Dette er hvad jeg har fået frem fra Combofix via fejlsikret tilstand:
ComboFix 09-10-30.01 - Julie 31-10-2009 15:45.1.2 - NTFSx86 MINIMAL
Microsoft® Windows Vista™ Business 6.0.6000.0.1252.45.1030.18.1013.657 [GMT 1:00]
Kører fra: E:\BANAN.exe
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-3815228288-3740772556-1963257759-500
c:\$recycle.bin\S-1-5-21-741154993-759284812-1146952621-500
c:\$recycle.bin\S-1-5-21-918056312-2952985149-2686913973-500
c:\programdata\10890523
c:\programdata\10890523\10890523.exe
c:\programdata\21366523
c:\programdata\21366523\21366523.exe
c:\programdata\50083319
c:\programdata\50083319\50083319.exe
c:\users\Julie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Security Tool.lnk
c:\users\Julie\Desktop\Security Tool.lnk
.
((((((((((((((((((((((((((((( Filer skabt fra 2009-09-28 til 2009-10-31 )))))))))))))))))))))))))))))))))))
.
2009-10-31 11:20 . 2009-10-31 11:20 -------- d-----w- c:\windows\LastGood
2009-10-30 19:49 . 2009-10-30 19:49 -------- d-----w- c:\users\Julie\AppData\Roaming\Malwarebytes
2009-10-30 19:48 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-30 19:48 . 2009-10-30 19:48 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-30 19:48 . 2009-10-30 19:48 -------- d-----w- c:\programdata\Malwarebytes
2009-10-30 19:48 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-30 19:41 . 2009-10-30 19:41 -------- d-----w- c:\program files\CCleaner
2009-10-28 12:06 . 2009-09-10 15:29 311296 ----a-w- c:\windows\system32\unregmp2.exe
2009-10-28 12:06 . 2009-09-10 17:40 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-10-28 12:06 . 2009-09-10 17:39 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-10-28 12:06 . 2009-09-10 15:29 8147968 ----a-w- c:\windows\system32\wmploc.DLL
2009-10-25 14:30 . 2009-10-25 14:30 -------- d-----w- c:\users\Julie\AppData\Local\TVU Networks
2009-10-25 14:30 . 2009-10-25 14:30 -------- d-----w- c:\programdata\TVU Networks
2009-10-25 14:29 . 2009-10-25 14:29 -------- d-----w- c:\program files\TVUPlayer
2009-10-16 14:05 . 2009-08-27 13:57 56320 ----a-w- c:\windows\system32\iesetup.dll
2009-10-16 14:05 . 2009-08-27 11:24 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-10-16 14:05 . 2009-08-27 09:51 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-10-16 14:05 . 2009-08-05 14:28 3467864 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-10-16 14:05 . 2009-08-05 14:28 3502152 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-16 14:05 . 2009-09-04 12:38 60928 ----a-w- c:\windows\system32\msasn1.dll
2009-10-16 14:05 . 2009-09-14 09:50 130048 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-10-16 14:05 . 2009-04-02 11:50 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2009-10-03 13:30 . 2009-10-01 09:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-10-03 13:24 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2009-10-03 13:24 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-10-03 13:24 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-10-03 13:24 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-10-03 13:24 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll
2009-10-03 13:24 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-10-03 13:24 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll
2009-10-03 13:23 . 2009-08-06 17:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-10-03 13:23 . 2009-08-06 16:44 33792 ----a-w- c:\windows\system32\wuapp.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-31 11:22 . 2007-02-02 10:39 80288 ----a-w- c:\windows\system32\perfc006.dat
2009-10-31 11:22 . 2007-02-02 10:39 485600 ----a-w- c:\windows\system32\perfh006.dat
2009-10-19 14:42 . 2009-02-08 20:46 -------- d-----w- c:\programdata\CanonIJPLM
2009-10-17 01:20 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-10 17:38 . 2009-10-16 14:06 216576 ----a-w- c:\windows\system32\msv1_0.dll
2009-08-29 03:41 . 2009-09-02 21:33 1686528 ----a-w- c:\windows\system32\gameux.dll
2009-08-29 03:40 . 2009-09-02 21:33 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-28 23:31 . 2009-09-02 21:33 4247552 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-27 14:02 . 2009-10-16 14:06 832512 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 13:57 . 2009-10-16 14:06 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-27 13:56 . 2009-10-16 14:06 72704 ----a-w- c:\windows\system32\admparse.dll
2009-08-14 17:16 . 2009-09-09 16:48 213592 ----a-w- c:\windows\system32\drivers\netio.sys
2009-08-14 16:42 . 2009-09-09 16:48 167424 ----a-w- c:\windows\system32\tcpipcfg.dll
2009-08-14 16:40 . 2009-09-09 16:48 103936 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-14 16:40 . 2009-09-09 16:48 15360 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 14:25 . 2009-09-09 16:48 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:25 . 2009-09-09 16:48 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 14:25 . 2009-09-09 16:48 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 14:25 . 2009-09-09 16:48 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 14:25 . 2009-09-09 16:48 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:25 . 2009-09-09 16:48 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 14:25 . 2009-09-09 16:48 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-14 14:24 . 2009-09-09 16:48 813568 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 14:23 . 2009-09-09 16:48 22016 ----a-w- c:\windows\system32\netiougc.exe
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-09 1232896]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2007-04-11 1006264]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-01 815104]
"LoadFUJ02E3"="c:\program files\Fujitsu\FUJ02E3\FUJ02E3.exe" [2006-11-17 80688]
"IndicatorUtility"="c:\program files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" [2006-11-07 97072]
"LoadFujitsuQuickTouch"="c:\program files\Fujitsu\Application Panel\QuickTouch.exe" [2006-11-26 260912]
"LoadBtnHnd"="c:\program files\Fujitsu\BtnHnd\BtnHnd.exe" [2006-11-12 68400]
"TvOutSwitch"="c:\program files\Fujitsu\DispSwitch\DispSwitchLauncher.exe" [2006-11-17 81920]
"PSUtility"="c:\program files\Fujitsu\PSUtility\TrayManager.exe" [2006-10-30 136744]
"SSUtility"="c:\program files\Fujitsu\SSUtility\FJSSDMN.exe" [2006-11-13 239144]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2005-12-15 188416]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-11 689488]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-18 1848648]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2006-11-20 4018176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
R0 FJGSDisk;G-Sensor Application Filter Driver;c:\windows\System32\drivers\FJGSDisk.sys [11-03-2007 18:52 10368]
R0 O2MDRDR;O2MDRDR;c:\windows\System32\drivers\o2media.sys [12-02-2007 18:07 36640]
R0 O2SDRDR;O2SDRDR;c:\windows\System32\drivers\o2sd.sys [12-02-2007 18:07 33152]
R3 FUJ02E3;Fujitsu FUJ02E3 Device Driver;c:\windows\System32\drivers\fuj02e3.sys [12-02-2007 18:08 5632]
S2 PowerSavingUtilityService;PowerSavingUtilityService;c:\program files\Fujitsu\PSUtility\PSUService.exe [30-10-2006 16:37 63016]
S2 WirelessSelectorService;WirelessSelectorService;c:\program files\Fujitsu\WirelessSelector\WSUService.exe [05-12-2006 00:06 57344]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [02-11-2006 11:25 167936]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\System32\drivers\mbamswissarmy.sys [30-10-2009 20:48 38224]
S3 SMSCIRDA;SMSC Infrared Device Driver;c:\windows\System32\drivers\smscirda.sys [25-04-2007 13:32 31232]
S3 USBAAPL;Apple Mobile USB Driver;c:\windows\System32\drivers\usbaapl.sys [07-11-2008 14:23 32000]
--- Andre Services/Drivers i Hukommelsen ---
*NewlyCreated* - ECACHE
*NewlyCreated* - MBR
*Deregistered* - mbr
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
Indhold af mappen 'Planlagte Opgaver'
2009-10-31 c:\windows\Tasks\User_Feed_Synchronization-{AA4F171B-F090-4B68-AD2D-81FE03516C29}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://tv2.dk/uInternet Settings,ProxyOverride = *.local
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
Trusted Zone: danid.dk
Trusted Zone: danskebank.dk
Trusted Zone: danid.dk
DPF: {1B77DC8B-0BCF-4669-ACA1-EBCAD4524D10} -
hxxps://hairtools.dk/salon/hairtools.cabDPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} -
hxxp://download06.managerzone.com/soccer-3d/PowerLoader.cabDPF: {4F2A3649-7A9F-4950-9C31-409FAC6FC7C8} -
hxxps://danid.dk/csp/authenticode/csp.exeDPF: {D8575CE3-3432-4540-88A9-85A1325D3375} -
hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cabDPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} -
hxxps://plugins.valueactive.eu/flashax/iefax.cab.
- - - - TOMME GENVEJE FJERNET - - - -
HKCU-Run-RiskIISetup.exe - c:\users\Julie\Desktop\RISKII~1.EXE
HKCU-Run-50083319 - c:\programdata\50083319\50083319.exe
HKCU-Run-10890523 - c:\programdata\10890523\10890523.exe
HKCU-Run-21366523 - c:\progra~2\21366523\21366523.exe
HKLM-RunOnce-<NO NAME> - (no file)
AddRemove-Lexmark 4300 Series - c:\program files\Lexmark 4300 Series\Install\x86\Uninst.exe
AddRemove-ScandicBookmakers.com - c:\program files\ScandicBookmakers.com\uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-31 15:51
Windows 6.0.6000 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Gennemført tid: 2009-10-31 15:52
ComboFix-quarantined-files.txt 2009-10-31 14:52
Pre-Kørsel: 8.252.784.640 byte ledig
Post-Kørsel: 7.983.915.008 byte ledig
- - End Of File - - DFD27B8DA800345E23BB0D6784F3A244