Der var to log-filer, den ene hed ComboFix.txt og den anden ComboFix-quarantined-files.txt
Først ComboFix.txt:
“Kenneth” – 2008-10-26 12:52:23 Service Pack 2 [SAFE MODE]
ComboFix 07-05.27.BV – Running from: “C:\Documents and Settings\Kenneth\Skrivebord\”
((((((((((((((((((((((((((((((( Files Created from 2008-09-26 to 2008-10-26 ))))))))))))))))))))))))))))))))))
2008-10-25 14:09 <DIR> d——– C:\Programmer\IVT Corporation
2008-10-25 14:07 27,904 –a—— C:\WINDOWS\system32\drivers\ndisprot.sys
2008-10-25 14:06 <DIR> dr-hs—- C:\resycled
2008-10-25 13:55 <DIR> d——– C:\Programmer\F‘lles filer\DFX
2008-10-25 13:55 <DIR> d——– C:\Programmer\DFX
2008-10-25 13:55 <DIR> d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\DFX
2008-10-25 12:52 9,464 ——— C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-10-25 12:52 9,336 ——— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-10-25 12:52 43,528 ——— C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-10-25 12:52 129,784 ——— C:\WINDOWS\system32\pxafs.dll
2008-10-25 12:51 <DIR> d——– C:\Programmer\Winamp
2008-10-25 12:51 <DIR> d——– C:\DOCUME~1\Kenneth\APPLIC~1\Winamp
2008-10-25 11:21 <DIR> d——– C:\Programmer\F‘lles filer\xing shared
2008-10-25 11:20 <DIR> d——– C:\Programmer\F‘lles filer\Real
2008-10-25 11:20 <DIR> d——– C:\DOCUME~1\Kenneth\APPLIC~1\Real
2008-10-19 12:32 <DIR> d——– C:\Programmer\Codemasters
2008-10-19 12:26 <DIR> d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hewlett-Packard
2008-10-18 22:02 <DIR> d——– C:\Programmer\7-Zip
2008-10-17 22:57 <DIR> d——– C:\Programmer\RelevantKnowledge
2008-10-17 22:56 <DIR> d——– C:\Programmer\Keenfinder
2008-10-17 22:53 <DIR> d——– C:\Programmer\NetMeter
2008-10-16 20:07 30 –a—— C:\Documents and Settings\Kenneth\jagex_runescape_preferences.dat
2008-10-16 20:07 30 –a—— C:\DOCUME~1\Kenneth\jagex_runescape_preferences.dat
2008-10-16 20:07 <DIR> d——– C:\WINDOWS\.jagex_cache_32
2008-10-15 22:56 <DIR> d——– C:\Programmer\MSXML 4.0
2008-10-15 14:28 <DIR> d——– C:\Programmer\uTorrent
2008-10-15 14:28 <DIR> d——– C:\DOCUME~1\Kenneth\APPLIC~1\uTorrent
2008-10-15 13:10 <DIR> d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
2008-10-15 13:06 <DIR> d——– C:\Programmer\Windows Live SkyDrive
2008-10-15 13:03 <DIR> d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2008-10-15 12:49 <DIR> d——– C:\WINDOWS\system32\NtmsData
2008-10-15 12:31 <DIR> d——– C:\DOCUME~1\ALLUSE~1\Skabeloner
2008-10-15 11:34 <DIR> dr——- C:\Dokumenter
2008-10-15 11:25 <DIR> d——– C:\Billeder
2008-10-15 11:20 <DIR> dr–s—- C:\My Stationery
2008-10-15 11:20 <DIR> dr——- C:\Videoer
2008-10-15 11:20 <DIR> d——– C:\Musik
2008-10-15 11:20 <DIR> d——– C:\Modtagne filer
2008-10-15 11:13 <DIR> d–h—– C:\$AVG8.VAULT$
2008-10-15 11:03 <DIR> d——– C:\Documents and Settings\Kenneth\Contacts
2008-10-15 11:03 <DIR> d——– C:\DOCUME~1\Kenneth\Contacts
2008-10-15 11:00 <DIR> d——– C:\Programmer\Windows Live
2008-10-15 10:04 <DIR> d——– C:\Programmer\NETGEAR WG311v2 Adapter
2008-10-15 10:03 62,865 –a—— C:\WINDOWS\system32\drivers\odysseyIM3.sys
2008-10-10 12:43 <DIR> d——– C:\Programmer\Muiltmedia keyboard Utility
2008-10-10 12:06 24,064 –a—— C:\WINDOWS\system32\msxml3a.dll
2008-10-10 12:06 1,331,200 ——— C:\WINDOWS\UNNeroVision.exe
2008-10-10 12:05 <DIR> d——– C:\DOCUME~1\Kenneth\APPLIC~1\Ahead
2008-10-10 12:05 <DIR> d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
2008-10-10 12:04 89,184 –a—— C:\WINDOWS\system32\drivers\imagedrv.sys
2008-10-10 12:04 569,344 –a—— C:\WINDOWS\system32\imagr5.dll
2008-10-10 12:04 544,768 –a—— C:\WINDOWS\system32\imagx5.dll
2008-10-10 12:04 38,912 –a—— C:\WINDOWS\system32\picn20.dll
2008-10-10 12:04 283,920 –a—— C:\WINDOWS\system32\ImagXpr5.dll
2008-10-10 12:04 155,648 –a—— C:\WINDOWS\system32\NeroCheck.exe
2008-10-10 12:04 <DIR> d——– C:\Programmer\F‘lles filer\Ahead
2008-10-10 12:04 <DIR> d——– C:\Programmer\Ahead
2008-10-08 16:06 <DIR> d——– C:\program files
2008-10-06 13:21 <DIR> d——– C:\WINDOWS\Downloaded Installations
2008-10-01 13:53 <DIR> d——– C:\Programmer\Steam
2008-10-01 13:24 <DIR> d——– C:\Downloads
2008-10-01 13:21 <DIR> d——– C:\Programmer\Trymedia
2008-10-01 13:15 270,880 –a—— C:\WINDOWS\system32\mucltui.dll
2008-10-01 13:15 210,976 –a—— C:\WINDOWS\system32\muweb.dll
2008-10-01 13:15 <DIR> d——– C:\WINDOWS\system32\CatRoot_bak
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2008-10-26 08:01:09 82,728 —-a-w C:\WINDOWS\system32\perfc006.dat
2008-10-26 08:01:09 456,062 —-a-w C:\WINDOWS\system32\perfh006.dat
2008-10-25 12:55:21 ——– d—–w C:\Programmer\Fælles filer\DFX
2008-10-25 12:55:21 ——– d—–w C:\Programmer\Fælles filer
2008-10-25 10:21:13 ——– d—–w C:\Programmer\Fælles filer\xing shared
2008-10-25 10:21:08 ——– d—–w C:\Programmer\Fælles filer\Real
2008-10-25 10:20:56 499,712 —-a-w C:\WINDOWS\system32\msvcp71.dll
2008-10-25 10:20:56 348,160 —-a-w C:\WINDOWS\system32\msvcr71.dll
2008-10-17 21:56:54 ——– d—–w C:\Programmer\FileSubmit
2008-10-15 19:06:32 ——– d—–w C:\Programmer\EA GAMES
2008-10-10 11:04:06 ——– d—–w C:\Programmer\Fælles filer\Ahead
2008-10-06 12:31:52 ——– d—–w C:\Programmer\Fælles filer\Wise Installation Wizard
2008-10-01 12:15:17 97,928 —-a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-09-23 13:55:52 ——– d—–w C:\Programmer\Fælles filer\Microsoft Shared
2008-09-23 13:52:07 ——– d—–w C:\Programmer\Microsoft Works
2008-09-23 13:51:38 ——– d—–w C:\Programmer\Fælles filer\DESIGNER
2008-09-23 13:50:43 ——– d—–w C:\Programmer\Microsoft.NET
2008-09-23 13:50:21 ——– d—–w C:\Programmer\Fælles filer\System
2008-09-22 14:45:22 ——– d—–w C:\Programmer\Fælles filer\DirectX
2008-09-22 14:08:16 ——– d—–w C:\Programmer\Fælles filer\Roxio Shared
2008-09-22 14:08:04 ——– d—–w C:\Programmer\Roxio
2008-09-22 13:29:10 ——– d–h–w C:\Programmer\InstallShield Installation Information
2008-09-22 13:28:46 ——– d—–w C:\Programmer\Fælles filer\InstallShield
2008-09-22 13:24:49 552 ——w C:\WINDOWS\system32\d3d8caps.dat
2008-09-21 14:02:58 43,520 ——w C:\WINDOWS\system32\CmdLineExt03.dll
2008-09-15 15:40:38 1,846,016 ——w C:\WINDOWS\system32\win32k.sys
2008-09-14 01:19:25 ——– d—–w C:\DOCUME~1\Kenneth\APPLIC~1\ViStart
2008-09-14 01:18:39 ——– d—–w C:\Programmer\Vistart Live bY Pri2sh
2008-09-14 01:18:30 ——– d—–w C:\DOCUME~1\Kenneth\APPLIC~1\Styler
2008-09-14 01:05:15 ——– d—–w C:\Programmer\TGTSoft
2008-09-14 00:35:06 ——– d—–w C:\Programmer\Adparatus
2008-09-13 23:10:28 ——– d—–w C:\DOCUME~1\Kenneth\APPLIC~1\MSN6
2008-09-13 16:29:28 ——– d—–w C:\Programmer\MagicISO
2008-09-13 15:53:11 ——– d—–w C:\Programmer\Alcohol Soft
2008-08-30 22:21:55 ——– d—–w C:\DOCUME~1\Kenneth\APPLIC~1\Media Player Classic
2008-08-30 21:49:30 ——– d—–w C:\Programmer\XP Codec Pack
2008-08-30 20:19:46 ——– d—–w C:\Programmer\DAEMON Tools Lite
2008-08-30 20:16:53 717,296 ——w C:\WINDOWS\system32\drivers\sptd.sys
2008-08-30 20:16:45 ——– d—–w C:\DOCUME~1\Kenneth\APPLIC~1\DAEMON Tools
2008-08-29 19:54:00 ——– d—–w C:\DOCUME~1\Kenneth\APPLIC~1\PC Suite
2008-08-29 19:53:45 ——– d—–w C:\DOCUME~1\Kenneth\APPLIC~1\Nokia
2008-08-29 19:52:40 ——– d—–w C:\Programmer\DIFX
2008-08-29 19:52:15 ——– d—–w C:\Programmer\Fælles filer\Nokia
2008-08-29 19:52:14 ——– d—–w C:\Programmer\Fælles filer\PCSuite
2008-08-29 19:52:13 ——– d—–w C:\Programmer\Nokia
2008-08-29 19:51:54 ——– d—–w C:\Programmer\PC Connectivity Solution
2008-08-28 10:04:17 333,056 ——w C:\WINDOWS\system32\drivers\srv.sys
2008-08-24 12:34:24 10,520 ——w C:\WINDOWS\system32\avgrsstx.dll
2008-08-14 17:17:16 44 -c—-w C:\WINDOWS\system32\msssc.dll
2008-08-14 14:18:23 0 –sha-r C:\MSDOS.SYS
2008-08-14 14:18:23 0 –sha-r C:\IO.SYS
2008-08-14 14:18:23 0 —-a-w C:\CONFIG.SYS
2008-08-14 14:18:23 0 —-a-w C:\AUTOEXEC.BAT
2008-08-14 14:15:48 21,644 -c—-w C:\WINDOWS\system32\emptyregdb.dat
2008-08-04 15:36:50 405,589 —-a-w C:\WINDOWS\system32\BsUI.dll
2008-08-04 15:33:40 143,450 —-a-w C:\WINDOWS\system32\BsCommon.dll
2008-08-01 13:59:24 9,728 —-a-w C:\WINDOWS\system32\BsMonUI.dll
2008-08-01 13:59:20 18,432 —-a-w C:\WINDOWS\system32\BsMonSvr.dll
2008-08-01 13:58:58 57,430 —-a-w C:\WINDOWS\system32\btfunc.dll
2008-08-01 13:58:50 278,647 —-a-w C:\WINDOWS\system32\outlookAddin.dll
2008-08-01 13:58:30 53,248 —-a-w C:\WINDOWS\system32\HtmPrintHelper.dll
2008-08-01 13:58:24 114,774 —-a-w C:\WINDOWS\system32\versit.dll
2008-08-01 13:58:14 622,693 —-a-w C:\WINDOWS\system32\BSShell.dll
2008-08-01 13:58:00 540,758 —-a-w C:\WINDOWS\system32\Bscdlg.dll
2008-08-01 13:57:50 114,788 —-a-w C:\WINDOWS\system32\BsProfileFunc.dll
2008-08-01 13:57:18 94,314 —-a-w C:\WINDOWS\system32\BsHelpCSps.dll
2008-08-01 13:57:16 520,307 —-a-w C:\WINDOWS\system32\BlueSoleilCSps.dll
2008-08-01 13:56:16 28,766 —-a-w C:\WINDOWS\system32\PlayerCtrl.dll
2008-08-01 13:56:14 98,403 —-a-w C:\WINDOWS\system32\Bs2Res.dll
2008-08-01 13:56:12 225,364 —-a-w C:\WINDOWS\system32\BsSDK.dll
2008-08-01 13:55:40 118,880 —-a-w C:\WINDOWS\system32\BsMobileSDK.dll
2008-08-01 13:55:30 28,672 —-a-w C:\WINDOWS\system32\BsMobileCSps.dll
2008-08-01 13:55:22 28,760 —-a-w C:\WINDOWS\system32\BsTrace.dll
2008-08-01 13:46:44 41,049 —-a-w C:\WINDOWS\system32\skypeagent.dll
2008-08-01 13:46:44 1,717,848 —-a-w C:\WINDOWS\system32\skype4com.dll
2008-08-01 13:46:30 65,536 —-a-w C:\WINDOWS\system32\BsVistaCommon.dll
2008-08-01 13:46:30 17,907,824 —-a-w C:\WINDOWS\system32\BsLangInDepRes.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{3049C3E9-B461-4BC5-8870-4C09146192CA}=C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-10-25 11:21]
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}=C:\Programmer\AVG\AVG8\avgssie.dll [2008-10-01 13:15]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 03:27]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ATICCC”=”C:\Programmer\ATI Technologies\ATI.ACE\cli.exe” [2006-01-02 15:41]
“AVG8_TRAY”=”C:\PROGRA~1\AVG\AVG8\avgtray.exe” [2008-10-01 13:15]
“FLMK08KB”=”C:\Programmer\Muiltmedia keyboard Utility\1.3\KbdAp32A.exe” [2008-10-10 12:43]
“SunJavaUpdateSched”=”C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe” [2008-06-10 03:27]
“smapp”=”C:\Programmer\Analog Devices\SoundMAX\SMTray.exe” [2003-05-05 07:57]
“TkBellExe”=”C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe” []
“BtTray”=”C:\Programmer\IVT Corporation\BlueSoleil\BtTray.exe” [2008-08-04 17:04]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=”C:\WINDOWS\system32\ctfmon.exe” [2004-08-26 16:53]
“STYLEXP”=”C:\Programmer\TGTSoft\StyleXP\StyleXP.exe” [2006-05-24 19:31]
“C:\Programmer\NetMeter\NetMeter.exe”=”C:\Programmer\NetMeter\NetMeter.exe” [2007-08-11 14:50]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
“Nokia.PCSync”=”C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe” /NoDialog
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
“appinit_dlls”=avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
********************************************************************
catchme 0.3.692 W2K/XP/Vista – userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-26 12:56:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
********************************************************************
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“C:\\Programmer\\NetMeter\\NetMeter.exe”=”C:\\Programmer\\NetMeter\\NetMeter.exe”
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Keenfinder Service]
“ImagePath”=”\”C:\Programmer\Keenfinder\keenfinder.exe\” \”C:\Programmer\Keenfinder\keenfinder.dll\” Service”
Completion time: 2008-10-26 12:58:22 – machine was rebooted
C:\ComboFix-quarantined-files.txt … 2008-10-26 12:58
— E O F —
______________________________________________________________________________
Og så den anden ComboFix-quarantined-files.txt:
<br />2008-10-26 12:54 28616 --a------ C:\Qoobox\Quarantine\Registry_backups\winlogon.reg.cf</p>
<p>Mappetr‘<br />Diskenhedens serienummer er 7869-B400<br />C:\QOOBOX<br />\---Quarantine<br /> \---Registry_backups<br /> winlogon.reg.cf<br /> <br />
______________________________________________________________________________
MVH
Kenneth