.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

2005-09-17 21:28 98304 ----a-w- c:\program\QuickTime\qttask.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegKillElbyCheck]

2002-11-02 06:33 45056 ----a-w- c:\program\Elaborate Bytes\DVD Region Killer\ElbyCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegKillTray]

2002-11-27 21:11 49152 ----a-w- c:\program\Elaborate Bytes\DVD Region Killer\RegKillTray.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tweak UI]

2003-03-25 04:49 106544 ----a-r- c:\windows\system32\tweakui.cpl

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]

2006-03-30 14:45 313472 ----a-w- c:\program\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USIUDF_Eject_Monitor]

2004-05-28 03:50 81920 ------w- c:\program\Delade filer\Ulead Systems\DVD\USISrv.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WordQ carat flag]

2004-02-06 05:00 24576 ----a-w- c:\program\WordQ\WordQcrs.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program\\Messenger\\msmsgs.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"26263:TCP"= 26263:TCP:BitComet 26263 TCP

"26263:UDP"= 26263:UDP:BitComet 26263 UDP

"9777:TCP"= 9777:TCP:qfcgjevx

 

R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [2005-10-25 160640]

R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [2005-10-25 5248]

R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [2004-10-25 155136]

R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [2004-10-25 5248]

R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [2003-05-07 11264]

R1 ATMhelpr;ATMhelpr;c:\windows\system32\drivers\ATMHELPR.SYS [2003-03-22 4064]

R2 Nhksrv;Netropa NHK Server;c:\windows\Nhksrv.exe [2002-11-12 28672]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program\Delade filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-03-11 109616]

R3 Msikbd2k;DellTouch;c:\windows\system32\drivers\Msikbd2k.sys [2002-11-12 6656]

R3 RegKill;RegKill;c:\windows\system32\drivers\RegKill.sys [2002-11-27 6400]

S0 ElbyVCD;ElbyVCD;c:\windows\system32\DRIVERS\ElbyVCD.sys --> c:\windows\system32\DRIVERS\ElbyVCD.sys [?]

S2 Ca533av;Icatch(IV) Video Camera Device;c:\windows\system32\drivers\Ca533av.sys [2010-06-21 515803]

S2 pnnesyksa;Installer Monitor;c:\windows\system32\svchost.exe -k netsvcs [2002-07-01 14336]

S3 Amps2prt;A4Tech PS/2 Port Mouse Driver;c:\windows\system32\drivers\Amps2prt.sys [2004-01-12 9728]

S3 Axtmvflt;Axesstel USB Filter Service;c:\windows\system32\drivers\Axtmvflt.sys [2010-06-03 3456]

S3 Axtmvmdm;Axesstel USB Modem;c:\windows\system32\drivers\Axtmvmdm.sys [2010-06-03 40064]

S3 Axtmvprt;Axesstel Diagnostic Port;c:\windows\system32\drivers\Axtmvprt.sys [2010-06-03 38784]

S3 QCEmerald;Logitech QuickCam Web;c:\windows\system32\drivers\OVCE.sys [2003-01-17 31872]

S3 TodosScReader;Driver for Todos Argosmini Usb;c:\windows\system32\drivers\amusb.sys [2003-04-23 82464]

 

--- Övriga tjänster/drivrutiner i minnet ---

 

*NewlyCreated* - PNNESYKSA

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

pnnesyksa

.

.

------- Extra genomsökning -------

.

uStart Page = hxxp://ccp.crystone.net/

IE: Download all links using BitComet - c:\program\BitComet\BitComet.exe/AddAllLink.htm

IE: Download all videos using BitComet - c:\program\BitComet\BitComet.exe/AddVideo.htm

IE: Download link using &BitComet - c:\program\BitComet\BitComet.exe/AddLink.htm

IE: E&xportera till Microsoft Excel - c:\program\MICROS~2\Office10\EXCEL.EXE/3000

IE: {{641F4F4E-6C91-4159-869E-9F5CE6F0F64E} - c:\program\MultiPoker\MultiPoker.exe

IE: {{B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - c:\program\PartyGaming\PartyCasino\RunCasino.exe

IE: {{EFFF8D47-D060-4108-B761-E8EC86622E56} - c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Absolute Poker\Absolute Poker.lnk

DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-12-24 13:17

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\pnnesyksa]

"ServiceDll"="c:\windows\system32\tehwfq.dll"

.

--------------------- DLLer som "laddats" under processer som körs ---------------------

 

- - - - - - - > 'explorer.exe'(3908)

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

.

Sluttid: 2010-12-24 13:20:40

ComboFix-quarantined-files.txt 2010-12-24 12:20

ComboFix2.txt 2010-12-23 18:44

ComboFix3.txt 2010-12-21 19:19

ComboFix4.txt 2010-12-18 19:45

ComboFix5.txt 2010-12-24 12:09

 

Före genomsökningen: 94 396 051 456 byte ledigt

Efter genomsökningen: 94 383 222 784 byte ledigt

 

- - End Of File - - BEE3E8DB852B3365F5A39D815B3DB5A5

 

Trevlig helg!!

Länk till kommentar
Dela på andra webbplatser

Tack detsamma! :)

 

Tyvärr så kommer det vi åtgärdar tillbaka hela tiden :(

 

1.

Spara DeFogger by jpshortstuff http://www.jpshortstuff.247fixes.com/Defogger.exe på Skrivbordet.

 

Starta DeFogger.

När programmets fönster kommer upp trycker du på knappen Disable för att inaktivera drivrutinerna som hör ihop med ditt installerade CD-emuleringsprogram.

Tryck på Yes/Ja för att fortsätta.

När programmet är klart kommer det upp ett meddelande 'Finished!'.

Tryck på OK.

Programmet ber om omstart av datorn, tryck på OK.

 

VIKTIGT! Om du får ett felmeddelande medan DeFogger kör, så klistra in loggen defogger_disable som då skapas på Skrivbordet.

 

Aktivera inte dessa drivrutiner innan rensningen är helt klar.

 

2.

Kör TDSSKiller på samma sätt som tidigare. Starta sedan om datorn.

 

3.

Spara Rootkit Unhooker på skrivbordet.

http://www.kernelmode.info/ARKs/RkU3.8.388.590.rar

Packa upp programmet. Om du inte har något uppackningsprogram för rar-filer kan du hämta 7-zip. http://www.7-zip.org/

 

Dra ut internetanslutningen. Stäng av alla program du ser inklusive brandvägg, antivirusprogram och antispionprogram.

 

Dubbelklicka på Rootkit Unhooker för att starta det (i Vista och Windows 7 högerklicka och välj Kör som administratör).

Välj fliken Report och klicka på Scan

Bocka för Drivers, Stealth, Files och Code Hooks, men avbocka de andra valen.

Tryck på OK

Vänta tills skannern är klar och då väljer du File - Save Report. Spara rapporten på Skrivbordet eller på något annat ställe där du hittar igen den. Klicka på Close.

 

Öppna den sparade rapporten i Anteckningar. Klistra in innehållet i ditt svar.

 

Observera att om det kommer upp en varning "Rootkit Unhooker has detected a parasite..." så ignorera den bara.

 

4.

Gör punkt 2 i inlägg 43 efter en omstart av datorn.

Länk till kommentar
Dela på andra webbplatser

defogger disable:

 

defogger_disable by jpshortstuff (23.02.10.1)

Log created at 14:15 on 25/12/2010 (Mikael Pettersson)

 

Checking for autostart values...

HKCU\~\Run values retrieved.

HKLM\~\Run values retrieved.

 

Checking for services/drivers...

a347bus -> Disabled (Service running -> reboot required)

a347scsi -> Disabled (Service running -> reboot required)

Unable to read atapi.sys

d347prt -> Disabled (Service running -> reboot required)

d347bus -> Disabled (Service running -> reboot required)

 

 

-=E.O.F=-

 

 

Länk till kommentar
Dela på andra webbplatser

tdsskiller:

 

2010/12/25 14:27:59.0781 TDSS rootkit removing tool 2.4.12.0 Dec 16 2010 09:46:46

2010/12/25 14:27:59.0781 ================================================================================

2010/12/25 14:27:59.0781 SystemInfo:

2010/12/25 14:27:59.0781

2010/12/25 14:27:59.0781 OS Version: 5.1.2600 ServicePack: 2.0

2010/12/25 14:27:59.0781 Product type: Workstation

2010/12/25 14:27:59.0781 ComputerName: DELL

2010/12/25 14:27:59.0781 UserName: Mikael Pettersson

2010/12/25 14:27:59.0781 Windows directory: C:\WINDOWS

2010/12/25 14:27:59.0781 System windows directory: C:\WINDOWS

2010/12/25 14:27:59.0781 Processor architecture: Intel x86

2010/12/25 14:27:59.0781 Number of processors: 1

2010/12/25 14:27:59.0781 Page size: 0x1000

2010/12/25 14:27:59.0781 Boot type: Normal boot

2010/12/25 14:27:59.0781 ================================================================================

2010/12/25 14:28:00.0328 Initialize success

2010/12/25 14:28:04.0437 ================================================================================

2010/12/25 14:28:04.0437 Scan started

2010/12/25 14:28:04.0437 Mode: Manual;

2010/12/25 14:28:04.0437 ================================================================================

2010/12/25 14:28:06.0187 a347bus (1f61cacacb521215f39061789147968c) C:\WINDOWS\system32\DRIVERS\a347bus.sys

2010/12/25 14:28:06.0609 a347scsi (113e4b318bbaa7483ca4e582a4d63f49) C:\WINDOWS\System32\Drivers\a347scsi.sys

2010/12/25 14:28:07.0531 ACPI (d51b4fd79d252851a8f13cfe9404cd2b) C:\WINDOWS\system32\DRIVERS\ACPI.sys

2010/12/25 14:28:08.0000 ACPIEC (decedc736cef3c0fff6e981b31e73a61) C:\WINDOWS\system32\drivers\ACPIEC.sys

2010/12/25 14:28:08.0625 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys

2010/12/25 14:28:09.0093 AFD (944ca435bfcfc82cc1ed9e3a7d731aa9) C:\WINDOWS\System32\drivers\afd.sys

2010/12/25 14:28:09.0500 agp440 (2c428fa0c3e3a01ed93c9b2a27d8d4bb) C:\WINDOWS\system32\DRIVERS\agp440.sys

2010/12/25 14:28:11.0156 Amfilter (20ceb8b2ff46d4b3277db3067b307c37) C:\WINDOWS\system32\DRIVERS\Amfilter.sys

2010/12/25 14:28:11.0515 Amps2prt (853ed69c22cef5cba05c43c08fbb6714) C:\WINDOWS\system32\DRIVERS\Amps2prt.sys

2010/12/25 14:28:12.0125 Amusbprt (2a1c3083cfaf12e20d0e9993ca0d80d8) C:\WINDOWS\system32\DRIVERS\Amusbprt.sys

2010/12/25 14:28:12.0500 Asapi (875f9079cabee679d34b49e466b61701) C:\WINDOWS\system32\drivers\Asapi.sys

2010/12/25 14:28:13.0937 Aspi32 (5b01af89d16d562825c4db4530f20cbb) C:\WINDOWS\system32\drivers\Aspi32.sys

2010/12/25 14:28:14.0515 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys

2010/12/25 14:28:15.0046 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys

2010/12/25 14:28:15.0812 ati2mtag (a5d15aa85c5a869bf04982bd50c7df8b) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys

2010/12/25 14:28:16.0343 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys

2010/12/25 14:28:16.0703 ATMhelpr (3ef1db7f168851914517d4ed36b57c04) C:\WINDOWS\system32\drivers\ATMhelpr.sys

2010/12/25 14:28:17.0093 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys

2010/12/25 14:28:17.0437 Axtmvflt (59629edd214c35a01e2527ac3b8a7fb3) C:\WINDOWS\system32\DRIVERS\Axtmvflt.sys

2010/12/25 14:28:17.0796 Axtmvmdm (37e23b1756eca768656097f72c0b458d) C:\WINDOWS\system32\DRIVERS\Axtmvmdm.sys

2010/12/25 14:28:18.0203 Axtmvprt (2c7170be24eacc0b432eb1832fee0ddc) C:\WINDOWS\system32\Drivers\Axtmvprt.sys

2010/12/25 14:28:18.0578 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys

2010/12/25 14:28:18.0984 Bridge (e4e6a0922e3d983728c9ad4e8d466954) C:\WINDOWS\system32\DRIVERS\bridge.sys

2010/12/25 14:28:19.0046 BridgeMP (e4e6a0922e3d983728c9ad4e8d466954) C:\WINDOWS\system32\DRIVERS\bridge.sys

2010/12/25 14:28:19.0625 Ca533av (a8eae8e358de3a21e6eb54f4fc7f65ec) C:\WINDOWS\system32\Drivers\Ca533av.sys

2010/12/25 14:28:20.0421 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys

2010/12/25 14:28:20.0812 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys

2010/12/25 14:28:21.0515 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys

2010/12/25 14:28:21.0921 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys

2010/12/25 14:28:22.0296 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys

2010/12/25 14:28:23.0562 d347bus (5776322f93cdb91086111f5ffbfda2a0) C:\WINDOWS\system32\DRIVERS\d347bus.sys

2010/12/25 14:28:23.0984 d347prt (b49f79ace459763f4e0380071be9cb45) C:\WINDOWS\System32\Drivers\d347prt.sys

2010/12/25 14:28:24.0843 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys

2010/12/25 14:28:25.0484 dmboot (80bad99bf48053d32309afa3e8112de9) C:\WINDOWS\system32\drivers\dmboot.sys

2010/12/25 14:28:26.0156 dmio (33824764d4161c320ad7b56b6fa5f053) C:\WINDOWS\system32\drivers\dmio.sys

2010/12/25 14:28:26.0562 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys

2010/12/25 14:28:26.0984 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys

2010/12/25 14:28:27.0625 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys

2010/12/25 14:28:28.0046 E100B (98ed0bea10477b0f252cca35eb50f838) C:\WINDOWS\system32\DRIVERS\e100b325.sys

2010/12/25 14:28:28.0375 eeCtrl (31c959319ef45b548d2111e338412270) C:\Program\Delade filer\Symantec Shared\EENGINE\eeCtrl.sys

2010/12/25 14:28:28.0734 ElbyCDIO (cd35088d84a17ca694658a3cb0ebd13c) C:\WINDOWS\system32\Drivers\ElbyCDIO.sys

2010/12/25 14:28:29.0125 ElbyDelay (0b15894b0698abcac9f19d060119d1d0) C:\WINDOWS\system32\Drivers\ElbyDelay.sys

2010/12/25 14:28:29.0671 EraserUtilRebootDrv (e7d1a496c71cd56bdd97f32c9141a03b) C:\Program\Delade filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys

2010/12/25 14:28:30.0140 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys

2010/12/25 14:28:30.0515 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys

2010/12/25 14:28:30.0890 Fips (725ba8685312faf7ff7b2aa7eb32ae57) C:\WINDOWS\system32\drivers\Fips.sys

2010/12/25 14:28:31.0281 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys

2010/12/25 14:28:31.0687 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\drivers\fltmgr.sys

2010/12/25 14:28:32.0125 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys

2010/12/25 14:28:32.0546 Ftdisk (45fc410cfe68ff036ad232a141e69c19) C:\WINDOWS\system32\DRIVERS\ftdisk.sys

2010/12/25 14:28:32.0937 gameenum (5f92fd09e5610a5995da7d775eadcd12) C:\WINDOWS\system32\DRIVERS\gameenum.sys

2010/12/25 14:28:33.0328 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys

2010/12/25 14:28:33.0734 hcwPP2 (b5254447f5a934818be540210c5f90e3) C:\WINDOWS\system32\DRIVERS\hcwPP2.sys

2010/12/25 14:28:34.0156 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys

2010/12/25 14:28:35.0093 HTTP (cb77bb47e67e84deb17ba29632501730) C:\WINDOWS\system32\Drivers\HTTP.sys

2010/12/25 14:28:36.0046 i8042prt (fb251fb7a44e34f3b9721472493d7992) C:\WINDOWS\system32\DRIVERS\i8042prt.sys

2010/12/25 14:28:36.0421 imagedrv (0a7c49b48c772591a2d362daa00246c8) C:\WINDOWS\system32\Drivers\imagedrv.sys

2010/12/25 14:28:36.0828 imagesrv (549ba4f539e7b8d8129500b96dd7b27a) C:\WINDOWS\system32\DRIVERS\imagesrv.sys

2010/12/25 14:28:37.0296 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\drivers\Imapi.sys

2010/12/25 14:28:38.0171 intelppm (3cf8684ac56b796f109e859f0cc65a99) C:\WINDOWS\system32\DRIVERS\intelppm.sys

2010/12/25 14:28:38.0562 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\drivers\ip6fw.sys

2010/12/25 14:28:38.0953 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys

2010/12/25 14:28:39.0328 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys

2010/12/25 14:28:39.0718 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys

2010/12/25 14:28:40.0171 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys

2010/12/25 14:28:40.0546 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys

2010/12/25 14:28:40.0921 isapnp (303640835cb95b00590b962283570648) C:\WINDOWS\system32\DRIVERS\isapnp.sys

2010/12/25 14:28:41.0296 Kbdclass (ce96bfa4af66a2fe61982093bd1d8ffb) C:\WINDOWS\system32\DRIVERS\kbdclass.sys

2010/12/25 14:28:41.0687 kbdhid (8414f174d2199730d06f309389d2da02) C:\WINDOWS\system32\DRIVERS\kbdhid.sys

2010/12/25 14:28:42.0156 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys

2010/12/25 14:28:42.0593 KSecDD (eb7ffe87fd367ea8fca0506f74a87fbb) C:\WINDOWS\system32\drivers\KSecDD.sys

2010/12/25 14:28:43.0265 lusbaudio (081caf42d5db1fcf8794fd77befd1b11) C:\WINDOWS\system32\drivers\OVSound2.sys

2010/12/25 14:28:43.0656 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys

2010/12/25 14:28:44.0093 Modem (16482d7667fb6783108bbd90ad36b159) C:\WINDOWS\system32\drivers\Modem.sys

2010/12/25 14:28:44.0453 Mouclass (91460066455e77da014cd5ef45b150e2) C:\WINDOWS\system32\DRIVERS\mouclass.sys

2010/12/25 14:28:44.0812 mouhid (98e474ecf11f1db62fb072157a95ea83) C:\WINDOWS\system32\DRIVERS\mouhid.sys

2010/12/25 14:28:45.0218 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys

2010/12/25 14:28:45.0906 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys

2010/12/25 14:28:46.0453 MRxSmb (025af03ce51645c62f3b6907a7e2be5e) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys

2010/12/25 14:28:46.0953 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys

2010/12/25 14:28:47.0343 Msikbd2k (9b99b04c28ccd19741dbbed64480195c) C:\WINDOWS\system32\DRIVERS\msikbd2k.sys

2010/12/25 14:28:47.0703 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys

2010/12/25 14:28:48.0078 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys

2010/12/25 14:28:48.0437 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys

2010/12/25 14:28:48.0796 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys

2010/12/25 14:28:49.0187 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys

2010/12/25 14:28:49.0578 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys

2010/12/25 14:28:49.0984 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys

2010/12/25 14:28:50.0640 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys

2010/12/25 14:28:51.0109 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys

2010/12/25 14:28:51.0468 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys

2010/12/25 14:28:51.0843 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys

2010/12/25 14:28:52.0296 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys

2010/12/25 14:28:52.0703 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys

2010/12/25 14:28:53.0109 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys

2010/12/25 14:28:53.0531 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys

2010/12/25 14:28:54.0000 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys

2010/12/25 14:28:54.0531 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys

2010/12/25 14:28:55.0093 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys

2010/12/25 14:28:55.0484 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys

2010/12/25 14:28:55.0843 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys

2010/12/25 14:28:56.0265 NwlnkIpx (79ea3fcda7067977625b3363a2657c80) C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys

2010/12/25 14:28:56.0671 NwlnkNb (56d34a67c05e94e16377c60609741ff8) C:\WINDOWS\system32\DRIVERS\nwlnknb.sys

2010/12/25 14:28:57.0109 NwlnkSpx (c0bb7d1615e1acbdc99757f6ceaf8cf0) C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys

2010/12/25 14:28:57.0515 OMCI (1d98907d80461371437a7c898c58c8ae) C:\WINDOWS\system32\DRIVERS\omci.sys

2010/12/25 14:28:58.0296 P16X (e433c553d00d76fbc616294b60a7a530) C:\WINDOWS\system32\drivers\P16X.sys

2010/12/25 14:28:59.0125 Parport (fb0832a8cd0b3ea70d133768f551ae78) C:\WINDOWS\system32\DRIVERS\parport.sys

2010/12/25 14:28:59.0531 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys

2010/12/25 14:28:59.0906 ParVdm (5cf71e14a108c492c1fb07543d579af5) C:\WINDOWS\system32\drivers\ParVdm.sys

2010/12/25 14:29:00.0328 PCI (9554dd34eddafa76d502cb0ec439273d) C:\WINDOWS\system32\DRIVERS\pci.sys

2010/12/25 14:29:01.0031 PCIIde (239de4275ee40fdf9912761467025244) C:\WINDOWS\system32\DRIVERS\pciide.sys

2010/12/25 14:29:01.0437 Pcmcia (40b2b244caa60e60aceb54f01767b14d) C:\WINDOWS\system32\drivers\Pcmcia.sys

2010/12/25 14:29:03.0500 PfModNT (2f5532f9b0f903b26847da674b4f55b2) C:\WINDOWS\System32\PfModNT.sys

2010/12/25 14:29:03.0562 Suspicious service (NoAccess): pnnesyksa

2010/12/25 14:29:03.0937 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys

2010/12/25 14:29:04.0328 Processor (90c88834631196c242f09439ee696135) C:\WINDOWS\system32\DRIVERS\processr.sys

2010/12/25 14:29:04.0734 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys

2010/12/25 14:29:05.0156 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys

2010/12/25 14:29:05.0546 PxHelp20 (b572ed0c3e6165643fa116af20425a54) C:\WINDOWS\system32\DRIVERS\PxHelp20.sys

2010/12/25 14:29:05.0906 QCEmerald (90849934d37133e069f31f3e9a66c9bc) C:\WINDOWS\system32\DRIVERS\OVCE.sys

2010/12/25 14:29:07.0500 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys

2010/12/25 14:29:07.0890 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys

2010/12/25 14:29:08.0312 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys

2010/12/25 14:29:08.0687 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys

2010/12/25 14:29:09.0156 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys

2010/12/25 14:29:09.0562 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys

2010/12/25 14:29:09.0968 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys

2010/12/25 14:29:10.0421 redbook (6ab3e65a46fb2a6f21ba5acfdfa44fab) C:\WINDOWS\system32\DRIVERS\redbook.sys

2010/12/25 14:29:10.0781 RegKill (27ce3d4c589e5fae38ea0bd0fdfa3fd6) C:\WINDOWS\system32\Drivers\RegKill.sys

2010/12/25 14:29:11.0140 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys

2010/12/25 14:29:11.0531 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS

2010/12/25 14:29:11.0937 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys

2010/12/25 14:29:12.0390 Ser2pl (b490ad520257dda26c1d587a71e527b5) C:\WINDOWS\system32\DRIVERS\ser2pl.sys

2010/12/25 14:29:12.0765 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys

2010/12/25 14:29:13.0171 Serial (6494c4e513795c363b20e0f2c9a2e9ab) C:\WINDOWS\system32\DRIVERS\serial.sys

2010/12/25 14:29:13.0562 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys

2010/12/25 14:29:14.0281 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys

2010/12/25 14:29:14.0890 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys

2010/12/25 14:29:15.0312 sr (125ccd7b6b7e4732a03b6f4d69f87f7b) C:\WINDOWS\system32\DRIVERS\sr.sys

2010/12/25 14:29:15.0812 Srv (ea554a3ffc3f536fe8320eb38f5e4843) C:\WINDOWS\system32\DRIVERS\srv.sys

2010/12/25 14:29:16.0312 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys

2010/12/25 14:29:16.0671 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys

2010/12/25 14:29:17.0031 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys

2010/12/25 14:29:17.0953 SYMDNS (59d8c75535b3cc1f53dead280e27fbe7) C:\WINDOWS\System32\Drivers\SYMDNS.SYS

2010/12/25 14:29:18.0375 SymEvent (403bd24fa5c55fc648abdd039629a954) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS

2010/12/25 14:29:18.0750 SYMFW (8025efbb54a03e93047a4ac21882806a) C:\WINDOWS\System32\Drivers\SYMFW.SYS

2010/12/25 14:29:19.0156 SYMIDS (fb3c0b132937434f38f0afebf9ae507b) C:\WINDOWS\System32\Drivers\SYMIDS.SYS

2010/12/25 14:29:19.0531 SYMNDIS (4af79c29cc656a8fa4035dfe2bb5108b) C:\WINDOWS\System32\Drivers\SYMNDIS.SYS

2010/12/25 14:29:19.0890 SYMREDRV (8d663525791eb438a71df7d96227b398) C:\WINDOWS\System32\Drivers\SYMREDRV.SYS

2010/12/25 14:29:20.0328 SYMTDI (4a294bf8a1a11485da5cb79216e3291b) C:\WINDOWS\System32\Drivers\SYMTDI.SYS

2010/12/25 14:29:21.0187 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys

2010/12/25 14:29:21.0703 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys

2010/12/25 14:29:22.0093 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys

2010/12/25 14:29:22.0484 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys

2010/12/25 14:29:22.0859 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys

2010/12/25 14:29:23.0281 TodosScReader (00189b579708bf2b0557d647a5d15f68) C:\WINDOWS\system32\Drivers\amusb.sys

2010/12/25 14:29:23.0953 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys

2010/12/25 14:29:24.0343 ULCDRHlp (8e6d8af8b2e589338292d8373195f206) C:\WINDOWS\system32\Drivers\ULCDRHlp.sys

2010/12/25 14:29:25.0093 Update (ced744117e91bdc0beb810f7d8608183) C:\WINDOWS\system32\DRIVERS\update.sys

2010/12/25 14:29:25.0562 usbaudio (45a0d14b26c35497ad93bce7e15c9941) C:\WINDOWS\system32\drivers\usbaudio.sys

2010/12/25 14:29:25.0937 USBCamera (0c28dd9ec68ccb6e95d49bfd24fd2c11) C:\WINDOWS\system32\Drivers\Bulk533.sys

2010/12/25 14:29:26.0312 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys

2010/12/25 14:29:26.0687 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys

2010/12/25 14:29:27.0109 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys

2010/12/25 14:29:27.0515 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys

2010/12/25 14:29:27.0875 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys

2010/12/25 14:29:28.0281 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

2010/12/25 14:29:28.0625 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys

2010/12/25 14:29:29.0062 USIUDF (ccc552def5fcdc9ffa86c98452f7b8b5) C:\WINDOWS\system32\Drivers\USIUDF.sys

2010/12/25 14:29:29.0515 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys

2010/12/25 14:29:30.0125 VolSnap (4d5f0d3eb992d4c2bfb59077d62240ba) C:\WINDOWS\system32\drivers\VolSnap.sys

2010/12/25 14:29:30.0562 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys

2010/12/25 14:29:31.0187 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys

2010/12/25 14:29:31.0640 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS

2010/12/25 14:29:32.0203 ================================================================================

2010/12/25 14:29:32.0203 Scan finished

2010/12/25 14:29:32.0203 ================================================================================

Länk till kommentar
Dela på andra webbplatser

Det tog et tag för mig att förstå hur jag skulle göra för att köra Rootkit Unhooker. Jag måste ha instalerat programmet sju gånger innan jag listade ut det:)

Ang punkt 4 så gick det inte att köra mbr.exe nu heller. I alla fall tror jag inte det. Den lilla rutan med text som kom upp stannade några sekunder längre, men sedan försvann den. Vet inte hur det ska se ut när det fungerar, men någon form av rapport ska det väll vara?

Här är resultatet av Rootkit Unhooker i alla fall:

 

RkU Version: 3.8.388.590, Type LE (SR2)

==============================================

OS Name: Windows XP

Version 5.1.2600 (Service Pack 2)

Number of processors #1

==============================================

>Drivers

==============================================

0x804D7000 C:\WINDOWS\system32\ntoskrnl.exe 2181120 bytes (Microsoft Corporation, NT:s kernel och system)

0x804D7000 PnpManager 2181120 bytes

0x804D7000 RAW 2181120 bytes

0x804D7000 WMIxWDM 2181120 bytes

0xBF800000 Win32k 1847296 bytes

0xBF800000 C:\WINDOWS\System32\win32k.sys 1847296 bytes (Microsoft Corporation, Win32-drivrutin för flera användare)

0xB987D000 C:\WINDOWS\system32\drivers\P16X.sys 1294336 bytes (Creative Technology Ltd., WDM Audio Miniport)

0xBFA11000 C:\WINDOWS\System32\ati3duag.dll 659456 bytes (ATI Technologies Inc. , ati3duag.dll)

0xF7B52000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver)

0xB99F0000 C:\WINDOWS\System32\DRIVERS\ati2mtag.sys 540672 bytes (ATI Technologies Inc., ATI Radeon Miniport Driver)

0x9CFBF000 C:\WINDOWS\System32\DRIVERS\mrxsmb.sys 454656 bytes (Microsoft Corporation, Windows NT SMB Minirdr)

0x9CF5C000 C:\Program\Delade filer\Symantec Shared\EENGINE\eeCtrl.sys 405504 bytes (Symantec Corporation, Symantec Eraser Control Driver)

0xB97A1000 C:\WINDOWS\System32\DRIVERS\update.sys 364544 bytes (Microsoft Corporation, Update Driver)

0xA8C31000 C:\WINDOWS\System32\DRIVERS\tcpip.sys 360448 bytes (Microsoft Corporation, TCP/IP Protocol Driver)

0x9CB72000 C:\WINDOWS\System32\DRIVERS\srv.sys 335872 bytes (Microsoft Corporation, Server driver)

0xA8D8E000 C:\WINDOWS\System32\Drivers\USIUDF.sys 294912 bytes (Ulead Systems, Inc., Ulead UDF Driver for Windows XP)

0xBFFA0000 C:\WINDOWS\System32\ATMFD.DLL 286720 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver)

0x9C929000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack)

0xBF9D5000 C:\WINDOWS\System32\ati2dvag.dll 245760 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Display Driver)

0xF7589000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI-drivrutin för NT)

0xF7413000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver)

0x9CC64000 C:\WINDOWS\System32\DRIVERS\mrxdav.sys 180224 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)

0xA8B06000 C:\WINDOWS\System32\Drivers\SYMTDI.SYS 180224 bytes (Symantec Corporation, Network Dispatch Driver)

0x9D02E000 C:\WINDOWS\System32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)

0x9D07B000 C:\WINDOWS\System32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver)

0xB9836000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))

0xB985A000 C:\WINDOWS\system32\drivers\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library)

0x9D0A3000 C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 143360 bytes (Symantec Corporation, Symantec Event Library)

0xB99B9000 C:\WINDOWS\System32\DRIVERS\USBPORT.SYS 143360 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)

0x9D059000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)

0x9F5AC000 C:\WINDOWS\System32\DRIVERS\ipnat.sys 135168 bytes (Microsoft Corporation, IP Network Address Translator)

0x806EC000 ACPI_HAL 131968 bytes

0x806EC000 C:\WINDOWS\system32\hal.dll 131968 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)

0xF7469000 fltmgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)

0xF74B9000 ftdisk.sys 126976 bytes (Microsoft Corporation, Drivrutin för FT Disk)

0xF75B7000 imagesrv.sys 126976 bytes (Ahead Software AG, Nero Image Server)

0x9CF3E000 C:\Program\Delade filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 122880 bytes (Symantec Corporation, Symantec Eraser Utility Driver)

0xF787C000 Mup.sys 110592 bytes (Microsoft Corporation, Multiple UNC Provider driver)

0xF74A1000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver)

0x9CF26000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes

0xF7489000 C:\WINDOWS\System32\Drivers\SCSIPORT.SYS 98304 bytes (Microsoft Corporation, SCSI Port Driver)

0xF7440000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)

0xB980B000 C:\WINDOWS\System32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))

0x9CF10000 C:\WINDOWS\System32\DRIVERS\nwlnkipx.sys 90112 bytes (Microsoft Corporation, NWLINK2 IPX Protocol Driver)

0x9CE5B000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper)

0xB9822000 C:\WINDOWS\System32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Drivrutin för parallellport)

0xB99DC000 C:\WINDOWS\System32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver)

0xA8CEF000 C:\WINDOWS\System32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver)

0xBF9C3000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver)

0xF7457000 sr.sys 73728 bytes (Microsoft Corporation, Filterdrivrutin för Systemåterställning)

0xF7578000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI-uppräknare)

0xB97FA000 C:\WINDOWS\System32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler)

0xA8E81000 C:\WINDOWS\System32\Drivers\Udfs.SYS 69632 bytes (Microsoft Corporation, UDF File System Driver)

0xA3AD0000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver)

0xA0562000 C:\WINDOWS\System32\DRIVERS\nwlnknb.sys 65536 bytes (Microsoft Corporation, NWLINK2 IPX Netbios Protocol Driver)

0xF74E8000 C:\WINDOWS\System32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Seriell drivrutin)

0xF7508000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)

0xBA58C000 C:\WINDOWS\System32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Drivrutin för Redbook-ljudfilter)

0xA3A90000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter)

0xBAF17000 C:\WINDOWS\System32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB)

0xA0239000 C:\WINDOWS\System32\DRIVERS\nwlnkspx.sys 57344 bytes (Microsoft Corporation, NWLINK2 SPX Protocol Driver)

0xBAF67000 C:\WINDOWS\System32\DRIVERS\cdrom.sys 53248 bytes (Microsoft Corporation, SCSI CD-ROM Driver)

0xF7637000 C:\WINDOWS\System32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll)

0xF74F8000 C:\WINDOWS\System32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, Drivrutin för i8042 Port)

0xBA57C000 C:\WINDOWS\System32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)

0xF7617000 VolSnap.sys 53248 bytes (Microsoft Corporation, Drivrutin för ögonblicksbilder av volymer)

0xBA55C000 C:\WINDOWS\System32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)

0xF7647000 agp440.sys 45056 bytes (Microsoft Corporation, 440 NT AGP Filter)

0xF74D8000 C:\WINDOWS\system32\drivers\Imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver)

0xF7607000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager)

0xBA56C000 C:\WINDOWS\System32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)

0xF7518000 C:\WINDOWS\System32\DRIVERS\intelppm.sys 40960 bytes (Microsoft Corporation, Drivrutin för processor)

0xBA4FC000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy)

0xBA52C000 C:\WINDOWS\System32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver)

0xF7627000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver)

0x9FBD2000 C:\WINDOWS\System32\Drivers\Fips.SYS 36864 bytes (Microsoft Corporation, Drivrutin för FIPS-krypto)

0x9FBF2000 C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS 36864 bytes (Microsoft Corporation, Hid Class Library)

0xF75F7000 isapnp.sys 36864 bytes (Microsoft Corporation, PNP ISA Bussdrivrutin)

0xBA54C000 C:\WINDOWS\System32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier)

0xA01E9000 C:\WINDOWS\System32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver)

0x9C8B1000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)

0xA48CB000 C:\WINDOWS\System32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)

0xB9ABC000 C:\WINDOWS\System32\Drivers\Asapi.SYS 32768 bytes (VOB Computersysteme GmbH, ASAPI)

0xB9AAC000 C:\WINDOWS\System32\Drivers\Modem.SYS 32768 bytes (Microsoft Corporation, Modem-drivrutin)

0xF7797000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver)

0xF77B7000 C:\WINDOWS\System32\DRIVERS\fdc.sys 28672 bytes (Microsoft Corporation, Floppy Disk Controller Driver)

0xF77E7000 C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)

0xF77BF000 C:\WINDOWS\System32\DRIVERS\kbdclass.sys 28672 bytes (Microsoft Corporation, Tangentbordsklassdrivrutin)

0xF7707000 C:\WINDOWS\System32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)

0xF77C7000 C:\WINDOWS\System32\Drivers\ULCDRHlp.sys 28672 bytes (Ulead Systems, Inc., ULCDRHlp driver)

0xF77AF000 C:\WINDOWS\System32\DRIVERS\usbehci.sys 28672 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)

0xB9A8C000 C:\WINDOWS\System32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Musklassdrivrutin)

0xF77CF000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)

0xF774F000 C:\WINDOWS\System32\DRIVERS\flpydisk.sys 20480 bytes (Microsoft Corporation, Floppy Driver)

0xF777F000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver)

0xB9A7C000 C:\WINDOWS\system32\DRIVERS\omci.sys 20480 bytes (Dell Computer Corporation, OMCI Device Driver)

0xF770F000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager)

0xB9A9C000 C:\WINDOWS\System32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library)

0xF7717000 PxHelp20.sys 20480 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)

0xB9A94000 C:\WINDOWS\System32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver)

0xB9AA4000 C:\WINDOWS\System32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper)

0xF77A7000 C:\WINDOWS\System32\DRIVERS\usbuhci.sys 20480 bytes (Microsoft Corporation, UHCI USB Miniport Driver)

0xA01A1000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver)

0x9CEAC000 C:\WINDOWS\System32\Drivers\Aspi32.SYS 16384 bytes (Adaptec, ASPI for WIN32 Kernel Driver)

0xF794B000 C:\WINDOWS\System32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver)

0xA038D000 C:\WINDOWS\System32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver)

0xBA158000 C:\WINDOWS\System32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator)

0xF7897000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver)

0x9D3E5000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver)

0x9CCB4000 C:\WINDOWS\System32\Drivers\ElbyCDIO.sys 12288 bytes (Elaborate Bytes AG, ElbyCD Windows NT/2000/XP I/O driver)

0xBA15C000 C:\WINDOWS\System32\DRIVERS\gameenum.sys 12288 bytes (Microsoft Corporation, Game Port Enumerator)

0x9E49B000 C:\WINDOWS\system32\DRIVERS\hidusb.sys 12288 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices)

0x9DD65000 C:\WINDOWS\System32\DRIVERS\mouhid.sys 12288 bytes (Microsoft Corporation, Filterdrivrutin för HID-mus)

0xBA150000 C:\WINDOWS\System32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)

0xA96CC000 C:\WINDOWS\System32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver)

0xF7A09000 C:\WINDOWS\system32\DRIVERS\Amfilter.sys 8192 bytes (A4Tech Co.,Ltd., A4Tech iWheelWorks Mouse Filter Driver)

0xF7A07000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver)

0xF799F000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes

0xF7A05000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver)

0xF798B000 imagedrv.sys 8192 bytes (Ahead Software AG, NERO IMAGEDRIVE SCSI miniport)

0xF7987000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)

0xF798F000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator)

0xF79EB000 C:\WINDOWS\system32\DRIVERS\msikbd2k.sys 8192 bytes (Netropa Corporation, Multimedia Keyboard Driver for Windows 2000/XP)

0xF79C9000 C:\WINDOWS\System32\Drivers\ParVdm.SYS 8192 bytes (Microsoft Corporation, Parallellportsdrivrutin för VDM)

0xA064A000 C:\WINDOWS\System32\PfModNT.sys 8192 bytes (Creative Technology Ltd., PCI/ISA Device Info. Service)

0xF7991000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport)

0xF79ED000 C:\WINDOWS\System32\Drivers\RegKill.sys 8192 bytes (Elaborate Bytes, DVD RegionKiller Lower Filter Driver)

0xF79F1000 C:\WINDOWS\System32\Drivers\RootMdm.sys 8192 bytes (Microsoft Corporation, Legacy Non-Pnp Modem Device Driver)

0xF79F3000 C:\WINDOWS\System32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)

0xF79F7000 C:\WINDOWS\System32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)

0xF7989000 C:\WINDOWS\System32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll)

0xA90C2000 C:\WINDOWS\System32\Drivers\ATMhelpr.SYS 4096 bytes (Adobe Systems Incorporated, Windows NT Font Driver Helper)

0xBAE2A000 C:\WINDOWS\System32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver)

0xA0751000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk)

0xBAE2F000 C:\WINDOWS\System32\Drivers\ElbyDelay.sys 4096 bytes (Elaborate Bytes AG, Elby Delay Lower Filter Driver)

0xA90F7000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver)

0xF7A4F000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE-bussdrivrutin)

==============================================

>Stealth

==============================================

==============================================

>Files

==============================================

!-->[Hidden] C:\a181816a106b8d8c256f

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Application Data\CanonBJ

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Application Data\DVD Shrink

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Media Player

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Connections\Cm

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\WIA\{6BDD1FC6-810F-11D0-BEC7-08002BE2092F}\0002

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Application Data\Sun\Java\Java Update

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Shared\QBackup\{1506786E-3E11-417B-8FAE-20B13FBC1416}

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Shared\QBackup\{58FE5698-5831-44F6-A1E1-6A43AFDA3CAD}

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Shared\QBackup\{88BB304F-92F7-451F-8215-2AECDCC1294A}

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Shared\QBackup\{8B162163-9E59-451F-AA36-D15BD7856F59}

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Shared\QBackup\{BEC8DF42-0C3D-4B77-A993-CE26993D0BE6}

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Shared\QBackup\{CB667FCF-BF96-4872-8BDA-A0EA181FC983}

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Application Data\Ulead Systems

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\Alcohol 120%

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\ArcSoft PhotoImpression 4

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\ArcSoft VideoImpression 1.6

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\Boilsoft AVI to VCD SVCD DVD Converter

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\Canon MP600

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\DVD Shrink

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\FreeRIP

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\Hauppauge WinTV

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\MIKSOFT

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\nanocosmos MPEG Tools for Hauppauge

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\Nero

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\Process Explorer

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\Simpli Software

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\Ulead DVD MovieFactory 3.5 Suite

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\VTPlus for WinTV

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\Windows Media

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\WinZip

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\WiViK

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\WordQ

!-->[Hidden] C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\WS_FTP

!-->[Hidden] C:\Documents and Settings\LocalService.NT INSTANS\Lokala inställningar\Application Data\Microsoft\Internet Explorer

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\AdobeUM

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Adobe\Acrobat\7.0\Collab

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Adobe\Acrobat\7.0\JavaScripts

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Adobe\Acrobat\7.0\Messages

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Adobe\Acrobat\7.0\Preferences

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Adobe\Acrobat\7.0\Updater

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Adobe\ESD

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Adobe\Linguistics

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\ArcSoft

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Canon

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Leadertech

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Macromedia\Flash Player

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Macromedia\Shockwave Player

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Microgaming\MPG

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Microsoft\CryptnetUrlCache

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Microsoft\Installer

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Microsoft\MSDAIPP\Offline

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Microsoft\Windows Messenger\1779515438

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Microsoft\Windows Messenger\1872838096

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\MobileAction

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Mozilla\Firefox\Profiles

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Mozilla\Profiles\default\6o37d5h8.slt\Mail\pop.chello.se\Inbox.sbd\Svar.sbd

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Opera

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\SmartFTP\Data

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Steinberg

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Sun\Java\Deployment\cache\6.0\host

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Sun\Java\Deployment\SystemCache

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Application Data\Ulead Systems

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Favoriter\Bookmarks Toolbar Folder

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Favoriter\Firefox and Mozilla Links

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Favoriter\Importerade bokmärken\Affärsverksamhet och Ekonomi

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Favoriter\Importerade bokmärken\Datorer och Internet

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Favoriter\Importerade bokmärken\Marknad

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Favoriter\Importerade bokmärken\Mina Saker

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Favoriter\Importerade bokmärken\Nyheter

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Favoriter\Importerade bokmärken\Resor

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Favoriter\Importerade bokmärken\Sport

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Favoriter\Importerade bokmärken\Underhållning

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Favoriter\Importerade bokmärken\Uppslagsverk

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Favoriter\Quick Searches

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\IECompatCache

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Lokala inställningar\Application Data\Adobe

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Lokala inställningar\Application Data\Ahead

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Lokala inställningar\Application Data\Microsoft\Feeds\Bookmarks Toolbar Folder~

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Lokala inställningar\Application Data\Microsoft\Internet Explorer\Recovery\Last Active

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Lokala inställningar\Application Data\Microsoft\Internet Explorer\Services

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Lokala inställningar\Application Data\Microsoft\Media Player

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Lokala inställningar\Application Data\Microsoft\Windows Media

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Lokala inställningar\Application Data\Mozilla

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Lokala inställningar\Application Data\NFS Underground 2

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Lokala inställningar\Temporary Internet Files\AntiPhishing

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Lokala inställningar\Temporary Internet Files\Content.IE5\AMNV4LRO\adlink_506_1040250_18004_16_AdId=5742728;BnId=1;itime=281788014;key=Säkerhet+Virus,%20skadliga%20program%20&%20botemedel;link=;ord=281788014[1].jss

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Lokala inställningar\Temporary Internet Files\Content.IE5\I9PDPKFI\adlink_506_1077841_18004_16_AdId=2848190;BnId=2;itime=285385968;key=Säkerhet+Virus,%20skadliga%20program%20&%20botemedel;nodecode=yes;link=[1].jsjs

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Lokala inställningar\Temporary Internet Files\Content.IE5\QPG3UPYM\adlink_506_1040249_18004_16_AdId=2305492;BnId=1;itime=213774932;key=Säkerhet+Virus,%20skadliga%20program%20&%20botemedel;nodecode=yes;link=[1].jsjs

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Lokala inställningar\Temporary Internet Files\Content.IE5\QPG3UPYM\adlink_506_1040249_18004_16_AdId=2305492;BnId=1;itime=281877521;key=Säkerhet+Virus,%20skadliga%20program%20&%20botemedel;nodecode=yes;link=[1].jsjs

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Mina dokument\DI-714P+ Router\Router Firmware

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Mina dokument\Mina bilder\2010-07-31 Rakad Leo

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Mina dokument\Mina bilder\2010-09-12 Harley första körturen

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Mina dokument\Mina bilder\2010-09-29Malakai och Sweetie

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Mina dokument\Mina bilder\2010-10-06 Harley och hovslagaren

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Mina dokument\Mina bilder\2010-10-17 Banshee och Solo

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Mina dokument\Mina bilder\2010-10-24 Malakai, foto Cila

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Mina dokument\Mina bilder\2010-11-28 Harley på julmarknad

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Mina dokument\Mina bilder\2010-12-01 Banshee bäbisar\2010-12-03

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Mina dokument\Mina bilder\ALC

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Mina dokument\Mina texter\Feedback från MIUN

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Mina dokument\My Albums

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Mina dokument\PcSetup

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Mina dokument\Seriemördare - Wikipedia-filer

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Mina dokument\Symantec

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Mina dokument\Ulead DVD MovieFactory

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Mina dokument\Ulead DVD MovieFactory 4.0

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Mina dokument\Ulead DVD Player\1.5\Bookmarks

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Phone Browser

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Recent\Delade dokum på Svarta stationära DELL (Dell)

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Start-meny\Program\A4Tech Hardware

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Start-meny\Program\AVIcodec

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Start-meny\Program\BitComet

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Start-meny\Program\DVD Decrypter

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Start-meny\Program\Games

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Start-meny\Program\Hauppauge WinTV

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Start-meny\Program\Lavasoft Ad-aware 6

!-->[Hidden] C:\Documents and Settings\Mikael Pettersson\Start-meny\Program\Steinberg Cubase VST32 5.1

!-->[Hidden] C:\Documents and Settings\NetworkService.NT INSTANS\Application Data\Microsoft\CLR Security Config

!-->[Hidden] C:\DRIVERS\NEC 2510 A - Firmware

!-->[Hidden] C:\DRIVERS\NERO UPDATE

!-->[Hidden] C:\DVD TEMP

!-->[Hidden] C:\Program\321Studios

!-->[Hidden] C:\Program\3DO

!-->[Hidden] C:\Program\A4Tech

!-->[Hidden] C:\Program\Adobe\Acrobat 7.0

!-->[Hidden] C:\Program\ahead\CoverDesigner\LSTemplates

!-->[Hidden] C:\Program\ahead\CoverDesigner\Templates

!-->[Hidden] C:\Program\ahead\ImageDrive

!-->[Hidden] C:\Program\ahead\MyMusic

!-->[Hidden] C:\Program\ahead\Nero

!-->[Hidden] C:\Program\ahead\Nero BackItUp

!-->[Hidden] C:\Program\ahead\Nero SoundTrax

!-->[Hidden] C:\Program\ahead\Nero StartSmart

!-->[Hidden] C:\Program\ahead\Nero Toolkit

!-->[Hidden] C:\Program\ahead\Nero Wave Editor

!-->[Hidden] C:\Program\ahead\WMPBurn

!-->[Hidden] C:\Program\Alcohol Soft

!-->[Hidden] C:\Program\ArcSoft\PhotoImpression 4\Calendar

!-->[Hidden] C:\Program\ArcSoft\PhotoImpression 4\Fantasy

!-->[Hidden] C:\Program\ArcSoft\PhotoImpression 4\Frames

!-->[Hidden] C:\Program\ArcSoft\PhotoImpression 4\Greeting

!-->[Hidden] C:\Program\ArcSoft\PhotoImpression 4\Registration

!-->[Hidden] C:\Program\ArcSoft\VideoImpression 1.6

!-->[Hidden] C:\Program\Betsson Poker

!-->[Hidden] C:\Program\BitComet

!-->[Hidden] C:\Program\Boilsoft AVI Converter

!-->[Hidden] C:\Program\CanonBJ

!-->[Hidden] C:\Program\D-Tools

!-->[Hidden] C:\Program\DC++\Certificates

!-->[Hidden] C:\Program\Delade filer\Adobe\TypeSpt\Unicode

!-->[Hidden] C:\Program\Delade filer\Ahead

!-->[Hidden] C:\Program\Delade filer\DirectX

!-->[Hidden] C:\Program\Delade filer\InstallShield\Professional\RunTime\09

!-->[Hidden] C:\Program\Delade filer\IviSDK

!-->[Hidden] C:\Program\Delade filer\Microsoft Shared\Ink

!-->[Hidden] C:\Program\Delade filer\Microsoft Shared\SpeechEngines

!-->[Hidden] C:\Program\Delade filer\Nokia

!-->[Hidden] C:\Program\Delade filer\Symantec Shared\EENGINE

!-->[Hidden] C:\Program\Delade filer\Symantec Shared\VirusDefs\20061230.018

!-->[Hidden] C:\Program\Delade filer\Symantec Shared\VirusDefs\tmp1e0f.tmp

!-->[Hidden] C:\Program\Delade filer\Symantec Shared\VirusDefs\tmp2c5f.tmp

!-->[Hidden] C:\Program\Delade filer\Symantec Shared\VirusDefs\tmp300e.tmp

!-->[Hidden] C:\Program\Delade filer\Symantec Shared\VirusDefs\tmp381e.tmp

!-->[Hidden] C:\Program\Delade filer\System\mui

!-->[Hidden] C:\Program\Delade filer\Ulead Systems

!-->[Hidden] C:\Program\DVD Decrypter

!-->[Hidden] C:\Program\DVD Shrink

!-->[Hidden] C:\Program\FreeRIP2

!-->[Hidden] C:\Program\HighMAT CD Writing Wizard

!-->[Hidden] C:\Program\ID3-TagIT

!-->[Hidden] C:\Program\InstallShield Installation Information\{2227E1FA-01F5-483C-AB0E-2A308E900B3D}

!-->[Hidden] C:\Program\InstallShield Installation Information\{448AB2CB-C94A-47DE-80B8-9D7824DEFA57}

!-->[Hidden] C:\Program\InstallShield Installation Information\{AD8E6D29-95EC-494E-8AF5-566E784819A6}

!-->[Hidden] C:\Program\InstallShield Installation Information\{B3A31EEE-7C65-4EE6-BB0D-5549FD2D67B9}

!-->[Hidden] C:\Program\InstallShield Installation Information\{C7D89BBE-D4B3-49E8-B185-7966B5345866}

!-->[Hidden] C:\Program\InstallShield Installation Information\{DEF2E5A3-0317-4822-B930-8B721EB483E4}

!-->[Hidden] C:\Program\InstallShield Installation Information\{F5EDF350-FBEE-40B7-926D-4DA2492BFF06}

!-->[Hidden] C:\Program\Internet Explorer\en-US

!-->[Hidden] C:\Program\Internet Explorer\mui

!-->[Hidden] C:\Program\Java\jre6\lib\zi\Atlantic

!-->[Hidden] C:\Program\Java\jre6\lib\zi\Australia

!-->[Hidden] C:\Program\Java\jre6\lib\zi\Etc

!-->[Hidden] C:\Program\Java\jre6\lib\zi\Europe

!-->[Hidden] C:\Program\Java\jre6\lib\zi\Indian

!-->[Hidden] C:\Program\Java\jre6\lib\zi\Pacific

!-->[Hidden] C:\Program\Java\jre6\lib\zi\SystemV

!-->[Hidden] C:\Program\Lavasoft

!-->[Hidden] C:\Program\MIKSOFT

!-->[Hidden] C:\Program\Movie Maker\shared

!-->[Hidden] C:\Program\Mozilla Firefox

!-->[Hidden] C:\Program\MSXML 4.0

!-->[Hidden] C:\Program\MultiPoker\HandHistory

!-->[Hidden] C:\Program\MultiPoker\Temp

!-->[Hidden] C:\Program\MultiPoker\tmpUpgrade

!-->[Hidden] C:\Program\nanocosmos

!-->[Hidden] C:\Program\No-IP

!-->[Hidden] C:\Program\Opera

!-->[Hidden] C:\Program\Origin

!-->[Hidden] C:\Program\PacificPoker

!-->[Hidden] C:\Program\PartyGaming\PartyCasino\Images\games

!-->[Hidden] C:\Program\PartyGaming\PartyCasino\Language\en_US\articles

!-->[Hidden] C:\Program\PartyGaming\PartyCasino\Language\en_US\Images\games\roulette\americanroulette

!-->[Hidden] C:\Program\PartyGaming\PartyCasino\Language\en_US\Images\games\roulette\europeanroulette

!-->[Hidden] C:\Program\PartyGaming\PartyCasino\Temp

!-->[Hidden] C:\Program\PartyGaming\PartyPoker\HandHistory

!-->[Hidden] C:\Program\PartyGaming\PartyPoker\Images

!-->[Hidden] C:\Program\PartyGaming\PartyPoker\Language

!-->[Hidden] C:\Program\PartyGaming\PartyPoker\tmpUpgrade

!-->[Hidden] C:\Program\Process Explorer

!-->[Hidden] C:\Program\SCi

!-->[Hidden] C:\Program\Simpli Software

!-->[Hidden] C:\Program\Sports Interactive

!-->[Hidden] C:\Program\TMPGEnc-2.00.29.113

!-->[Hidden] C:\Program\Ulead Systems

!-->[Hidden] C:\Program\UltraIso

!-->[Hidden] C:\Program\Uninstall Information\mupdate

!-->[Hidden] C:\Program\vtplus

!-->[Hidden] C:\Program\Winamp\Plugins\avs\Winamp 5 Picks

!-->[Hidden] C:\Program\Winamp\Plugins\DSP_SPS

!-->[Hidden] C:\Program\Winamp\Plugins\Milkdrop

!-->[Hidden] C:\Program\Winamp\Skins\Winamp Modern\xml

!-->[Hidden] C:\Program\Windows Journal Viewer

!-->[Hidden] C:\Program\Windows Media Components

!-->[Hidden] C:\Program\Windows Media Player\Icons

!-->[Hidden] C:\Program\Windows Media Player\Installer

!-->[Hidden] C:\Program\Windows Media Player\sample playlists

!-->[Hidden] C:\Program\WinLemm

!-->[Hidden] C:\Program\WinTV

!-->[Hidden] C:\Program\WinZip

!-->[Hidden] C:\Program\WiViK

!-->[Hidden] C:\Program\WordQ

!-->[Hidden] C:\Program\WS_FTP

!-->[Hidden] C:\Qoobox\BackEnv\AppData.folder.dat

!-->[Hidden] C:\Qoobox\BackEnv\Cache.folder.dat

!-->[Hidden] C:\Qoobox\BackEnv\Cookies.folder.dat

!-->[Hidden] C:\Qoobox\BackEnv\Desktop.folder.dat

!-->[Hidden] C:\Qoobox\BackEnv\Favorites.folder.dat

!-->[Hidden] C:\Qoobox\BackEnv\History.folder.dat

!-->[Hidden] C:\Qoobox\BackEnv\LocalAppData.folder.dat

!-->[Hidden] C:\Qoobox\BackEnv\LocalSettings.folder.dat

!-->[Hidden] C:\Qoobox\BackEnv\Music.folder.dat

!-->[Hidden] C:\Qoobox\BackEnv\NetHood.folder.dat

!-->[Hidden] C:\Qoobox\BackEnv\Personal.folder.dat

!-->[Hidden] C:\Qoobox\BackEnv\Pictures.folder.dat

!-->[Hidden] C:\Qoobox\BackEnv\PrintHood.folder.dat

!-->[Hidden] C:\Qoobox\BackEnv\Profiles.Folder.dat

!-->[Hidden] C:\Qoobox\BackEnv\Profiles.Folder.folder.dat

!-->[Hidden] C:\Qoobox\BackEnv\Programs.folder.dat

!-->[Hidden] C:\Qoobox\BackEnv\Recent.folder.dat

!-->[Hidden] C:\Qoobox\BackEnv\SendTo.folder.dat

!-->[Hidden] C:\Qoobox\BackEnv\SetPath.bat

!-->[Hidden] C:\Qoobox\BackEnv\StartMenu.folder.dat

!-->[Hidden] C:\Qoobox\BackEnv\StartUp.folder.dat

!-->[Hidden] C:\Qoobox\BackEnv\SysPath.dat

!-->[Hidden] C:\Qoobox\BackEnv\Templates.folder.dat

!-->[Hidden] C:\Qoobox\BackEnv\VikPev00

!-->[Hidden] C:\WINDOWS\$hf_mig$

!-->[Hidden] C:\WINDOWS\$MSI31Uninstall_KB893803v2$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB810217$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB817778$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB828028$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB828741$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB834707$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB835732$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB837001$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB839643$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB839645$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB840315$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB840374$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB841873$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB842773$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB867282$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB873333$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB883939$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB885250$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB885884$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB887472$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB887742$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB888113$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB888302$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB890046$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB890047$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB890175$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB891781$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB893066$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB896358$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB896422$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB896424$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB896428$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB900485$\spuninst

!-->[Hidden] C:\WINDOWS\$NtUninstallKB911564$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB911565$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB911927$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB913446$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB913580$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB914388$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB916595$\spuninst

!-->[Hidden] C:\WINDOWS\$NtUninstallKB917159$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB920213$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB922760$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB923689$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB923694$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB923980$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB924270$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB925398_WMP64$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB925454$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB925486$\spuninst

!-->[Hidden] C:\WINDOWS\$NtUninstallKB925902$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB926255$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB927891$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB929338$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB930178$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB930916$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB931261$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB931768$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB931784$

!-->[Hidden] C:\WINDOWS\$NtUninstallKB932168$

!-->[Hidden] C:\WINDOWS\assembly

!-->[Hidden] C:\WINDOWS\Debug\WPD

!-->[Hidden] C:\WINDOWS\Downloaded Installations

!-->[Hidden] C:\WINDOWS\Help\starter

!-->[Hidden] C:\WINDOWS\ime\imjp8_1\DICTS

!-->[Hidden] C:\WINDOWS\inf\IEM

!-->[Hidden] C:\WINDOWS\Installer\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}

!-->[Hidden] C:\WINDOWS\Installer\{3DED3A72-61A8-4B87-98A5-EF0BC8038AA0}

!-->[Hidden] C:\WINDOWS\Installer\{43DCF766-6838-4F9A-8C91-D92DA586DFA7}

!-->[Hidden] C:\WINDOWS\Installer\{5B275A18-B96B-42D7-B7D3-76045F91C7BD}

!-->[Hidden] C:\WINDOWS\Installer\{992A2DB1-4ABC-4738-BD71-045C5FFE00D1}

!-->[Hidden] C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A70500000002}

!-->[Hidden] C:\WINDOWS\Installer\{AC76BA86-7AD7-5464-3428-7050000000A7}

!-->[Hidden] C:\WINDOWS\Installer\{BCA3BC04-FC30-11D3-ABF1-00105AC9C13A}

!-->[Hidden] C:\WINDOWS\Installer\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}

!-->[Hidden] C:\WINDOWS\Installer\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}

!-->[Hidden] C:\WINDOWS\Installer\{EB489F13-5AA1-450D-8E8E-44D6B55A5574}

!-->[Hidden] C:\WINDOWS\Microsoft.NET

!-->[Hidden] C:\WINDOWS\Minidump

!-->[Hidden] C:\WINDOWS\msdownld.tmp

!-->[Hidden] C:\WINDOWS\PeerNet

!-->[Hidden] C:\WINDOWS\provisioning

!-->[Hidden] C:\WINDOWS\pss

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{077ACEC7-979C-40AB-9835-435BA1511E0D}

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{077ACEC7-979C-40AB-9835-435BA1511E0D}$BACKUP$

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{3695EB93-6443-448D-8E2E-1F6F4FC79BC1}

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{3FDF25EE-E592-4495-8391-6E9C504DAC2B}

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{3FDF25EE-E592-4495-8391-6E9C504DAC2B}$BACKUP$

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{60204BB3-7078-4F70-8F69-68297621941C}

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{60204BB3-7078-4F70-8F69-68297621941C}$BACKUP$

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{89FDAB62-6F46-4C7E-A559-E00B9A0BACB6}

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}$BACKUP$

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}$BACKUP$

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{CAC24AF7-5447-4F19-9FA6-F6E6E69D395E}

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{CFB4B314-0328-45E1-94AF-45A3F5F48E0B}

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{CFB4B314-0328-45E1-94AF-45A3F5F48E0B}$BACKUP$

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}

!-->[Hidden] C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$

!-->[Hidden] C:\WINDOWS\SoftwareDistribution\Download\1a6bce64b16baa84a1f1ff78a35ed237

!-->[Hidden] C:\WINDOWS\SoftwareDistribution\WebSetup

!-->[Hidden] C:\WINDOWS\SoftwareDistribution\WuRedir

!-->[Hidden] C:\WINDOWS\speech

!-->[Hidden] C:\WINDOWS\srchasst\mui\041e

!-->[Hidden] C:\WINDOWS\system32\bits

!-->[Hidden] C:\WINDOWS\system32\CanonIJ Uninstaller Information

!-->[Hidden] C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache

!-->[Hidden] C:\WINDOWS\system32\LogFiles

!-->[Hidden] C:\WINDOWS\system32\Macromed\Common

!-->[Hidden] C:\WINDOWS\system32\Macromed\Director

!-->[Hidden] C:\WINDOWS\system32\Macromed\Shockwave 10

!-->[Hidden] C:\WINDOWS\system32\Macromed\update

!-->[Hidden] C:\WINDOWS\system32\mui\0409

!-->[Hidden] C:\WINDOWS\system32\mui\041D

!-->[Hidden] C:\WINDOWS\system32\mui\041e

!-->[Hidden] C:\WINDOWS\system32\oobe\mui

!-->[Hidden] C:\WINDOWS\system32\ReinstallBackups\0007

!-->[Hidden] C:\WINDOWS\system32\ReinstallBackups\0010

!-->[Hidden] C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.0.6000.374

!-->[Hidden] C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll

!-->[Hidden] C:\WINDOWS\system32\spool\drivers\w32x86\canonmp600718e

!-->[Hidden] C:\WINDOWS\system32\URTTemp

!-->[Hidden] C:\WINDOWS\system32\windows media

!-->[Hidden] C:\WINDOWS\twain_32\MP600

!-->[Hidden] C:\WINDOWS\WBEM

!-->[Hidden] C:\WINDOWS\WinSxS\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8

!-->[Hidden] C:\WINDOWS\WinSxS\Policies\x86_policy.5.1.Microsoft.Windows.SystemCompatible_6595b64144ccf1df_x-ww_a0111510

!-->[Hidden] C:\WINDOWS\WinSxS\Policies\x86_policy.5.2.Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_x-ww_362e60dd

!-->[Hidden] C:\WINDOWS\WinSxS\Policies\x86_policy.5.2.Microsoft.Windows.Networking.Rtcdll_6595b64144ccf1df_x-ww_c7b7206f

!-->[Hidden] C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a

!-->[Hidden] C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.1.0.0_x-ww_b319d8da

!-->[Hidden] C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213

!-->[Hidden] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.1515_x-ww_7bb98b8a

!-->[Hidden] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9

!-->[Hidden] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.2180_x-ww_b2505ed9

!-->[Hidden] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82

!-->[Hidden] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7

!-->[Hidden] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95

!-->[Hidden] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_sv_7e5e60c6

!-->[Hidden] F:\debug

!-->[Hidden] F:\Documents and Settings\Administratör

!-->[Hidden] F:\Documents and Settings\All Users.WINDOWS.0

!-->[Hidden] F:\Documents and Settings\Besökare\Application Data\Adobe\Flash Player\AssetCache

!-->[Hidden] F:\Documents and Settings\Besökare\Application Data\Macromedia\Flash Player\#SharedObjects\CKQBMHYW\cdn5.specificclick.net

!-->[Hidden] F:\Documents and Settings\Besökare\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com

!-->[Hidden] F:\Documents and Settings\Besökare\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#cdn5.specificclick.net

!-->[Hidden] F:\Documents and Settings\Besökare\Application Data\Microsoft\AddIns

!-->[Hidden] F:\Documents and Settings\Besökare\Application Data\Microsoft\Network

!-->[Hidden] F:\Documents and Settings\Besökare\Application Data\Microsoft\Office

!-->[Hidden] F:\Documents and Settings\Besökare\Application Data\Microsoft\Proof

!-->[Hidden] F:\Documents and Settings\Besökare\Application Data\Microsoft\Templates

!-->[Hidden] F:\Documents and Settings\Besökare\Application Data\Microsoft\Word

!-->[Hidden] F:\Documents and Settings\Besökare\Application Data\Personal

!-->[Hidden] F:\Documents and Settings\Besökare\Favoriter\Microsoft-webbplatser

!-->[Hidden] F:\Documents and Settings\Besökare\Lokala inställningar\Application Data\Microsoft\Feeds

!-->[Hidden] F:\Documents and Settings\Besökare\Lokala inställningar\Application Data\Scansoft

!-->[Hidden] F:\Documents and Settings\Besökare\Mina dokument\Mina bilder\IMHKABDC

!-->[Hidden] F:\Documents and Settings\Besökare\UserData

!-->[Hidden] F:\Documents and Settings\Default User.WINDOWS.0

!-->[Hidden] F:\Documents and Settings\Gäst\Application Data

!-->[Hidden] F:\Documents and Settings\Gäst\Cookies

!-->[Hidden] F:\Documents and Settings\Gäst\Favoriter

!-->[Hidden] F:\Documents and Settings\Gäst\Lokala inställningar

!-->[Hidden] F:\Documents and Settings\Gäst\Mallar

!-->[Hidden] F:\Documents and Settings\Gäst\Mina dokument

!-->[Hidden] F:\Documents and Settings\Gäst\Nätverket

!-->[Hidden] F:\Documents and Settings\Gäst\Recent

!-->[Hidden] F:\Documents and Settings\Gäst\SendTo

!-->[Hidden] F:\Documents and Settings\Gäst\Skrivare

!-->[Hidden] F:\Documents and Settings\Gäst\Skrivbord

!-->[Hidden] F:\Documents and Settings\Gäst\Start-meny\Program\Autostart

!-->[Hidden] F:\Documents and Settings\Gäst\Start-meny\Program\Tillbehör\Hjälpmedel

!-->[Hidden] F:\Documents and Settings\Gäst\Start-meny\Program\Tillbehör\Underhållning

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Adobe\Flash Player

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Ahead

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\ArcSoft

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Macromedia\Flash Player\#SharedObjects\8HQNLWEX\bannerfarm.ace.advertising.com

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Macromedia\Flash Player\#SharedObjects\8HQNLWEX\hstse.tradedoubler.com

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Macromedia\Flash Player\#SharedObjects\8HQNLWEX\ia.media-imdb.com

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Macromedia\Flash Player\#SharedObjects\8HQNLWEX\s.ytimg.com

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Macromedia\Flash Player\#SharedObjects\8HQNLWEX\track.adform.net\Banners

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Macromedia\Flash Player\#SharedObjects\8HQNLWEX\www.blocket.se

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bannerfarm.ace.advertising.com

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#hstse.tradedoubler.com

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#ia.media-imdb.com

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#pixmania.com

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#s.ytimg.com

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#slide.com

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#track.adform.net

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.blocket.se

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.nordea.se

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Macromedia\Shockwave Player

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Microsoft\CryptnetUrlCache

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Microsoft\SystemCertificates\My\Keys

!-->[Hidden] F:\Documents and Settings\Hanna\Application Data\Personal

!-->[Hidden] F:\Documents and Settings\Hanna\Favoriter\Egna sidor

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\0V4OU9IM

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\0X75P5ZF

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\1PWHBV9G

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\3KZM1JE4

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\46AASWIU

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\4GREQQ8H

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\55NJ91QU

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\6PWQ3R08

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\7C1Y8HSU

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\7Z2KDZTU

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\8IKV0JWA

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\9Y2FCJW3

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\A3FHUBT1

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\CCIU8ZTJ

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\E21DP8KI

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\F7P0S7Y7

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\FIY4FLD7

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\GFBYBUUR

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\IZXX2P5V

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\K6COJ5I8

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\MCFKHFTM

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\OSLJVNYR

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\S4YMX844

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\STBE0USN

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\Y4H7NKGI

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\Y53EOJHT

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temporary Internet Files\Content.IE5\ZS7HA28I

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temp\bye30.tmp

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temp\bye36.tmp

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temp\fcctemp

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temp\isp34.tmp

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temp\iss33.tmp

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temp\iss39.tmp

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Temp\ScanSoft

!-->[Hidden] F:\Documents and Settings\Hanna\Lokala inställningar\Tidigare\History.IE5\MSHist012010050320100510

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\bilder

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\bitpim

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\FirstClass

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Hemsida

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Hemsida, design

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Mina bilder\2009_02_25

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Mina bilder\Banshees Kattunge

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Mina bilder\Bengalhane, Solo

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Mina bilder\Jag

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Mina bilder\Jul2008

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Mina bilder\Mantissa april2007

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Mina bilder\MP Navigator\2009_01_21

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Mina bilder\MP Navigator\2010_03_17

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Mina bilder\MP Navigator\Save_20090121

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Mina bilder\mulor och mulåsnor\Rosinante och Ia

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Mina bilder\Råttorna

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Mina bilder\Stöde 2009\Utställningen i stöde

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Mina bilder\Stöde2009

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Mina bilder\Vilda djur

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Mina bilder\Åsnor\Almanacksbilder\Liggande

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Mina bilder\Åsnor\Almanacksbilder\Stående

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Mina bilder\Åsnor\Harley

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Mina bilder\Åsnor\Rådsparkens åsnor

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\My Albums

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Namn

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Texter

!-->[Hidden] F:\Documents and Settings\Hanna\Mina dokument\Åsnehemsida

!-->[Hidden] F:\Documents and Settings\LocalService.NT INSTANS

!-->[Hidden] F:\Documents and Settings\LocalService.NT INSTANS.000

!-->[Hidden] F:\Documents and Settings\LocalService.NT INSTANS.001

!-->[Hidden] F:\Documents and Settings\LocalService.NT INSTANS.002

!-->[Hidden] F:\Documents and Settings\NetworkService.NT INSTANS.000

!-->[Hidden] F:\Documents and Settings\NetworkService.NT INSTANS.001

!-->[Hidden] F:\Documents and Settings\NetworkService.NT INSTANS.002

!-->[Hidden] F:\Documents and Settings\NetworkService.NT INSTANS\Application Data\Microsoft\Credentials

!-->[Hidden] F:\Documents and Settings\NetworkService.NT INSTANS\Application Data\Microsoft\Internet Explorer

!-->[Hidden] F:\Documents and Settings\NetworkService.NT INSTANS\Lokala inställningar\Application Data

!-->[Hidden] F:\Documents and Settings\NetworkService.NT INSTANS\Lokala inställningar\Temp

!-->[Hidden] F:\Documents and Settings\NetworkService.NT INSTANS\Lokala inställningar\Temporary Internet Files\Content.IE5\012Z0163

!-->[Hidden] F:\Documents and Settings\NetworkService.NT INSTANS\Lokala inställningar\Temporary Internet Files\Content.IE5\D6S4IVWY

!-->[Hidden] F:\Documents and Settings\NetworkService.NT INSTANS\Lokala inställningar\Temporary Internet Files\Content.IE5\KJ6HGXM1

!-->[Hidden] F:\Documents and Settings\NetworkService.NT INSTANS\Lokala inställningar\Temporary Internet Files\Content.IE5\O9IV0TYV

!-->[Hidden] F:\drivers

!-->[Hidden] F:\NVIDIA

!-->[Hidden] F:\Program\Adobe\Acrobat 5.0\Help\SVE

!-->[Hidden] F:\Program\Adobe\Acrobat 5.0\Reader\plug_ins\Annotations

!-->[Hidden] F:\Program\Adobe\Acrobat 5.0\Reader\plug_ins\ImageViewer

!-->[Hidden] F:\Program\Adobe\Acrobat 5.0\Reader\plug_ins\vdkhome

!-->[Hidden] F:\Program\Adobe\Acrobat 5.0\Reader\Upphovsrätt

!-->[Hidden] F:\Program\Adobe\Acrobat 5.0\Resource\CIDFont

!-->[Hidden] F:\Program\Axesstel

!-->[Hidden] F:\Program\Bethesda Softworks\Morrowind\Data Files\Sound\Cr\wolf

!-->[Hidden] F:\Program\Bethesda Softworks\Morrowind\Data Files\Sound\Cr\wosk

!-->[Hidden] F:\Program\Bethesda Softworks\Morrowind\Data Files\Sound\Vo\d

!-->[Hidden] F:\Program\Bethesda Softworks\Morrowind\Data Files\Sound\Vo\i

!-->[Hidden] F:\Program\Bethesda Softworks\Morrowind\Data Files\Sound\Vo\k

!-->[Hidden] F:\Program\Bethesda Softworks\Morrowind\Data Files\Sound\Vo\Misc

!-->[Hidden] F:\Program\Bethesda Softworks\Morrowind\Data Files\Sound\Vo\n

!-->[Hidden] F:\Program\Bethesda Softworks\Morrowind\Data Files\Sound\Vo\ww

!-->[Hidden] F:\Program\Bethesda Softworks\Morrowind\Data Files\Video

!-->[Hidden] F:\Program\Bethesda Softworks\Morrowind\Saves

!-->[Hidden] F:\Program\Bethesda Softworks\Oblivion\Data

!-->[Hidden] F:\Program\Bethesda Softworks\Oblivion\Saves

!-->[Hidden] F:\Program\BitPim

!-->[Hidden] F:\Program\Delade filer\InstallShield\Professional\RunTime\09

!-->[Hidden] F:\Program\Delade filer\Roxio Shared

!-->[Hidden] F:\Program\Delade filer\SWF Studio

!-->[Hidden] F:\Program\Delade filer\Symantec Shared\SPManifests

!-->[Hidden] F:\Program\Delade filer\Symantec Shared\SymcData\idsdefs\20051122.048

!-->[Hidden] F:\Program\Delade filer\System\mui

!-->[Hidden] F:\Program\directx

!-->[Hidden] F:\Program\Hyperlinker

!-->[Hidden] F:\Program\InstallShield Installation Information\{B52D7A21-03E5-4C0C-82FA-FD8EB4C92149}

!-->[Hidden] F:\Program\Internet Explorer\mui

!-->[Hidden] F:\Program\Internet Explorer\Quarantine

!-->[Hidden] F:\Program\Internet Explorer\sv-se

!-->[Hidden] F:\Program\Microsoft Office\Templates\Formgivningsmallar 97

!-->[Hidden] F:\Program\Movie Maker\shared

!-->[Hidden] F:\Program\Personal

!-->[Hidden] F:\Program\Roxio

!-->[Hidden] F:\Program\Spybot - Search & Destroy

!-->[Hidden] F:\Program\TGTSoft\StyleXP\Icons\Current.Eva

!-->[Hidden] F:\Program\themexp

!-->[Hidden] F:\Program\Windows Media Player\Icons

!-->[Hidden] F:\Program\Windows Media Player\sample playlists

!-->[Hidden] F:\RECYCLER\S-1-5-21-1409082233-1004336348-725345543-1004\Dg3

!-->[Hidden] F:\RECYCLER\S-1-5-21-1409082233-1004336348-725345543-1004\Dg4

!-->[Hidden] F:\System Volume Information\_restore{D9E916F6-40C9-42EB-ACAB-6E0C6DCD4AF5}\RP828\snapshot

!-->[Hidden] F:\System Volume Information\_restore{D9E916F6-40C9-42EB-ACAB-6E0C6DCD4AF5}\RP829

!-->[Hidden] F:\System Volume Information\_restore{D9E916F6-40C9-42EB-ACAB-6E0C6DCD4AF5}\RP830

!-->[Hidden] F:\System Volume Information\_restore{D9E916F6-40C9-42EB-ACAB-6E0C6DCD4AF5}\RP831

!-->[Hidden] F:\System Volume Information\_restore{D9E916F6-40C9-42EB-ACAB-6E0C6DCD4AF5}\RP832

!-->[Hidden] F:\System Volume Information\_restore{D9E916F6-40C9-42EB-ACAB-6E0C6DCD4AF5}\RP833

!-->[Hidden] F:\System Volume Information\_restore{D9E916F6-40C9-42EB-ACAB-6E0C6DCD4AF5}\RP834\snapshot\Repository

!-->[Hidden] F:\System Volume Information\_restore{D9E916F6-40C9-42EB-ACAB-6E0C6DCD4AF5}\RP835\snapshot

!-->[Hidden] F:\System Volume Information\_restore{D9E916F6-40C9-42EB-ACAB-6E0C6DCD4AF5}\RP841\snapshot\Repository

!-->[Hidden] F:\System Volume Information\_restore{D9E916F6-40C9-42EB-ACAB-6E0C6DCD4AF5}\RP842

!-->[Hidden] F:\System Volume Information\_restore{D9E916F6-40C9-42EB-ACAB-6E0C6DCD4AF5}\RP843

!-->[Hidden] F:\System Volume Information\_restore{D9E916F6-40C9-42EB-ACAB-6E0C6DCD4AF5}\RP845\snapshot\Repository

!-->[Hidden] F:\System Volume Information\_restore{D9E916F6-40C9-42EB-ACAB-6E0C6DCD4AF5}\RP846\snapshot

!-->[Hidden] F:\System Volume Information\_restore{D9E916F6-40C9-42EB-ACAB-6E0C6DCD4AF5}\RP848\snapshot\Repository

!-->[Hidden] F:\System Volume Information\_restore{D9E916F6-40C9-42EB-ACAB-6E0C6DCD4AF5}\RP854\snapshot

!-->[Hidden] F:\System Volume Information\_restore{D9E916F6-40C9-42EB-ACAB-6E0C6DCD4AF5}\RP857

!-->[Hidden] F:\System Volume Information\_restore{D9E916F6-40C9-42EB-ACAB-6E0C6DCD4AF5}\RP858

!-->[Hidden] F:\System Volume Information\_restore{D9E916F6-40C9-42EB-ACAB-6E0C6DCD4AF5}\RP859

!-->[Hidden] F:\System Volume Information\_restore{D9E916F6-40C9-42EB-ACAB-6E0C6DCD4AF5}\RP860

!-->[Hidden] F:\System Volume Information\_restore{D9E916F6-40C9-42EB-ACAB-6E0C6DCD4AF5}\RP861\snapshot\Repository

!-->[Hidden] F:\WINDOWS.0

==============================================

>Hooks

==============================================

ntoskrnl.exe+0x00004AA2, Type: Inline - RelativeJump 0x804DBAA2-->804DBAA9 [ntoskrnl.exe]

[1016]svchost.exe-->ntdll.dll-->NtQueryInformationProcess, Type: Inline - RelativeJump 0x7C90E01B-->00000000 [unknown_code_page]

[916]svchost.exe-->ntdll.dll-->NtQueryInformationProcess, Type: Inline - RelativeJump 0x7C90E01B-->00000000 [unknown_code_page]

 

 

!!POSSIBLE ROOTKIT ACTIVITY DETECTED!! =)

 

 

Länk till kommentar
Dela på andra webbplatser

Om du inte förstår något jag skriver så fråga på :)

 

Har du, eller någon annan användare av datorn, själv ändrat så att det är en massa mappar som är markerade som dolda (hiden)?

 

Har du kollat om filen C:\mbr.log har skapats när du har försökt köra mbr.exe enligt anvisningarna?

Länk till kommentar
Dela på andra webbplatser

Nej någon mbr.log fil kan jag inte hitta.

 

Jag har inte ändrat något på datan med flit i alla fall. Men då jag bytte till denna dator i sommras så flyttade vi över en av hårddiskarna ifrån min gamla dator där jag hade det mesta sparat till den nya (F). Vi hade då lite problem i början eftersom min förra dator var lösenordsskyddad. Jag kommer inte ihåg hur vi (eller de som hjälpte mig, jag tittade mest på) kom runt problemet, men det hade något att göra med att byta administrator eller något sånt. Kanske filerna från den hårddisken visas som dolda?

Länk till kommentar
Dela på andra webbplatser

Det är mycket på F: som är dolt, men även sådant som mappen C:\Program\BitComet.

 

Ladda ner mbr.exe till Skrivbordet:

http://www2.gmer.net/mbr/mbr.exe

 

Dra ur internetanslutningen och inaktivera/stäng av antivirus- och andra säkerhetsprogram.

 

Start - Alla program - Tillbehör - Kommandotolken

Skriv in:

 

%userprofile%\skrivbord\mbr.exe" -tDFR -s > "C:\mbr.log"

 

Programmet går rätt fort. Om du får något felmeddelande så skriv in det i ditt svar.

Klistra in innehållet i mbr.log som skapas i C:\.

Länk till kommentar
Dela på andra webbplatser

BitComet kommer upp nästan varje gång jag ska ladda ner något. Det är där jag ser prossessen. Men det kanske är ett onödigt program ändå, jag kan ju trots allt ladda ner filer även utan BitComet, men det är den datorn oftast väljer att använda

 

Jag får inte mbr.exe att fungera. Jag kan ha gjort något fel, jag har aldrig överhuvudtaget ens öppnat kommandotolken förut. Det står i alla fall: C:\Documents är inte ett internt kommando, externt kommando, program eller kommandofil

 

när jag skriver in %userprofile%\skrivbord\mbr.exe" -tDFR -s > "C:\mbr.log" och trycker på "enter"

 

 

 

Länk till kommentar
Dela på andra webbplatser

Förlåt, nu saknades det en ". Så här ska det vara (hoppas jag):

 

"%userprofile%\skrivbord\mbr.exe" -tDFR -s > "C:\mbr.log"

Länk till kommentar
Dela på andra webbplatser

Jag vet inte om det fungerade eller ej. Jag fick inget felmeddelande denna gång. Det liksom blinkade till och sen kom det upp en ny "kommandorad"

Länk till kommentar
Dela på andra webbplatser

Ja det gjorde det faktiskt (nu blev jag förvånad att det fungerade!)

 

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net

Windows 5.1.2600 Disk: IC35L120AVVA07-0 rev.VA6OA51A -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4

 

device: opened successfully

user: MBR read successfully

 

Disk trace:

called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys

1 nt!IofCallDriver[0x804E37C5] -> \Device\Harddisk0\DR0[0x8A454AB8]

3 CLASSPNP[0xF763805B] -> nt!IofCallDriver[0x804E37C5] -> \Device\Ide\IdeDeviceP0T0L0-4[0x8A3EFD98]

kernel: MBR read successfully

_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [bP+0x0], CH; JL 0x2e; JNZ 0x3a; }

user & kernel MBR OK

 

Filesystem trace:

called modules: ntoskrnl.exe hal.dll fltmgr.sys eeCtrl.sys sr.sys Ntfs.sys

C:\Program\Delade filer\Symantec Shared\EENGINE\eeCtrl.sys Symantec Corporation ERASER ENGINE

1 nt!IofCallDriver[0x804E37C5] -> [0x89C3B020]

3 fltmgr[0xF746CE95] -> nt!IofCallDriver[0x804E37C5] -> [0x8A40ADD0]

5 sr[0xF745C870] -> nt!IofCallDriver[0x804E37C5] -> [0x8A4028A8]

7 fltmgr[0xF74793B1] -> nt!IofCallDriver[0x804E37C5] -> [0x8A44F770]

9 nt[0x8056A143] -> nt!IofCallDriver[0x804E37C5] -> [0x89C3B020]

11 fltmgr[0xF746D098] -> nt!IofCallDriver[0x804E37C5] -> [0x8A40ADD0]

13 sr[0xF7457453] -> nt!IofCallDriver[0x804E37C5] -> [0x8A4028A8]

15 fltmgr[0xF746D098] -> nt!IofCallDriver[0x804E37C5] -> [0x8A44F770]

 

Registry trace:

called modules: ntoskrnl.exe hal.dll

 

 

 

Länk till kommentar
Dela på andra webbplatser

Nu har det ju gått några dagar igen. Ta bort den ComboFix du har och ladda ner den senaste versionen. Kör den utan någon CFScript.

Länk till kommentar
Dela på andra webbplatser

Jag glömde stänga av brandväggen denna gång, är det ett problem?

 

ComboFix 10-12-28.03 - Mikael Pettersson 2010-12-29 20:57:08.10.1 - x86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.46.1053.18.1535.1179 [GMT 1:00]

Körs från: c:\documents and settings\Mikael Pettersson\Skrivbord\ComboFix.exe

* Skapade en ny återställningspunkt

.

 

(((((((((((((((((((((((( Filer Skapade från 2010-11-28 till 2010-12-29 ))))))))))))))))))))))))))))))

.

 

2010-12-22 18:44 . 2010-12-22 18:44 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\ArcSoft

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-11-12 17:53 . 2010-08-22 12:34 472808 ----a-w- c:\windows\system32\deployJava1.dll

2010-11-12 15:34 . 2007-05-12 15:02 73728 ----a-w- c:\windows\system32\javacpl.cpl

.

 

((((((((((((((((((((((((((((( SnapShot@2010-12-15_17.59.05 )))))))))))))))))))))))))))))))))))))))))

.

+ 2010-12-29 18:23 . 2010-12-29 18:23 16384 c:\windows\temp\Perflib_Perfdata_6f8.dat

+ 2005-05-26 02:16 . 2009-08-06 17:24 44768 c:\windows\system32\wups2.dll

+ 2004-08-12 10:07 . 2009-08-06 17:24 35552 c:\windows\system32\wups.dll

+ 2004-08-12 10:07 . 2009-08-06 17:24 35552 c:\windows\system32\dllcache\wups.dll

+ 2002-01-30 13:49 . 2004-08-04 05:59 95360 c:\windows\system32\dllcache\atapi.sys

+ 2010-12-18 19:20 . 2010-11-12 17:53 157472 c:\windows\system32\javaws.exe

+ 2010-12-18 19:27 . 2010-11-12 17:53 145184 c:\windows\system32\javaw.exe

- 2010-08-22 12:34 . 2010-08-22 12:34 145184 c:\windows\system32\javaw.exe

+ 2010-12-18 19:27 . 2010-11-12 17:53 145184 c:\windows\system32\java.exe

- 2010-08-22 12:34 . 2010-08-22 12:34 145184 c:\windows\system32\java.exe

+ 2010-12-18 19:20 . 2010-12-18 19:20 180224 c:\windows\Installer\fd58ba.msi

.

(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Not* Tomma poster & legitima standardposter visas inte.

REGEDIT4

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"diagent"="c:\program\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 135264]

"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]

"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-12-07 196608]

"QuickTime Task"="c:\program\QuickTime\qttask.exe" [2005-09-17 98304]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"SRUUninstall"="c:\windows\system32\msiexec.exe" [2005-03-21 78848]

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start-meny^Program^Autostart^Adobe Gamma Loader.lnk]

path=c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Autostart\Adobe Gamma Loader.lnk

backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start-meny^Program^Autostart^Adobe Reader Speed Launch.lnk]

path=c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Autostart\Adobe Reader Speed Launch.lnk

backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start-meny^Program^Autostart^Microsoft Office.lnk]

path=c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Autostart\Microsoft Office.lnk

backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start-meny^Program^Autostart^SmartTrust CSP Certificate Utility.lnk]

path=c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Autostart\SmartTrust CSP Certificate Utility.lnk

backup=c:\windows\pss\SmartTrust CSP Certificate Utility.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start-meny^Program^Autostart^WordQCRS.lnk]

path=c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Autostart\WordQCRS.lnk

backup=c:\windows\pss\WordQCRS.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^Mikael Pettersson^Start-meny^Program^Autostart^No-IP DUC.lnk]

path=c:\documents and settings\Mikael Pettersson\Start-meny\Program\Autostart\No-IP DUC.lnk

backup=c:\windows\pss\No-IP DUC.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellTouch]

2002-01-16 22:49 163840 ----a-w- c:\windows\MMKeybd.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

2005-09-17 21:28 98304 ----a-w- c:\program\QuickTime\qttask.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegKillElbyCheck]

2002-11-02 06:33 45056 ----a-w- c:\program\Elaborate Bytes\DVD Region Killer\ElbyCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegKillTray]

2002-11-27 21:11 49152 ----a-w- c:\program\Elaborate Bytes\DVD Region Killer\RegKillTray.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tweak UI]

2003-03-25 04:49 106544 ----a-r- c:\windows\system32\tweakui.cpl

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]

2006-03-30 14:45 313472 ----a-w- c:\program\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USIUDF_Eject_Monitor]

2004-05-28 03:50 81920 ------w- c:\program\Delade filer\Ulead Systems\DVD\USISrv.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WordQ carat flag]

2004-02-06 05:00 24576 ----a-w- c:\program\WordQ\WordQcrs.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program\\Messenger\\msmsgs.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"26263:TCP"= 26263:TCP:BitComet 26263 TCP

"26263:UDP"= 26263:UDP:BitComet 26263 UDP

"9777:TCP"= 9777:TCP:qfcgjevx

 

R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [2003-05-07 11264]

R1 ATMhelpr;ATMhelpr;c:\windows\system32\drivers\ATMHELPR.SYS [2003-03-22 4064]

R2 Nhksrv;Netropa NHK Server;c:\windows\Nhksrv.exe [2002-11-12 28672]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program\Delade filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-03-11 109616]

R3 Msikbd2k;DellTouch;c:\windows\system32\drivers\Msikbd2k.sys [2002-11-12 6656]

R3 RegKill;RegKill;c:\windows\system32\drivers\RegKill.sys [2002-11-27 6400]

S0 ElbyVCD;ElbyVCD;c:\windows\system32\DRIVERS\ElbyVCD.sys --> c:\windows\system32\DRIVERS\ElbyVCD.sys [?]

S2 Ca533av;Icatch(IV) Video Camera Device;c:\windows\system32\drivers\Ca533av.sys [2010-06-21 515803]

S2 pnnesyksa;Installer Monitor;c:\windows\system32\svchost.exe -k netsvcs [2002-07-01 14336]

S3 Amps2prt;A4Tech PS/2 Port Mouse Driver;c:\windows\system32\drivers\Amps2prt.sys [2004-01-12 9728]

S3 Axtmvflt;Axesstel USB Filter Service;c:\windows\system32\drivers\Axtmvflt.sys [2010-06-03 3456]

S3 Axtmvmdm;Axesstel USB Modem;c:\windows\system32\drivers\Axtmvmdm.sys [2010-06-03 40064]

S3 Axtmvprt;Axesstel Diagnostic Port;c:\windows\system32\drivers\Axtmvprt.sys [2010-06-03 38784]

S3 QCEmerald;Logitech QuickCam Web;c:\windows\system32\drivers\OVCE.sys [2003-01-17 31872]

S3 TodosScReader;Driver for Todos Argosmini Usb;c:\windows\system32\drivers\amusb.sys [2003-04-23 82464]

S4 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [2005-10-25 160640]

S4 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [2005-10-25 5248]

S4 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [2004-10-25 155136]

S4 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [2004-10-25 5248]

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

pnnesyksa

.

.

------- Extra genomsökning -------

.

uStart Page = hxxp://ccp.crystone.net/

IE: Download all links using BitComet - c:\program\BitComet\BitComet.exe/AddAllLink.htm

IE: Download all videos using BitComet - c:\program\BitComet\BitComet.exe/AddVideo.htm

IE: Download link using &BitComet - c:\program\BitComet\BitComet.exe/AddLink.htm

IE: E&xportera till Microsoft Excel - c:\program\MICROS~2\Office10\EXCEL.EXE/3000

IE: {{641F4F4E-6C91-4159-869E-9F5CE6F0F64E} - c:\program\MultiPoker\MultiPoker.exe

IE: {{B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - c:\program\PartyGaming\PartyCasino\RunCasino.exe

IE: {{EFFF8D47-D060-4108-B761-E8EC86622E56} - c:\documents and settings\All Users.WINDOWS\Start-meny\Program\Absolute Poker\Absolute Poker.lnk

DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-12-29 21:03

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\pnnesyksa]

"ServiceDll"="c:\windows\system32\tehwfq.dll"

.

--------------------- DLLer som "laddats" under processer som körs ---------------------

 

- - - - - - - > 'explorer.exe'(4080)

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

.

Sluttid: 2010-12-29 21:07:25

ComboFix-quarantined-files.txt 2010-12-29 20:07

ComboFix2.txt 2010-12-24 12:20

ComboFix3.txt 2010-12-23 18:44

ComboFix4.txt 2010-12-21 19:19

ComboFix5.txt 2010-12-29 19:52

 

Före genomsökningen: 94 280 843 264 byte ledigt

Efter genomsökningen: 94 303 113 216 byte ledigt

 

- - End Of File - - C727C6C485D7A9F22E0668BD24513F33

 

 

 

Länk till kommentar
Dela på andra webbplatser

Arkiverat

Det här ämnet är nu arkiverat och är stängt för ytterligare svar.

×
×
  • Skapa nytt...