så fik jeg vist det hele med :o) .....
ComboFix 10-11-02.06 - Melissa 03-11-2010 22:26:55.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1030.18.1022.654 [GMT 1:00]
Kører fra: c:\documents and settings\Melissa\Skrivebord\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\Melissa\Skrivebord\CFScript.txt
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Forrige Kørsel -------
.
c:\documents and settings\All Users\Dokumenter\Server\admin.txt
c:\documents and settings\All Users\Dokumenter\Server\server.dat
c:\documents and settings\Melissa\Application Data\8F7C6F19DF9055DA7C4FE342751D275F\enemies-names.txt
c:\documents and settings\Melissa\Application Data\8F7C6F19DF9055DA7C4FE342751D275F\local.ini
c:\documents and settings\Melissa\Application Data\8F7C6F19DF9055DA7C4FE342751D275F\lsrslt.ini
c:\documents and settings\Melissa\Application Data\completescan
c:\documents and settings\Melissa\Application Data\install
c:\windows\system32\AutoRun.inf
c:\windows\system32\drivers\ptxmlmce.sys
c:\windows\explorer.exe . . . er inficeret!!
c:\windows\system32\winlogon.exe . . . er inficeret!!
.
\\.\PhysicalDrive0 - Bootkit TDL4 was found and disinfected
.
((((((((((((((((((((((((((((((((((((((( Drivers/Tjenester )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SSHNAS
((((((((((((((((((((((((((((( Filer skabt fra 2010-10-03 til 2010-11-03 )))))))))))))))))))))))))))))))))))
.
2010-11-03 21:19 . 2010-11-03 21:19 -------- d-----w- c:\programmer\Fælles filer\Java
2010-11-03 21:18 . 2010-09-15 03:50 472808 ----a-w- c:\programmer\Mozilla Firefox\plugins\npdeployJava1.dll
2010-11-03 21:18 . 2010-09-15 03:50 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-03 20:16 . 2010-11-03 20:16 -------- d-----w- c:\documents and settings\Melissa\Application Data\AVG10
2010-11-03 20:15 . 2010-11-03 20:15 -------- d--h--w- c:\documents and settings\All Users\Application Data\Common Files
2010-11-03 20:13 . 2010-11-03 21:21 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG10
2010-11-03 20:12 . 2010-11-03 20:12 -------- d-----w- c:\programmer\AVG
2010-10-31 19:27 . 2010-10-31 19:27 -------- d-----w- c:\documents and settings\Melissa\Application Data\PeaZip
2010-10-31 19:27 . 2010-10-31 19:27 -------- d-----w- c:\programmer\PeaZip
2010-10-30 14:22 . 2010-10-30 14:22 -------- d-----w- c:\programmer\CCleaner
2010-10-30 13:48 . 2010-10-30 13:48 -------- d-----w- c:\documents and settings\Melissa\Application Data\Malwarebytes
2010-10-30 13:48 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-30 13:48 . 2010-10-30 13:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-10-30 13:48 . 2010-10-30 13:48 -------- d-----w- c:\programmer\Malwarebytes' Anti-Malware
2010-10-30 13:48 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-30 11:05 . 2010-10-30 11:05 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure
2010-10-30 08:07 . 2010-10-30 08:07 -------- d-----w- c:\documents and settings\Melissa\Application Data\Office Genuine Advantage
2010-10-30 08:04 . 2010-10-30 08:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-10-29 22:27 . 2010-10-29 22:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-10-29 21:29 . 2010-11-03 20:12 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
2010-10-29 18:05 . 2010-10-30 16:19 -------- d-----w- c:\programmer\Spybot - Search & Destroy
2010-10-29 18:05 . 2010-10-30 16:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-10-20 15:56 . 2010-10-20 15:56 -------- d-----r- c:\documents and settings\NetworkService\Foretrukne
2010-10-20 15:06 . 2010-10-20 15:06 0 ----a-w- c:\windows\system32\dlo212.tmp
2010-10-20 15:05 . 2010-10-20 15:05 -------- d-sh--w- c:\documents and settings\Melissa\IECompatCache
2010-10-20 14:42 . 2010-10-20 14:42 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-10-20 08:40 . 2010-10-20 08:40 196 ----a-w- c:\documents and settings\Melissa\Application Data\24679.bat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 10:23 . 2007-04-02 18:14 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2008-04-14 07:05 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2008-04-14 07:05 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-18 06:53 . 2001-10-09 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-15 01:29 . 2009-09-04 15:26 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-09-10 05:51 . 2008-04-14 07:05 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:51 . 2008-04-14 07:06 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-09-10 05:51 . 2008-04-14 07:05 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-01 11:52 . 2008-04-14 07:03 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-09-01 07:57 . 2008-04-14 06:38 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 08:03 . 2008-04-14 07:05 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:53 . 2008-04-14 07:05 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-27 01:43 . 2008-05-05 05:25 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-26 13:39 . 2008-04-13 10:15 357248 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-23 16:12 . 2008-04-14 07:05 617472 ----a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2008-04-14 07:06 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45 . 2008-04-14 07:05 590848 ----a-w- c:\windows\system32\rpcrt4.dll
.
------- Sigcheck -------
- 2008-04-14 . 026612781A4599A2355F8C0DDC44C706 . 507904 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
- 2008-04-14 . 1B926C0405A89FC158B56D52D8D8BA47 . 1034752 . . [6.00.2900.5512] . . c:\windows\explorer.exe
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\programmer\Vuze_Remote\tbVuz1.dll" [2010-09-10 2735200]
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2010-09-10 16:50 2735200 ----a-w- c:\programmer\Vuze_Remote\tbVuz1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\programmer\Vuze_Remote\tbVuz1.dll" [2010-09-10 2735200]
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BA14329E-9550-4989-B3F2-9732E92D17CC}"= "c:\programmer\Vuze_Remote\tbVuz1.dll" [2010-09-10 2735200]
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\programmer\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Creative Live! Cam Manager"="c:\programmer\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe" [2007-06-07 155648]
"Skype"="c:\programmer\Skype\Phone\Skype.exe" [2009-10-09 25623336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-12-04 7340032]
"nwiz"="nwiz.exe" [2005-12-04 1519616]
"NVRotateSysTray"="c:\windows\system32\nvsysrot.dll" [2005-12-04 49152]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-09 15691264]
"QuickTime Task"="c:\programmer\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\programmer\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"Adobe Reader Speed Launcher"="c:\programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"fssui"="c:\programmer\Windows Live\Family Safety\fsui.exe" [2009-08-05 647520]
"SunJavaUpdateSched"="c:\programmer\Fælles filer\Java\Java Update\jusched.exe" [2010-05-14 248552]
"V0400Mon.exe"="c:\windows\V0400Mon.exe" [2007-06-04 32768]
"DivXUpdate"="c:\programmer\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WUAppSetup"="c:\programmer\Fælles filer\logishrd\WUApp32.exe" [2007-02-03 430080]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\Messenger\\msmsgs.exe"=
"c:\\Programmer\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmer\\iTunes\\iTunes.exe"=
"c:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmer\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmer\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmer\\Java\\jre6\\bin\\java.exe"=
"c:\\Programmer\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5950:TCP"= 5950:TCP:spport
"5603:TCP"= 5603:TCP:zpgpl
S2 bsczbyri;USB to IEEE-1284.4 Translation HPZius12Controller;c:\windows\System32\svchost.exe -k netsvcs [14-04-2008 08:06 14336]
S2 pujpuh;System Support;c:\windows\system32\svchost.exe -k netsvcs [14-04-2008 08:06 14336]
S3 ADM8511;ADMtek ADM8511/AN986 USB til Fast Ethernet-converter;c:\windows\system32\drivers\adm8511.sys [09-02-2009 18:31 20160]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\programmer\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [30-01-2009 18:02 23152]
S3 F5D5055;Belkin F5D5055 Gigabit USB 2.0 Network Adapter;c:\windows\system32\drivers\F5D5055.sys [24-06-2009 20:38 30336]
S3 SVRPEDRV;SVRPEDRV;\??\c:\docume~1\N\LOKALE~1\Temp\RarSFX0\S10VWF\PEDrv.sys --> c:\docume~1\N\LOKALE~1\Temp\RarSFX0\S10VWF\PEDrv.sys [?]
S3 USBAAPL;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl.sys [29-09-2008 17:44 32000]
S3 VF0400Afx;VF0400 Audio FX;c:\windows\system32\drivers\V0400Afx.sys [08-02-2010 17:02 142656]
S3 VF0400Vfx;VF0400 Video FX;c:\windows\system32\drivers\V0400Vfx.sys [08-02-2010 17:02 7424]
S3 VF0400Vid;Live! Cam Notebook Pro (VF0400);c:\windows\system32\drivers\V0400Vid.sys [08-02-2010 17:02 166720]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
bsczbyri
pujpuh
.
Indhold af mappen 'Planlagte Opgaver'
2008-11-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmer\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-11-03 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 13:07]
.
.
------- Yderligere scanning -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} -
hxxp://fubar.com/js/ImageUploader/ImageUploader6.cabFF - ProfilePath - c:\documents and settings\Melissa\Application Data\Mozilla\Firefox\Profiles\xoxacg3f.default\
FF - prefs.js: browser.startup.homepage -
hxxp://go.microsoft.com/fwlink/?LinkId=69157FF - component: c:\programmer\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: c:\documents and settings\Melissa\Lokale indstillinger\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\programmer\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\programmer\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\programmer\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\programmer\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\programmer\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLITIKKER ----
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
c:\programmer\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - TOMME GENVEJE FJERNET - - - -
BHO-{0A6A344B-F48D-4175-9274-2CC1D0846480} - c:\windows\system32\dlo212.dll
HKLM-Run-Tvs - c:\program files\Toshiba\Tvs\TvsTray.exe
AddRemove-Musicnotes Combined Installer_is1 - c:\programmer\Musicnotes\unins000.exe
AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\programmer\DivX\DivXCodecUninstall.exe
AddRemove-UnityWebPlayer - c:\documents and settings\Melissa\Lokale indstillinger\Application Data\Unity\WebPlayer\Uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-11-03 22:33
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\programmer\Lavalys\EVEREST Ultimate Edition\kerneld.wnt"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pujpuh]
"ServiceDll"="c:\windows\system32\qznebvm.dll"
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs startet under kørende Processer ---------------------
- - - - - - - > 'explorer.exe'(208)
c:\windows\system32\nview.dll
c:\windows\system32\NVWRSDA.DLL
c:\windows\system32\nvwddi.dll
c:\windows\system32\webcheck.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\programmer\Bonjour\mDNSResponder.exe
c:\programmer\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\programmer\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\rundll32.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\rundll32.exe
c:\windows\system32\wscntfy.exe
c:\programmer\iPod\bin\iPodService.exe
c:\programmer\Windows Live\Contacts\wlcomm.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Gennemført tid: 2010-11-03 22:36:16 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2010-11-03 21:36
Pre-Kørsel: 15.460.151.296 byte ledig
Post-Kørsel: 15.436.861.440 byte ledig
- - End Of File - - 883757E7BAACA7BB6C755D5FB575BB5C