MalwareBytes log:
Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.orgDatabase version: 6940
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11
24-06-2011 22:24:39
mbam-log-2011-06-24 (22-24-39).txt
Skanningstype: Fuldstændig skanning (C:\|D:\|E:\|)
Objekter skannet: 307896
Tid gået: 48 minut(ter), 35 sekund(er)
Hukommelses Processorer Inficeret: 0
Hukommelses Moduler Inficeret: 0
Registreringsdatabasenøgler Inficeret: 0
Registreringsdatabaseværdier Inficeret: 0
Registreringsdatabasedata Objekter Inficeret: 0
Inficerede Mapper: 0
Inficerede Filer: 3
Hukommelses Processorer Inficeret:
(Ingen skadelige objekter blev fundet)
Hukommelses Moduler Inficeret:
(Ingen skadelige objekter blev fundet)
Registreringsdatabasenøgler Inficeret:
(Ingen skadelige objekter blev fundet)
Registreringsdatabaseværdier Inficeret:
(Ingen skadelige objekter blev fundet)
Registreringsdatabasedata Objekter Inficeret:
(Ingen skadelige objekter blev fundet)
Inficerede Mapper:
(Ingen skadelige objekter blev fundet)
Inficerede Filer:
c:\system volume information\_restore{5228097e-46ba-4eb0-a0ca-471353418dc9}\RP1295\A0199880.exe (Trojan.Crypt) -> Quarantined and deleted successfully.
c:\system volume information\_restore{5228097e-46ba-4eb0-a0ca-471353418dc9}\RP1295\A0199882.exe (Trojan.Crypt) -> Quarantined and deleted successfully.
d:\programmer\pokertracker 3\Data\Plugins\bodogcommunicator.pt3 (Trojan.Agent) -> Quarantined and deleted successfully.
-------------------------------------------------------
DDS log
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26
Run by Insane at 15:58:24 on 2011-06-25
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1030.18.1023.193 [GMT 2:00]
.
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Programmer\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Programmer\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
D:\Programmer\Avira\AntiVir Desktop\avguard.exe
D:\Programmer\Java\bin\jqs.exe
C:\Programmer\D-Tools\daemon.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Programmer\Windows Defender\MSASCui.exe
D:\Programmer\Winamp\winampa.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
D:\Programmer\Avira\AntiVir Desktop\avgnt.exe
C:\Programmer\Windows Live\Messenger\msnmsgr.exe
D:\Programmer\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Programmer\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Programmer\Logitech\SetPoint\SetPoint.exe
D:\Programmer\Digsby\lib\digsby-app.exe
C:\Programmer\Fælles filer\Logishrd\KHAL2\KHALMNPR.EXE
C:\Programmer\Windows Live\Contacts\wlcomm.exe
C:\Programmer\Skype\Plugin Manager\skypePM.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\Programmer\Mozilla Firefox\plugin-container.exe
D:\Programmer\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\NOTEPAD.EXE
.
============== Pseudo HJT Report ===============
.
uStart Page =
hxxp://www.google.com/BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\programmer\fælles filer\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: WormRadar.com IESiteBlocker.NavFilter: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - AVG Safe Search
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - d:\programmer\java\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\programmer\fælles filer\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - d:\programmer\megaupload\mega manager\MegaIEMn.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\programmer\java\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - d:\programmer\java\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [StartCCC] c:\programmer\ati technologies\ati.ace\core-static\CLIStart.exe
uRun: [MsnMsgr] "c:\programmer\windows live\messenger\msnmsgr.exe" /background
uRun: [Skype] "c:\programmer\skype\phone\Skype.exe" /nosplash /minimized
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [DAEMON Tools-1033] "c:\programmer\d-tools\daemon.exe" -lang 1033
mRun: [WINDVDPatch] CTHELPER.EXE
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [Jet Detection] c:\programmer\creative\sblive\program\ADGJDet.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [Windows Defender] "c:\programmer\windows defender\MSASCui.exe" -hide
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [WinampAgent] d:\programmer\winamp\winampa.exe
mRun: [KeePass 2 PreLoad] "d:\programmer\keepass password safe 2\KeePass.exe" --preload
mRun: [avgnt] "d:\programmer\avira\antivir desktop\avgnt.exe" /min
mRun: [SunJavaUpdateSched] "d:\programmer\java\bin\jusched.exe"
mRun: [Adobe ARM] "c:\programmer\fælles filer\adobe\arm\1.0\AdobeARM.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\insane\menuen~1\progra~1\start\digsby.lnk - d:\programmer\digsby\digsby.exe
StartupFolder: c:\docume~1\alluse~1\menuen~1\progra~1\start\logite~1.lnk - d:\programmer\logitech\setpoint\SetPoint.exe
StartupFolder: c:\docume~1\alluse~1\menuen~1\progra~1\start\micros~1.lnk - d:\programmer\microsoft office 2003\office10\OSA.EXE
IE: E&xport to Microsoft Excel - d:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - d:\games\cdpoker\casino.exe
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\documents and settings\insane\skrivebord\PartyPoker.lnk
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\programmer\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBC} - d:\programmer\java\bin\jp2iexp.dll
Trusted Zone: danid.dk
Trusted Zone: danid.dk
DPF: Microsoft XML Parser for Java -
file://c:\windows\java\classes\xmldso.cabDPF: {17492023-C23A-453E-A040-C7C580BBF700} -
hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cabDPF: {5EC7C511-CD0F-42E6-830C-1BD9882F3458} -
hxxp://download.ppstream.com/bin/powerplayer.cabDPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} -
hxxp://download.eset.com/special/eos/OnlineScanner.cabDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cabDPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -
hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cabDPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cabDPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
hxxps://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabDPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} -
hxxps://flashpoker.ladbrokes.com/ladbrokes/FlashAX.cabDPF: {D821DC4A-0814-435E-9820-661C543A4679} -
hxxp://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocxDPF: {D8575CE3-3432-4540-88A9-85A1325D3375} -
hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cabTCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{AFC8AF5F-2D22-4844-8F9A-DB47C09A7D78} : DhcpNameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\fllesf~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: LBTWlgn - c:\programmer\fælles filer\logishrd\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\insane\application data\mozilla\firefox\profiles\a0u2orng.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.com/firefoxFF - plugin: c:\programmer\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\programmer\microsoft silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: c:\programmer\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\programmer\mozilla firefox\plugins\npunagi2.dll
FF - plugin: c:\programmer\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\programmer\octoshape streaming services\insane\octoprogram-l03-nms0806260_sua_000\npoctoshape.dll
FF - plugin: c:\programmer\octoshape streaming services\insane\octoprogram-l03-nms0810164_sua_000\npoctoshape.dll
FF - plugin: c:\programmer\octoshape streaming services\insane\octoprogram-l03-nms1002010_sua_000\npoctoshape.dll
FF - plugin: c:\programmer\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - plugin: d:\programmer\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: d:\programmer\adobe\reader 10.0\reader\browser\nppdf32.dll
FF - plugin: d:\programmer\java\bin\new_plugin\npdeployJava1.dll
FF - plugin: d:\programmer\java\bin\new_plugin\npjp2.dll
.
============= SERVICES / DRIVERS ===============
.
R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [2007-5-6 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [2007-5-6 5248]
R1 atitray;atitray;c:\programmer\ray adams\ati tray tools\atitray.sys [2007-5-22 18088]
R1 avgio;avgio;d:\programmer\avira\antivir desktop\avgio.sys [2011-6-24 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;d:\programmer\avira\antivir desktop\sched.exe [2011-6-24 136360]
R2 AntiVirService;Avira AntiVir Guard;d:\programmer\avira\antivir desktop\avguard.exe [2011-6-24 269480]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-6-24 61960]
R2 postgresql-8.4;postgresql-8.4 - PostgreSQL Server 8.4;D:/Programmer/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N "postgresql-8.4" -D "D:/Programmer/PostgreSQL/8.4/data" -w --> D:/Programmer/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N postgresql-8.4 [?]
R2 WinDefend;Windows Defender;c:\programmer\windows defender\MsMpEng.exe [2006-11-3 13592]
S1 SASKUTIL;SASKUTIL;\??\d:\programmer\superantispyware\saskutil.sys --> d:\programmer\superantispyware\SASKUTIL.sys [?]
S2 pgsql-8.2;PostgreSQL Database Server 8.2;d:\programmer\postgresql\bin\pg_ctl.exe runservice -w -n "pgsql-8.2" -d "d:\programmer\postgresql\data\" --> d:\programmer\postgresql\bin\pg_ctl.exe runservice -w -N pgsql-8.2 [?]
S3 B-Service;B-Service;c:\documents and settings\insane\application data\mikogo\B-Service.exe [2009-4-9 185640]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-6-24 39984]
.
=============== Created Last 30 ================
.
2011-06-25 12:52:17 -------- d-sh--w- c:\documents and settings\insane\PrivacIE
2011-06-25 12:00:50 -------- d-sh--w- c:\documents and settings\insane\IETldCache
2011-06-25 11:57:02 -------- dc-h--w- c:\windows\ie8
2011-06-25 06:16:41 -------- d-----w- c:\documents and settings\insane\lokale indstillinger\application data\Secunia PSI
2011-06-24 23:07:22 2106216 ----a-w- c:\programmer\mozilla firefox\D3DCompiler_43.dll
2011-06-24 23:07:21 1998168 ----a-w- c:\programmer\mozilla firefox\d3dx9_43.dll
2011-06-24 20:31:56 -------- d-----w- c:\documents and settings\all users\application data\SUPERAntiSpyware.com
2011-06-24 20:31:42 -------- d-----w- c:\documents and settings\insane\application data\SUPERAntiSpyware.com
2011-06-24 19:29:43 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-24 19:29:42 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-24 15:34:55 -------- d-----w- c:\windows\system32\NtmsData
2011-06-24 15:33:18 -------- d-----w- c:\documents and settings\insane\application data\Avira
2011-06-24 15:29:40 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-06-24 15:29:40 -------- d-----w- c:\documents and settings\all users\application data\Avira
2011-06-24 15:06:11 388096 ----a-r- c:\documents and settings\insane\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-06-24 06:06:22 7074640 ----a-w- c:\documents and settings\all users\application data\microsoft\windows defender\definition updates\{07f84577-6fd4-494b-82dd-e211514d66aa}\mpengine.dll
2011-06-16 06:23:11 3698584 -c--a-w- c:\windows\system32\dllcache\ieapfltr.dat
2011-06-16 06:21:09 759296 -c--a-w- c:\windows\system32\dllcache\VGX.dll
2011-06-16 06:20:17 138496 -c----w- c:\windows\system32\dllcache\afd.sys
2011-06-16 06:20:16 105472 -c----w- c:\windows\system32\dllcache\mup.sys
2011-06-16 06:20:02 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2011-06-16 06:19:59 692736 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2011-06-15 08:08:08 -------- d-----w- c:\documents and settings\all users\application data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-06-06 10:55:30 183696 ----a-w- c:\programmer\mozilla firefox\plugins\nppdf32.dll
2011-06-06 10:55:30 183696 ----a-w- c:\programmer\internet explorer\plugins\nppdf32.dll
2011-05-28 11:50:32 -------- d-----w- c:\documents and settings\insane\application data\go
2011-05-28 11:50:29 -------- d-----w- c:\documents and settings\all users\application data\Easybits GO
.
==================== Find3M ====================
.
2011-06-25 09:55:36 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-06-25 09:55:36 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-06-25 06:27:58 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-24 17:14:10 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-05-02 15:32:15 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-05-01 15:00:29 72080 ----a-w- c:\documents and settings\insane\g2mdlhlpx.exe
2011-04-29 16:19:43 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-21 13:37:43 105472 ----a-w- c:\windows\system32\drivers\mup.sys
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.netWindows 5.1.2600 Disk: ST3160023AS rev.3.20 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-22
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x86BEBBD8]<<
_asm { JMP 0x4; }
1 nt!IofCallDriver[0x804E13B9] -> \Device\Harddisk0\DR0[0x86FA5AB8]
3 CLASSPNP[0xF76AFFD7] -> nt!IofCallDriver[0x804E13B9] -> \Device\Ide\IdeDeviceP1T0L0-17[0x86F2DD98]
\Driver\atapi[0x86F31280] -> IRP_MJ_CREATE -> 0x86BEBBD8
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
detected hooks:
\Driver\atapi -> 0x86bebbd8
user != kernel MBR !!!
Warning: possible MBR rootkit infection !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.
.
============= FINISH: 15:59:08,89 ===============
--------------------------------------------------------------
Der var en til dds log også med programmer jeg har på computeren osv. Kunne ikke finde noget på listen jeg ikke kunne genkende men sig blot hvis i gerne vil se den og så smider jeg den op også.
Mvh DB