Bro
Topic Starter
A previous topic of mine was recently closed. Therefore I would like to hear if there are any problems with my computer, since I didn't find out. I have attached logs from five different programs, which I was instructed to in my previous topic.
GMER log:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-30 15:10:21
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\Steffen\AppData\Local\Temp\kwddrfob.sys
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Dynamisk WDF/Microsoft Corporation)
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0021860bd92f
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xE6 0x22 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xAD 0x0B 0xA6 0xE1 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x40 0x66 0xCA 0x20 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x7F 0x24 0xD5 0xFC …
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0021860bd92f (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xE6 0x22 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xAD 0x0B 0xA6 0xE1 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x40 0x66 0xCA 0x20 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x7F 0x24 0xD5 0xFC …
—- EOF - GMER 1.0.15 —-
Malwarebytes' Anti-Malware log:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4054
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005
30-04-2010 16:41:32
mbam-log-2010-04-30 (16-41-32).txt
Skanningstype: Hurtig skanning
Objekter skannet: 125351
Tid gået: 9 minut(ter), 2 sekund(er)
Hukommelses Processorer Inficeret: 0
Hukommelses Moduler Inficeret: 0
Registreringsdatabasenøgler Inficeret: 4
Registreringsdatabaseværdier Inficeret: 0
Registreringsdatabasedata Objekter Inficeret: 0
Inficerede Mapper: 0
Inficerede Filer: 3
Hukommelses Processorer Inficeret:
(Ingen skadelige objekter blev fundet)
Hukommelses Moduler Inficeret:
(Ingen skadelige objekter blev fundet)
Registreringsdatabasenøgler Inficeret:
HKEY_CURRENT_USER\Software\YVIBBBHA8C (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\QZAIB7KITK (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Registreringsdatabaseværdier Inficeret:
(Ingen skadelige objekter blev fundet)
Registreringsdatabasedata Objekter Inficeret:
(Ingen skadelige objekter blev fundet)
Inficerede Mapper:
(Ingen skadelige objekter blev fundet)
Inficerede Filer:
C:\Users\Steffen\AppData\Local\temp\amowcxsren.exe (Adware.AdRotator) -> Quarantined and deleted successfully.
C:\Users\Steffen\AppData\Local\temp\stp4cf45.exe (Trojan.FraudTool) -> Quarantined and deleted successfully.
C:\Users\Steffen\AppData\Local\temp\Vlz.exe (Trojan.Fraudpack) -> Quarantined and deleted successfully.
Combofix log
ComboFix 10-05-01.01 - Steffen 01-05-2010 19:52:45.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.45.1030.18.3070.2024 [GMT 2:00]
Kører fra: c:\users\Steffen\Desktop\ComboFix.exe
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((( Filer skabt fra 2010-04-01 til 2010-05-01 )))))))))))))))))))))))))))))))))))
.
2010-05-01 18:10 . 2010-05-01 18:11 ——– d—–w- c:\users\Steffen\AppData\Local\temp
2010-05-01 18:10 . 2010-05-01 18:10 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-05-01 18:10 . 2010-05-01 18:10 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-04-30 14:25 . 2010-04-30 14:25 6153352 —-a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-04-29 22:11 . 2010-04-29 22:11 ——– d—–w- c:\program files\Foosball
2010-04-29 22:09 . 2010-04-29 22:09 ——– d—–w- c:\program files\Rats!
2010-04-27 06:25 . 2010-04-27 06:25 563712 —-a-w- c:\program files\OTL.exe
2010-04-26 09:40 . 2010-04-26 09:40 388096 —-a-r- c:\users\Steffen\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-04-25 18:49 . 2010-04-25 18:49 730624 —-a-w- c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156\newupdate1142C.exe
2010-04-25 18:49 . 2010-04-25 18:49 ——– d—–w- c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156
2010-04-23 06:32 . 2006-12-14 08:00 110592 —-a-w- c:\users\Steffen\AppData\Roaming\U3\temp\cleanup.exe
2010-04-23 06:31 . 2007-02-12 15:46 3096576 —ha-w- c:\users\Steffen\AppData\Roaming\U3\temp\Launchpad Removal.exe
2010-04-23 06:31 . 2010-04-23 06:32 ——– d—–w- c:\users\Steffen\AppData\Roaming\U3
2010-04-22 05:23 . 2010-04-22 05:23 ——– d—–w- c:\users\Steffen\AppData\Local\Adobe
2010-04-19 19:46 . 2010-04-19 19:46 ——– d—–w- c:\users\Steffen\AppData\Roaming\Malwarebytes
2010-04-19 19:46 . 2010-04-29 13:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-19 19:46 . 2010-04-19 19:46 ——– d—–w- c:\programdata\Malwarebytes
2010-04-19 19:46 . 2010-04-30 14:29 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-19 19:46 . 2010-04-29 13:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-18 11:14 . 2010-04-18 23:09 ——– d—–w- c:\program files\Musikprogrammer
2010-04-18 10:39 . 2010-04-18 10:39 ——– d—–w- c:\program files\Trend Micro
2010-04-15 15:30 . 2010-04-15 15:30 ——– d—–w- c:\programdata\{87784988-8668-411D-B26A-0C946ED2BE3C}
2010-04-15 15:30 . 2009-03-31 16:02 575004 —-a-w- c:\programdata\{87784988-8668-411D-B26A-0C946ED2BE3C}\mia.dll
2010-04-15 15:30 . 2009-03-31 16:02 2131640 —-a-w- c:\programdata\{87784988-8668-411D-B26A-0C946ED2BE3C}\printer og drev (sct. knuds gymnasium).exe
2010-04-15 15:30 . 2010-04-15 15:30 ——– d—–w- c:\program files\Skoleprinter
2010-04-15 10:12 . 2010-04-15 10:12 ——– d—–w- c:\program files\Grafværktøj
2010-04-15 10:11 . 1999-03-23 06:12 299520 —-a-w- c:\windows\uninst.exe
2010-04-14 05:23 . 2010-03-04 17:33 430080 —-a-w- c:\windows\system32\vbscript.dll
2010-04-14 05:23 . 2010-02-23 11:10 79360 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-14 05:23 . 2010-02-23 11:10 212992 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-14 05:23 . 2010-02-23 11:10 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-14 05:23 . 2010-02-18 14:07 3600776 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-14 05:23 . 2010-02-18 14:07 3548040 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-04-14 05:22 . 2009-12-23 11:33 172032 —-a-w- c:\windows\system32\wintrust.dll
2010-04-14 05:22 . 2010-02-18 14:07 904576 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-14 05:22 . 2010-02-18 13:30 200704 —-a-w- c:\windows\system32\iphlpsvc.dll
2010-04-14 05:22 . 2010-02-18 11:28 25088 —-a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-14 05:19 . 2010-01-13 17:34 98304 —-a-w- c:\windows\system32\cabview.dll
2010-04-11 14:18 . 2010-04-11 14:19 ——– d—–w- C:\a0c698d600d463d0cf
2010-04-09 10:59 . 2010-04-19 14:06 ——– d-sh–w- c:\programdata\SysWoW32
2010-04-09 10:58 . 2010-04-09 10:58 203776 –sh–w- c:\programdata\unrar.exe
2010-04-05 15:47 . 2010-04-05 15:47 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-04-05 15:43 . 2010-04-05 22:16 ——– d—–w- c:\programdata\Lavasoft
2010-04-05 15:43 . 2010-04-05 15:44 ——– d—–w- c:\program files\Lavasoft
2010-04-02 21:14 . 2010-04-02 21:15 ——– d—–w- c:\program files\GIMP-2.0
2010-04-02 21:12 . 2010-04-02 21:12 ——– d—–w- c:\program files\Common Files\GTK
2010-04-02 15:52 . 2010-03-29 07:59 52224 —-a-w- c:\users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
2010-04-02 15:52 . 2010-03-29 07:59 101376 —-a-w- c:\users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-01 17:43 . 2008-12-26 20:54 32061 —-a-w- c:\programdata\nvModes.dat
2010-05-01 10:18 . 2008-05-21 04:08 12 —-a-w- c:\windows\bthservsdp.dat
2010-05-01 10:15 . 2008-02-26 01:47 82814 —-a-w- c:\windows\system32\perfc006.dat
2010-05-01 10:15 . 2008-02-26 01:47 479574 —-a-w- c:\windows\system32\perfh006.dat
2010-04-28 16:17 . 2010-04-28 16:17 78808 —-a-w- c:\program files\Extras.Txt
2010-04-28 16:16 . 2010-04-28 16:16 110164 —-a-w- c:\program files\OTL.Txt
2010-04-19 07:54 . 2009-07-10 09:44 ——– d—–w- c:\program files\Microsoft Silverlight
2010-04-18 23:05 . 2009-08-03 10:44 ——– d—–w- c:\users\Steffen\AppData\Roaming\vlc
2010-04-18 21:12 . 2008-11-26 20:05 ——– d—–w- c:\users\Steffen\AppData\Roaming\LimeWire
2010-04-17 20:55 . 2009-12-27 11:58 ——– d—–w- c:\program files\Google
2010-04-15 10:12 . 2010-04-15 10:12 ——– d—–w- c:\program files\Grafværktøj
2010-04-14 06:08 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-04-14 05:36 . 2008-10-27 17:38 ——– d—–w- c:\programdata\Microsoft Help
2010-04-09 10:46 . 2008-11-26 20:04 ——– d—–w- c:\program files\LimeWire
2010-04-02 11:55 . 2010-03-28 17:47 ——– d—–w- c:\users\Steffen\AppData\Roaming\uTorrent
2010-03-28 17:50 . 2010-03-28 17:50 ——– d—–w- c:\program files\uTorrent
2010-03-26 16:25 . 2008-05-21 04:35 ——– d—–w- c:\programdata\NVIDIA
2010-03-26 10:31 . 2008-10-10 11:44 ——– d—–w- c:\program files\CCleaner
2010-03-19 16:35 . 2010-03-08 19:34 439816 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\setup.exe
2010-03-19 16:35 . 2010-03-19 16:35 5971968 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\chr\ChromeInstaller.exe
2010-03-19 16:34 . 2010-03-19 16:34 79368 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\vista.exe
2010-03-19 16:34 . 2010-03-19 16:34 64000 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\gcapi_dll.dll
2010-03-19 16:34 . 2010-03-19 16:34 52288 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\gtapi.dll
2010-03-19 16:34 . 2010-03-19 16:34 50688 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\fftbapi.dll
2010-03-19 16:34 . 2010-03-19 16:34 118784 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\compat.dll
2010-03-19 16:34 . 2010-03-19 16:34 49152 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\CarboniteCompatibility.dll
2010-03-18 17:33 . 2010-03-18 17:27 ——– d—–w- c:\users\Steffen\AppData\Roaming\Teleca
2010-03-18 17:32 . 2010-03-18 17:32 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
2010-03-18 17:26 . 2010-03-18 17:26 ——– d—–w- c:\program files\Common Files\Teleca Shared
2010-03-18 17:26 . 2010-03-18 17:26 ——– d—–w- c:\programdata\HTC
2010-03-18 17:26 . 2010-03-18 17:26 ——– d—–w- c:\programdata\Teleca
2010-03-18 17:26 . 2010-03-18 17:24 ——– d—–w- c:\program files\HTC
2010-03-18 17:24 . 2010-03-18 17:24 ——– d—–w- c:\program files\Spirent Communications
2010-03-12 15:40 . 2010-03-12 15:39 ——– d—–w- c:\program files\Common Files\DVDVideoSoft
2010-03-12 15:39 . 2010-03-12 15:39 ——– d—–w- c:\program files\DVDVideoSoft
2010-03-12 15:31 . 2010-03-12 15:30 ——– d—–w- c:\program files\YouTube Downloader
2010-03-11 18:47 . 2010-03-11 18:47 444952 —-a-w- c:\windows\system32\wrap_oal.dll
2010-03-11 18:47 . 2010-03-11 18:47 109080 —-a-w- c:\windows\system32\OpenAL32.dll
2010-03-11 18:47 . 2010-03-11 18:47 ——– d—–w- c:\program files\OpenAL
2010-03-11 18:46 . 2010-03-11 18:46 ——– d—–w- c:\program files\Prodigium Game Studios
2010-03-11 07:17 . 2010-02-15 14:13 64164264 —-a-w- c:\users\Steffen\AppData\Roaming\Nokia\Ovi Suite\Software Updater\NokiaOviSuite2Installer.exe
2010-03-09 16:25 . 2010-04-01 15:39 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-03-09 15:42 . 2010-04-01 15:39 834048 —-a-w- c:\windows\system32\wininet.dll
2010-02-26 16:13 . 2010-03-16 16:35 17160 —-a-w- c:\windows\Help\OEM\scripts\HPHCDisableObject.exe
2010-02-24 19:55 . 2008-08-29 17:17 121072 —-a-w- c:\users\Steffen\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-24 08:16 . 2009-10-03 14:37 181632 ——w- c:\windows\system32\MpSigStub.exe
2010-02-22 18:16 . 2008-11-13 12:44 680 —-a-w- c:\users\Steffen\AppData\Local\d3d9caps.dat
2010-02-22 12:28 . 2010-03-09 09:47 1282824 —-a-w- c:\windows\Help\OEM\scripts\SamsungHDDFW1HC.exe
2010-02-20 23:06 . 2010-03-10 11:18 24064 —-a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:05 . 2010-03-10 11:17 30720 —-a-w- c:\windows\system32\httpapi.dll
2010-02-20 20:53 . 2010-03-10 11:17 411648 —-a-w- c:\windows\system32\drivers\http.sys
2010-02-12 10:32 . 2010-03-05 08:52 293376 —-a-w- c:\windows\system32\browserchoice.exe
2010-02-05 13:45 . 2010-02-05 13:45 72488 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-04 15:51 . 2010-03-09 09:47 49152 —-a-w- c:\windows\Help\OEM\scripts\Interop.TaskScheduler.dll
2008-02-26 02:57 . 2008-02-26 02:37 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2007-09-20 671744]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-10-03 13826664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~3\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Steffen^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Screen Clipper and Launcher til OneNote 2007.lnk]
path=c:\users\Steffen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Screen Clipper and Launcher til OneNote 2007.lnk
backup=c:\windows\pss\Screen Clipper and Launcher til OneNote 2007.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CamSpace]
2009-09-08 16:41 1404928 —-a-w- c:\program files\CamSpace\CamSpaceAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
2009-12-18 10:24 427328 —-a-w- c:\program files\DAEMON Tools Pro\DTProAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-19 07:33 125952 —-a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2010-02-21 20:45 30192 —-a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-09-28 17:45 133104 —-atw- c:\users\Steffen\AppData\Local\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 09:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
2008-10-09 05:58 75008 —-a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 14:24 54840 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-01-22 18:16 141608 —-a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2007-08-23 15:36 455968 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-04-29 13:39 1090952 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mobile Connectivity Suite]
2009-11-19 15:19 598016 —-a-r- c:\program files\HTC\HTC Sync\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2009-10-03 10:40 13826664 —-a-w- c:\windows\System32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2009-10-03 10:40 92776 —-a-w- c:\windows\System32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OnScreenDisplay]
2007-09-04 20:54 554320 —-a-w- c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2007-10-01 02:34 181544 —-a-w- c:\program files\HP\QuickPlay\QPService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 22:08 417792 —-a-w- c:\program files\QuickTime & Real Alternative\QuickTime Alternative\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-07-31 13:23 149280 —-a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-02-15 18:12 198160 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
2007-08-17 06:13 218408 ——w- c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WAWifiMessage]
2007-01-08 23:53 311296 —-a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-07-01 16:37 37888 —-a-w- c:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-19 07:33 202240 —-a-w- c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(:8d,99,72,53,18,00,ca,01
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-01-23 691696]
R2 appdrvrem01;Application Driver Auto Removal Service (01);c:\windows\System32\appdrvrem01.exe svc [x]
R2 gupdate;Tjenesten Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-12-27 133104]
R3 GoogleDesktopManager-110309-193829;Google Desktop-administrator 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-02-21 30192]
R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-06-10 24576]
S1 appdrv01;Application Driver (01);c:\windows\system32\Drivers\appdrv01.sys [2009-07-19 2915944]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2009-12-02 42368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 15:34 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Indhold af mappen 'Planlagte Opgaver'
2010-05-01 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-27 05:56]
2010-05-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-27 11:59]
2010-05-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-27 11:59]
2010-04-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-142386170-2914611657-1622844314-1000Core.job
- c:\users\Steffen\AppData\Local\Google\Update\GoogleUpdate.exe [2009-09-28 17:45]
2010-05-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-142386170-2914611657-1622844314-1000UA.job
- c:\users\Steffen\AppData\Local\Google\Update\GoogleUpdate.exe [2009-09-28 17:45]
2010-04-06 c:\windows\Tasks\HPCeeScheduleForSteffen.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-02-26 19:58]
.
.
——- Yderligere scanning ——-
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_dk&c=81&bd=Pavilion&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_dk&c=81&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send billede til &Bluetooth-enhed… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send siden til &Bluetooth-enhed… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: danskebank.dk
DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} - hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
FF - ProfilePath - c:\users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\s0kfb21q.default\
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\program files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\components\FirefoxExtension.dll
FF - component: c:\users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
FF - component: c:\users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLITIKKER —-
c:\program files\Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-01 20:11
Windows 6.0.6002 Service Pack 2 NTFS
scanner skjulte processer …
scanner skjulte autostarter …
scanner skjulte filer …
c:\users\Steffen\AppData\Local\Temp\catchme.dll 53248 bytes executable
scanning gennemført med succes
skjulte filer: 1
**************************************************************************
.
——————— LÅSTE REGISTRERINGS NØGLER ———————
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs startet under kørende Processer ———————
- - - - - - - > 'lsass.exe'(696)
c:\windows\system32\DPPWDFLT.dll
- - - - - - - > 'Explorer.exe'(1728)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
c:\program files\MediaMonkey\DeskPlayer.dll
.
Gennemført tid: 2010-05-01 20:17:14
ComboFix-quarantined-files.txt 2010-05-01 18:17
ComboFix2.txt 2010-04-20 15:08
Pre-Kørsel: 64.812.265.472 byte ledig
Post-Kørsel: 64.842.977.280 byte ledig
- - End Of File - - FCCD9EFAC68644D9CFF46240FFB4956E
VirusTotal
Searched for following file: C:\ProgramData\1925965306
File 1925965306 received on 2010.05.02 11:43:19 (UTC)
Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.05.02 -
AhnLab-V3 2010.05.02.00 2010.05.01 -
AntiVir 8.2.1.224 2010.04.30 -
Antiy-AVL 2.0.3.7 2010.04.30 -
Authentium 5.2.0.5 2010.05.01 -
Avast 4.8.1351.0 2010.05.02 -
Avast5 5.0.332.0 2010.05.02 -
AVG 9.0.0.787 2010.05.02 -
BitDefender 7.2 2010.05.02 -
CAT-QuickHeal 10.00 2010.05.01 -
ClamAV 0.96.0.3-git 2010.05.02 -
Comodo 4739 2010.05.02 -
DrWeb 5.0.2.03300 2010.05.02 -
eSafe 7.0.17.0 2010.04.29 -
eTrust-Vet 35.2.7462 2010.04.30 -
F-Prot 4.5.1.85 2010.05.01 -
F-Secure 9.0.15370.0 2010.05.02 -
Fortinet 4.0.14.0 2010.05.01 -
GData 21 2010.05.02 -
Ikarus T3.1.1.80.0 2010.05.02 -
Jiangmin 13.0.900 2010.05.02 -
Kaspersky 7.0.0.125 2010.05.02 -
McAfee 5.400.0.1158 2010.05.02 -
McAfee-GW-Edition 6.8.5 2010.05.01 -
Microsoft 1.5703 2010.05.02 -
NOD32 5079 2010.05.02 -
Norman 6.04.12 2010.05.01 -
nProtect 2010-05-02.01 2010.05.02 -
Panda 10.0.2.7 2010.05.01 -
PCTools 7.0.3.5 2010.05.02 -
Prevx 3.0 2010.05.02 -
Rising 22.45.04.03 2010.04.30 -
Sophos 4.53.0 2010.05.02 -
Sunbelt 6249 2010.05.02 -
Symantec 20091.2.0.41 2010.05.02 -
TheHacker 6.5.2.0.275 2010.05.02 -
TrendMicro 9.120.0.1004 2010.05.01 -
TrendMicro-HouseCall 9.120.0.1004 2010.05.02 -
VBA32 3.12.12.4 2010.04.30 -
ViRobot 2010.5.1.2299 2010.05.02 -
VirusBuster 5.0.27.0 2010.05.01 -
Additional information
File size: 817 bytes
MD5…: 672c1e7e48e2884aadf5a1007d4eadfc
SHA1..: 6199b1c92cbcdcd95a8b0d7540f8dc02d910d454
SHA256: 3db65629d26f99c9e67b64ef561ede0a484facf5d1726caf2f1d86ade01a7a84
ssdeep: 12:5ZEbTKLz+eSG9vh3J9nJQoiSu5n9W8UFlRRVPPPjIhO0cuE:3EbTC+CX9JQb/
U3RRNIhO0cn
PEiD..: -
PEInfo: -
RDS…: NSRL Reference Data Set
-
pdfid.: -
trid..: MP3 audio (100.0%)
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned
Searched for following file: C:\ProgramData\580629930
File 580629930 received on 2010.05.02 11:40:54 (UTC)
Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.05.02 -
AhnLab-V3 2010.05.02.00 2010.05.01 -
AntiVir 8.2.1.224 2010.04.30 -
Antiy-AVL 2.0.3.7 2010.04.30 -
Authentium 5.2.0.5 2010.05.01 -
Avast 4.8.1351.0 2010.05.02 -
Avast5 5.0.332.0 2010.05.02 -
AVG 9.0.0.787 2010.05.02 -
BitDefender 7.2 2010.05.02 -
CAT-QuickHeal 10.00 2010.05.01 -
ClamAV 0.96.0.3-git 2010.05.02 -
Comodo 4739 2010.05.02 -
DrWeb 5.0.2.03300 2010.05.02 -
eSafe 7.0.17.0 2010.04.29 -
eTrust-Vet 35.2.7462 2010.04.30 -
F-Prot 4.5.1.85 2010.05.01 -
F-Secure 9.0.15370.0 2010.05.02 -
Fortinet 4.0.14.0 2010.05.01 -
GData 21 2010.05.02 -
Ikarus T3.1.1.80.0 2010.05.02 -
Jiangmin 13.0.900 2010.05.02 -
Kaspersky 7.0.0.125 2010.05.02 -
McAfee 5.400.0.1158 2010.05.02 -
McAfee-GW-Edition 6.8.5 2010.05.01 -
Microsoft 1.5703 2010.05.02 -
NOD32 5079 2010.05.02 -
Norman 6.04.12 2010.05.01 -
nProtect 2010-05-02.01 2010.05.02 -
Panda 10.0.2.7 2010.05.01 -
PCTools 7.0.3.5 2010.05.02 -
Prevx 3.0 2010.05.02 -
Rising 22.45.04.03 2010.04.30 -
Sophos 4.53.0 2010.05.02 -
Sunbelt 6249 2010.05.02 -
Symantec 20091.2.0.41 2010.05.02 -
TheHacker 6.5.2.0.275 2010.05.02 -
TrendMicro 9.120.0.1004 2010.05.01 -
TrendMicro-HouseCall 9.120.0.1004 2010.05.02 -
VBA32 3.12.12.4 2010.04.30 -
ViRobot 2010.5.1.2299 2010.05.02 -
VirusBuster 5.0.27.0 2010.05.01 -
Additional information
File size: 1023 bytes
MD5…: 5f65b01c59c8b3c331d1f8c058fb2d96
SHA1..: 9809dbf3a54085f85c1a18c25d0e4c1262568793
SHA256: 999e3d3ef27f2a9e7c3be6a1059f98f91aedbcda006955389c239751bf62cbaf
ssdeep: 12:JKAL/Oji16Q6jH3tr42NmNbfXr+Y6NLWreNfDMkwk08w69O8QS8/vNKjs:oDi
AQ6T3t8gQbfSppop8QS8nNKjs
PEiD..: -
PEInfo: -
RDS…: NSRL Reference Data Set
-
pdfid.: -
trid..: file seems to be plain text/ASCII (0.0%)
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned
Searched for following file: C:\ProgramData\sl1132078904
File sl1132078904 received on 2010.05.02 11:47:48 (UTC)
Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.05.02 -
AhnLab-V3 2010.05.02.00 2010.05.01 -
AntiVir 8.2.1.224 2010.04.30 -
Antiy-AVL 2.0.3.7 2010.04.30 -
Authentium 5.2.0.5 2010.05.01 -
Avast 4.8.1351.0 2010.05.02 -
Avast5 5.0.332.0 2010.05.02 -
AVG 9.0.0.787 2010.05.02 -
BitDefender 7.2 2010.05.02 -
CAT-QuickHeal 10.00 2010.05.01 -
ClamAV 0.96.0.3-git 2010.05.02 -
Comodo 4739 2010.05.02 -
DrWeb 5.0.2.03300 2010.05.02 -
eSafe 7.0.17.0 2010.04.29 -
eTrust-Vet 35.2.7462 2010.04.30 -
F-Prot 4.5.1.85 2010.05.01 -
F-Secure 9.0.15370.0 2010.05.02 -
Fortinet 4.0.14.0 2010.05.01 -
GData 21 2010.05.02 -
Ikarus T3.1.1.80.0 2010.05.02 -
Jiangmin 13.0.900 2010.05.02 -
Kaspersky 7.0.0.125 2010.05.02 -
McAfee 5.400.0.1158 2010.05.02 -
McAfee-GW-Edition 6.8.5 2010.05.01 -
Microsoft 1.5703 2010.05.02 -
NOD32 5079 2010.05.02 -
Norman 6.04.12 2010.05.01 -
nProtect 2010-05-02.01 2010.05.02 -
Panda 10.0.2.7 2010.05.01 -
PCTools 7.0.3.5 2010.05.02 -
Prevx 3.0 2010.05.02 -
Rising 22.45.04.03 2010.04.30 -
Sophos 4.53.0 2010.05.02 -
Sunbelt 6249 2010.05.02 -
Symantec 20091.2.0.41 2010.05.02 -
TheHacker 6.5.2.0.275 2010.05.02 -
TrendMicro 9.120.0.1004 2010.05.01 -
TrendMicro-HouseCall 9.120.0.1004 2010.05.02 -
VBA32 3.12.12.4 2010.04.30 -
ViRobot 2010.5.1.2299 2010.05.02 -
VirusBuster 5.0.27.0 2010.05.01 -
Additional information
File size: 113 bytes
MD5…: ca140f2455b62bcc84b95128a6ca05a4
SHA1..: 04f9ebf37742816dc3a4505633ec33ba333c7d3a
SHA256: 408722726b2023cd8bc54c8d12cec6db09c56ae78df1ab98cdaf77fbc92e50b4
ssdeep: 3:9eoxBuPv7+9uoxMJm7FyyvHnthv3vknvHnthSj:iXa9VI6vB
PEiD..: -
PEInfo: -
RDS…: NSRL Reference Data Set
-
pdfid.: -
trid..: Unknown!
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned
In the code box in OTL, i was instructed to write:
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
[2010-04-25 20:50:11 | 000,223,232 | -HS- | C] () – C:\Users\Steffen\AppData\Local\ave.exe
[2010-04-25 20:50:11 | 000,009,952 | -HS- | C] () – C:\Users\Steffen\AppData\Local\UJ0QRjYY
[2010-04-25 20:50:11 | 000,009,952 | -HS- | C] () – C:\ProgramData\UJ0QRjYY
[2010-04-09 12:59:07 | 000,000,000 | -HSD | C] – C:\ProgramData\SysWoW32
[2010-04-19 22:06:25 | 000,000,817 | —- | M] () – C:\ProgramData\1925965306
[2010-04-19 16:05:58 | 000,001,023 | -HS- | M] () – C:\ProgramData\580629930
[2010-04-09 12:59:07 | 000,000,113 | —- | M] () – C:\ProgramData\sl1132078904
:Files
c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156\newupdate1142C.exe
c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
After pressing Run Fix with the inserted code, this is the log I got out of it:
OTL log:
All processes killed
========== OTL ==========
No active process named explorer.exe was found!
File C:\Users\Steffen\AppData\Local\ave.exe not found.
C:\Users\Steffen\AppData\Local\UJ0QRjYY moved successfully.
C:\ProgramData\UJ0QRjYY moved successfully.
C:\ProgramData\SysWoW32 folder moved successfully.
C:\ProgramData\1925965306 moved successfully.
C:\ProgramData\580629930 moved successfully.
C:\ProgramData\sl1132078904 moved successfully.
========== FILES ==========
c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156\newupdate1142C.exe moved successfully.
c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156 folder moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
User: Steffen
->Temp folder emptied: 211566 bytes
->Temporary Internet Files folder emptied: 20703588 bytes
->Java cache emptied: 1568560 bytes
->FireFox cache emptied: 67359042 bytes
->Google Chrome cache emptied: 429100018 bytes
->Flash cache emptied: 279874 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 26324 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 495,00 mb
OTL by OldTimer - Version 3.2.3.0 log created on 05042010_101245
Files\Folders moved on Reboot…
Registry entries deleted on Reboot…
GMER log:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-30 15:10:21
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\Steffen\AppData\Local\Temp\kwddrfob.sys
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Dynamisk WDF/Microsoft Corporation)
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0021860bd92f
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xE6 0x22 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xAD 0x0B 0xA6 0xE1 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x40 0x66 0xCA 0x20 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x7F 0x24 0xD5 0xFC …
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0021860bd92f (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xE6 0x22 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xAD 0x0B 0xA6 0xE1 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x40 0x66 0xCA 0x20 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x7F 0x24 0xD5 0xFC …
—- EOF - GMER 1.0.15 —-
Malwarebytes' Anti-Malware log:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4054
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005
30-04-2010 16:41:32
mbam-log-2010-04-30 (16-41-32).txt
Skanningstype: Hurtig skanning
Objekter skannet: 125351
Tid gået: 9 minut(ter), 2 sekund(er)
Hukommelses Processorer Inficeret: 0
Hukommelses Moduler Inficeret: 0
Registreringsdatabasenøgler Inficeret: 4
Registreringsdatabaseværdier Inficeret: 0
Registreringsdatabasedata Objekter Inficeret: 0
Inficerede Mapper: 0
Inficerede Filer: 3
Hukommelses Processorer Inficeret:
(Ingen skadelige objekter blev fundet)
Hukommelses Moduler Inficeret:
(Ingen skadelige objekter blev fundet)
Registreringsdatabasenøgler Inficeret:
HKEY_CURRENT_USER\Software\YVIBBBHA8C (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\QZAIB7KITK (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Registreringsdatabaseværdier Inficeret:
(Ingen skadelige objekter blev fundet)
Registreringsdatabasedata Objekter Inficeret:
(Ingen skadelige objekter blev fundet)
Inficerede Mapper:
(Ingen skadelige objekter blev fundet)
Inficerede Filer:
C:\Users\Steffen\AppData\Local\temp\amowcxsren.exe (Adware.AdRotator) -> Quarantined and deleted successfully.
C:\Users\Steffen\AppData\Local\temp\stp4cf45.exe (Trojan.FraudTool) -> Quarantined and deleted successfully.
C:\Users\Steffen\AppData\Local\temp\Vlz.exe (Trojan.Fraudpack) -> Quarantined and deleted successfully.
Combofix log
ComboFix 10-05-01.01 - Steffen 01-05-2010 19:52:45.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.45.1030.18.3070.2024 [GMT 2:00]
Kører fra: c:\users\Steffen\Desktop\ComboFix.exe
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((( Filer skabt fra 2010-04-01 til 2010-05-01 )))))))))))))))))))))))))))))))))))
.
2010-05-01 18:10 . 2010-05-01 18:11 ——– d—–w- c:\users\Steffen\AppData\Local\temp
2010-05-01 18:10 . 2010-05-01 18:10 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-05-01 18:10 . 2010-05-01 18:10 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-04-30 14:25 . 2010-04-30 14:25 6153352 —-a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-04-29 22:11 . 2010-04-29 22:11 ——– d—–w- c:\program files\Foosball
2010-04-29 22:09 . 2010-04-29 22:09 ——– d—–w- c:\program files\Rats!
2010-04-27 06:25 . 2010-04-27 06:25 563712 —-a-w- c:\program files\OTL.exe
2010-04-26 09:40 . 2010-04-26 09:40 388096 —-a-r- c:\users\Steffen\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-04-25 18:49 . 2010-04-25 18:49 730624 —-a-w- c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156\newupdate1142C.exe
2010-04-25 18:49 . 2010-04-25 18:49 ——– d—–w- c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156
2010-04-23 06:32 . 2006-12-14 08:00 110592 —-a-w- c:\users\Steffen\AppData\Roaming\U3\temp\cleanup.exe
2010-04-23 06:31 . 2007-02-12 15:46 3096576 —ha-w- c:\users\Steffen\AppData\Roaming\U3\temp\Launchpad Removal.exe
2010-04-23 06:31 . 2010-04-23 06:32 ——– d—–w- c:\users\Steffen\AppData\Roaming\U3
2010-04-22 05:23 . 2010-04-22 05:23 ——– d—–w- c:\users\Steffen\AppData\Local\Adobe
2010-04-19 19:46 . 2010-04-19 19:46 ——– d—–w- c:\users\Steffen\AppData\Roaming\Malwarebytes
2010-04-19 19:46 . 2010-04-29 13:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-19 19:46 . 2010-04-19 19:46 ——– d—–w- c:\programdata\Malwarebytes
2010-04-19 19:46 . 2010-04-30 14:29 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-19 19:46 . 2010-04-29 13:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-18 11:14 . 2010-04-18 23:09 ——– d—–w- c:\program files\Musikprogrammer
2010-04-18 10:39 . 2010-04-18 10:39 ——– d—–w- c:\program files\Trend Micro
2010-04-15 15:30 . 2010-04-15 15:30 ——– d—–w- c:\programdata\{87784988-8668-411D-B26A-0C946ED2BE3C}
2010-04-15 15:30 . 2009-03-31 16:02 575004 —-a-w- c:\programdata\{87784988-8668-411D-B26A-0C946ED2BE3C}\mia.dll
2010-04-15 15:30 . 2009-03-31 16:02 2131640 —-a-w- c:\programdata\{87784988-8668-411D-B26A-0C946ED2BE3C}\printer og drev (sct. knuds gymnasium).exe
2010-04-15 15:30 . 2010-04-15 15:30 ——– d—–w- c:\program files\Skoleprinter
2010-04-15 10:12 . 2010-04-15 10:12 ——– d—–w- c:\program files\Grafværktøj
2010-04-15 10:11 . 1999-03-23 06:12 299520 —-a-w- c:\windows\uninst.exe
2010-04-14 05:23 . 2010-03-04 17:33 430080 —-a-w- c:\windows\system32\vbscript.dll
2010-04-14 05:23 . 2010-02-23 11:10 79360 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-14 05:23 . 2010-02-23 11:10 212992 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-14 05:23 . 2010-02-23 11:10 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-14 05:23 . 2010-02-18 14:07 3600776 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-14 05:23 . 2010-02-18 14:07 3548040 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-04-14 05:22 . 2009-12-23 11:33 172032 —-a-w- c:\windows\system32\wintrust.dll
2010-04-14 05:22 . 2010-02-18 14:07 904576 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-14 05:22 . 2010-02-18 13:30 200704 —-a-w- c:\windows\system32\iphlpsvc.dll
2010-04-14 05:22 . 2010-02-18 11:28 25088 —-a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-14 05:19 . 2010-01-13 17:34 98304 —-a-w- c:\windows\system32\cabview.dll
2010-04-11 14:18 . 2010-04-11 14:19 ——– d—–w- C:\a0c698d600d463d0cf
2010-04-09 10:59 . 2010-04-19 14:06 ——– d-sh–w- c:\programdata\SysWoW32
2010-04-09 10:58 . 2010-04-09 10:58 203776 –sh–w- c:\programdata\unrar.exe
2010-04-05 15:47 . 2010-04-05 15:47 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-04-05 15:43 . 2010-04-05 22:16 ——– d—–w- c:\programdata\Lavasoft
2010-04-05 15:43 . 2010-04-05 15:44 ——– d—–w- c:\program files\Lavasoft
2010-04-02 21:14 . 2010-04-02 21:15 ——– d—–w- c:\program files\GIMP-2.0
2010-04-02 21:12 . 2010-04-02 21:12 ——– d—–w- c:\program files\Common Files\GTK
2010-04-02 15:52 . 2010-03-29 07:59 52224 —-a-w- c:\users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
2010-04-02 15:52 . 2010-03-29 07:59 101376 —-a-w- c:\users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-01 17:43 . 2008-12-26 20:54 32061 —-a-w- c:\programdata\nvModes.dat
2010-05-01 10:18 . 2008-05-21 04:08 12 —-a-w- c:\windows\bthservsdp.dat
2010-05-01 10:15 . 2008-02-26 01:47 82814 —-a-w- c:\windows\system32\perfc006.dat
2010-05-01 10:15 . 2008-02-26 01:47 479574 —-a-w- c:\windows\system32\perfh006.dat
2010-04-28 16:17 . 2010-04-28 16:17 78808 —-a-w- c:\program files\Extras.Txt
2010-04-28 16:16 . 2010-04-28 16:16 110164 —-a-w- c:\program files\OTL.Txt
2010-04-19 07:54 . 2009-07-10 09:44 ——– d—–w- c:\program files\Microsoft Silverlight
2010-04-18 23:05 . 2009-08-03 10:44 ——– d—–w- c:\users\Steffen\AppData\Roaming\vlc
2010-04-18 21:12 . 2008-11-26 20:05 ——– d—–w- c:\users\Steffen\AppData\Roaming\LimeWire
2010-04-17 20:55 . 2009-12-27 11:58 ——– d—–w- c:\program files\Google
2010-04-15 10:12 . 2010-04-15 10:12 ——– d—–w- c:\program files\Grafværktøj
2010-04-14 06:08 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-04-14 05:36 . 2008-10-27 17:38 ——– d—–w- c:\programdata\Microsoft Help
2010-04-09 10:46 . 2008-11-26 20:04 ——– d—–w- c:\program files\LimeWire
2010-04-02 11:55 . 2010-03-28 17:47 ——– d—–w- c:\users\Steffen\AppData\Roaming\uTorrent
2010-03-28 17:50 . 2010-03-28 17:50 ——– d—–w- c:\program files\uTorrent
2010-03-26 16:25 . 2008-05-21 04:35 ——– d—–w- c:\programdata\NVIDIA
2010-03-26 10:31 . 2008-10-10 11:44 ——– d—–w- c:\program files\CCleaner
2010-03-19 16:35 . 2010-03-08 19:34 439816 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\setup.exe
2010-03-19 16:35 . 2010-03-19 16:35 5971968 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\chr\ChromeInstaller.exe
2010-03-19 16:34 . 2010-03-19 16:34 79368 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\vista.exe
2010-03-19 16:34 . 2010-03-19 16:34 64000 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\gcapi_dll.dll
2010-03-19 16:34 . 2010-03-19 16:34 52288 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\gtapi.dll
2010-03-19 16:34 . 2010-03-19 16:34 50688 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\fftbapi.dll
2010-03-19 16:34 . 2010-03-19 16:34 118784 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\compat.dll
2010-03-19 16:34 . 2010-03-19 16:34 49152 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\CarboniteCompatibility.dll
2010-03-18 17:33 . 2010-03-18 17:27 ——– d—–w- c:\users\Steffen\AppData\Roaming\Teleca
2010-03-18 17:32 . 2010-03-18 17:32 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
2010-03-18 17:26 . 2010-03-18 17:26 ——– d—–w- c:\program files\Common Files\Teleca Shared
2010-03-18 17:26 . 2010-03-18 17:26 ——– d—–w- c:\programdata\HTC
2010-03-18 17:26 . 2010-03-18 17:26 ——– d—–w- c:\programdata\Teleca
2010-03-18 17:26 . 2010-03-18 17:24 ——– d—–w- c:\program files\HTC
2010-03-18 17:24 . 2010-03-18 17:24 ——– d—–w- c:\program files\Spirent Communications
2010-03-12 15:40 . 2010-03-12 15:39 ——– d—–w- c:\program files\Common Files\DVDVideoSoft
2010-03-12 15:39 . 2010-03-12 15:39 ——– d—–w- c:\program files\DVDVideoSoft
2010-03-12 15:31 . 2010-03-12 15:30 ——– d—–w- c:\program files\YouTube Downloader
2010-03-11 18:47 . 2010-03-11 18:47 444952 —-a-w- c:\windows\system32\wrap_oal.dll
2010-03-11 18:47 . 2010-03-11 18:47 109080 —-a-w- c:\windows\system32\OpenAL32.dll
2010-03-11 18:47 . 2010-03-11 18:47 ——– d—–w- c:\program files\OpenAL
2010-03-11 18:46 . 2010-03-11 18:46 ——– d—–w- c:\program files\Prodigium Game Studios
2010-03-11 07:17 . 2010-02-15 14:13 64164264 —-a-w- c:\users\Steffen\AppData\Roaming\Nokia\Ovi Suite\Software Updater\NokiaOviSuite2Installer.exe
2010-03-09 16:25 . 2010-04-01 15:39 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-03-09 15:42 . 2010-04-01 15:39 834048 —-a-w- c:\windows\system32\wininet.dll
2010-02-26 16:13 . 2010-03-16 16:35 17160 —-a-w- c:\windows\Help\OEM\scripts\HPHCDisableObject.exe
2010-02-24 19:55 . 2008-08-29 17:17 121072 —-a-w- c:\users\Steffen\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-24 08:16 . 2009-10-03 14:37 181632 ——w- c:\windows\system32\MpSigStub.exe
2010-02-22 18:16 . 2008-11-13 12:44 680 —-a-w- c:\users\Steffen\AppData\Local\d3d9caps.dat
2010-02-22 12:28 . 2010-03-09 09:47 1282824 —-a-w- c:\windows\Help\OEM\scripts\SamsungHDDFW1HC.exe
2010-02-20 23:06 . 2010-03-10 11:18 24064 —-a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:05 . 2010-03-10 11:17 30720 —-a-w- c:\windows\system32\httpapi.dll
2010-02-20 20:53 . 2010-03-10 11:17 411648 —-a-w- c:\windows\system32\drivers\http.sys
2010-02-12 10:32 . 2010-03-05 08:52 293376 —-a-w- c:\windows\system32\browserchoice.exe
2010-02-05 13:45 . 2010-02-05 13:45 72488 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-04 15:51 . 2010-03-09 09:47 49152 —-a-w- c:\windows\Help\OEM\scripts\Interop.TaskScheduler.dll
2008-02-26 02:57 . 2008-02-26 02:37 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2007-09-20 671744]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-10-03 13826664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~3\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Steffen^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Screen Clipper and Launcher til OneNote 2007.lnk]
path=c:\users\Steffen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Screen Clipper and Launcher til OneNote 2007.lnk
backup=c:\windows\pss\Screen Clipper and Launcher til OneNote 2007.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CamSpace]
2009-09-08 16:41 1404928 —-a-w- c:\program files\CamSpace\CamSpaceAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
2009-12-18 10:24 427328 —-a-w- c:\program files\DAEMON Tools Pro\DTProAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-19 07:33 125952 —-a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2010-02-21 20:45 30192 —-a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-09-28 17:45 133104 —-atw- c:\users\Steffen\AppData\Local\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 09:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
2008-10-09 05:58 75008 —-a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 14:24 54840 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-01-22 18:16 141608 —-a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2007-08-23 15:36 455968 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-04-29 13:39 1090952 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mobile Connectivity Suite]
2009-11-19 15:19 598016 —-a-r- c:\program files\HTC\HTC Sync\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2009-10-03 10:40 13826664 —-a-w- c:\windows\System32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2009-10-03 10:40 92776 —-a-w- c:\windows\System32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OnScreenDisplay]
2007-09-04 20:54 554320 —-a-w- c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2007-10-01 02:34 181544 —-a-w- c:\program files\HP\QuickPlay\QPService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 22:08 417792 —-a-w- c:\program files\QuickTime & Real Alternative\QuickTime Alternative\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-07-31 13:23 149280 —-a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-02-15 18:12 198160 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
2007-08-17 06:13 218408 ——w- c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WAWifiMessage]
2007-01-08 23:53 311296 —-a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-07-01 16:37 37888 —-a-w- c:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-19 07:33 202240 —-a-w- c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(:8d,99,72,53,18,00,ca,01
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-01-23 691696]
R2 appdrvrem01;Application Driver Auto Removal Service (01);c:\windows\System32\appdrvrem01.exe svc [x]
R2 gupdate;Tjenesten Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-12-27 133104]
R3 GoogleDesktopManager-110309-193829;Google Desktop-administrator 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-02-21 30192]
R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-06-10 24576]
S1 appdrv01;Application Driver (01);c:\windows\system32\Drivers\appdrv01.sys [2009-07-19 2915944]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2009-12-02 42368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 15:34 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Indhold af mappen 'Planlagte Opgaver'
2010-05-01 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-27 05:56]
2010-05-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-27 11:59]
2010-05-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-27 11:59]
2010-04-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-142386170-2914611657-1622844314-1000Core.job
- c:\users\Steffen\AppData\Local\Google\Update\GoogleUpdate.exe [2009-09-28 17:45]
2010-05-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-142386170-2914611657-1622844314-1000UA.job
- c:\users\Steffen\AppData\Local\Google\Update\GoogleUpdate.exe [2009-09-28 17:45]
2010-04-06 c:\windows\Tasks\HPCeeScheduleForSteffen.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-02-26 19:58]
.
.
——- Yderligere scanning ——-
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_dk&c=81&bd=Pavilion&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_dk&c=81&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send billede til &Bluetooth-enhed… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send siden til &Bluetooth-enhed… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: danskebank.dk
DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} - hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
FF - ProfilePath - c:\users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\s0kfb21q.default\
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\program files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\components\FirefoxExtension.dll
FF - component: c:\users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
FF - component: c:\users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLITIKKER —-
c:\program files\Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-01 20:11
Windows 6.0.6002 Service Pack 2 NTFS
scanner skjulte processer …
scanner skjulte autostarter …
scanner skjulte filer …
c:\users\Steffen\AppData\Local\Temp\catchme.dll 53248 bytes executable
scanning gennemført med succes
skjulte filer: 1
**************************************************************************
.
——————— LÅSTE REGISTRERINGS NØGLER ———————
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs startet under kørende Processer ———————
- - - - - - - > 'lsass.exe'(696)
c:\windows\system32\DPPWDFLT.dll
- - - - - - - > 'Explorer.exe'(1728)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
c:\program files\MediaMonkey\DeskPlayer.dll
.
Gennemført tid: 2010-05-01 20:17:14
ComboFix-quarantined-files.txt 2010-05-01 18:17
ComboFix2.txt 2010-04-20 15:08
Pre-Kørsel: 64.812.265.472 byte ledig
Post-Kørsel: 64.842.977.280 byte ledig
- - End Of File - - FCCD9EFAC68644D9CFF46240FFB4956E
VirusTotal
Searched for following file: C:\ProgramData\1925965306
File 1925965306 received on 2010.05.02 11:43:19 (UTC)
Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.05.02 -
AhnLab-V3 2010.05.02.00 2010.05.01 -
AntiVir 8.2.1.224 2010.04.30 -
Antiy-AVL 2.0.3.7 2010.04.30 -
Authentium 5.2.0.5 2010.05.01 -
Avast 4.8.1351.0 2010.05.02 -
Avast5 5.0.332.0 2010.05.02 -
AVG 9.0.0.787 2010.05.02 -
BitDefender 7.2 2010.05.02 -
CAT-QuickHeal 10.00 2010.05.01 -
ClamAV 0.96.0.3-git 2010.05.02 -
Comodo 4739 2010.05.02 -
DrWeb 5.0.2.03300 2010.05.02 -
eSafe 7.0.17.0 2010.04.29 -
eTrust-Vet 35.2.7462 2010.04.30 -
F-Prot 4.5.1.85 2010.05.01 -
F-Secure 9.0.15370.0 2010.05.02 -
Fortinet 4.0.14.0 2010.05.01 -
GData 21 2010.05.02 -
Ikarus T3.1.1.80.0 2010.05.02 -
Jiangmin 13.0.900 2010.05.02 -
Kaspersky 7.0.0.125 2010.05.02 -
McAfee 5.400.0.1158 2010.05.02 -
McAfee-GW-Edition 6.8.5 2010.05.01 -
Microsoft 1.5703 2010.05.02 -
NOD32 5079 2010.05.02 -
Norman 6.04.12 2010.05.01 -
nProtect 2010-05-02.01 2010.05.02 -
Panda 10.0.2.7 2010.05.01 -
PCTools 7.0.3.5 2010.05.02 -
Prevx 3.0 2010.05.02 -
Rising 22.45.04.03 2010.04.30 -
Sophos 4.53.0 2010.05.02 -
Sunbelt 6249 2010.05.02 -
Symantec 20091.2.0.41 2010.05.02 -
TheHacker 6.5.2.0.275 2010.05.02 -
TrendMicro 9.120.0.1004 2010.05.01 -
TrendMicro-HouseCall 9.120.0.1004 2010.05.02 -
VBA32 3.12.12.4 2010.04.30 -
ViRobot 2010.5.1.2299 2010.05.02 -
VirusBuster 5.0.27.0 2010.05.01 -
Additional information
File size: 817 bytes
MD5…: 672c1e7e48e2884aadf5a1007d4eadfc
SHA1..: 6199b1c92cbcdcd95a8b0d7540f8dc02d910d454
SHA256: 3db65629d26f99c9e67b64ef561ede0a484facf5d1726caf2f1d86ade01a7a84
ssdeep: 12:5ZEbTKLz+eSG9vh3J9nJQoiSu5n9W8UFlRRVPPPjIhO0cuE:3EbTC+CX9JQb/
U3RRNIhO0cn
PEiD..: -
PEInfo: -
RDS…: NSRL Reference Data Set
-
pdfid.: -
trid..: MP3 audio (100.0%)
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned
Searched for following file: C:\ProgramData\580629930
File 580629930 received on 2010.05.02 11:40:54 (UTC)
Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.05.02 -
AhnLab-V3 2010.05.02.00 2010.05.01 -
AntiVir 8.2.1.224 2010.04.30 -
Antiy-AVL 2.0.3.7 2010.04.30 -
Authentium 5.2.0.5 2010.05.01 -
Avast 4.8.1351.0 2010.05.02 -
Avast5 5.0.332.0 2010.05.02 -
AVG 9.0.0.787 2010.05.02 -
BitDefender 7.2 2010.05.02 -
CAT-QuickHeal 10.00 2010.05.01 -
ClamAV 0.96.0.3-git 2010.05.02 -
Comodo 4739 2010.05.02 -
DrWeb 5.0.2.03300 2010.05.02 -
eSafe 7.0.17.0 2010.04.29 -
eTrust-Vet 35.2.7462 2010.04.30 -
F-Prot 4.5.1.85 2010.05.01 -
F-Secure 9.0.15370.0 2010.05.02 -
Fortinet 4.0.14.0 2010.05.01 -
GData 21 2010.05.02 -
Ikarus T3.1.1.80.0 2010.05.02 -
Jiangmin 13.0.900 2010.05.02 -
Kaspersky 7.0.0.125 2010.05.02 -
McAfee 5.400.0.1158 2010.05.02 -
McAfee-GW-Edition 6.8.5 2010.05.01 -
Microsoft 1.5703 2010.05.02 -
NOD32 5079 2010.05.02 -
Norman 6.04.12 2010.05.01 -
nProtect 2010-05-02.01 2010.05.02 -
Panda 10.0.2.7 2010.05.01 -
PCTools 7.0.3.5 2010.05.02 -
Prevx 3.0 2010.05.02 -
Rising 22.45.04.03 2010.04.30 -
Sophos 4.53.0 2010.05.02 -
Sunbelt 6249 2010.05.02 -
Symantec 20091.2.0.41 2010.05.02 -
TheHacker 6.5.2.0.275 2010.05.02 -
TrendMicro 9.120.0.1004 2010.05.01 -
TrendMicro-HouseCall 9.120.0.1004 2010.05.02 -
VBA32 3.12.12.4 2010.04.30 -
ViRobot 2010.5.1.2299 2010.05.02 -
VirusBuster 5.0.27.0 2010.05.01 -
Additional information
File size: 1023 bytes
MD5…: 5f65b01c59c8b3c331d1f8c058fb2d96
SHA1..: 9809dbf3a54085f85c1a18c25d0e4c1262568793
SHA256: 999e3d3ef27f2a9e7c3be6a1059f98f91aedbcda006955389c239751bf62cbaf
ssdeep: 12:JKAL/Oji16Q6jH3tr42NmNbfXr+Y6NLWreNfDMkwk08w69O8QS8/vNKjs:oDi
AQ6T3t8gQbfSppop8QS8nNKjs
PEiD..: -
PEInfo: -
RDS…: NSRL Reference Data Set
-
pdfid.: -
trid..: file seems to be plain text/ASCII (0.0%)
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned
Searched for following file: C:\ProgramData\sl1132078904
File sl1132078904 received on 2010.05.02 11:47:48 (UTC)
Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.05.02 -
AhnLab-V3 2010.05.02.00 2010.05.01 -
AntiVir 8.2.1.224 2010.04.30 -
Antiy-AVL 2.0.3.7 2010.04.30 -
Authentium 5.2.0.5 2010.05.01 -
Avast 4.8.1351.0 2010.05.02 -
Avast5 5.0.332.0 2010.05.02 -
AVG 9.0.0.787 2010.05.02 -
BitDefender 7.2 2010.05.02 -
CAT-QuickHeal 10.00 2010.05.01 -
ClamAV 0.96.0.3-git 2010.05.02 -
Comodo 4739 2010.05.02 -
DrWeb 5.0.2.03300 2010.05.02 -
eSafe 7.0.17.0 2010.04.29 -
eTrust-Vet 35.2.7462 2010.04.30 -
F-Prot 4.5.1.85 2010.05.01 -
F-Secure 9.0.15370.0 2010.05.02 -
Fortinet 4.0.14.0 2010.05.01 -
GData 21 2010.05.02 -
Ikarus T3.1.1.80.0 2010.05.02 -
Jiangmin 13.0.900 2010.05.02 -
Kaspersky 7.0.0.125 2010.05.02 -
McAfee 5.400.0.1158 2010.05.02 -
McAfee-GW-Edition 6.8.5 2010.05.01 -
Microsoft 1.5703 2010.05.02 -
NOD32 5079 2010.05.02 -
Norman 6.04.12 2010.05.01 -
nProtect 2010-05-02.01 2010.05.02 -
Panda 10.0.2.7 2010.05.01 -
PCTools 7.0.3.5 2010.05.02 -
Prevx 3.0 2010.05.02 -
Rising 22.45.04.03 2010.04.30 -
Sophos 4.53.0 2010.05.02 -
Sunbelt 6249 2010.05.02 -
Symantec 20091.2.0.41 2010.05.02 -
TheHacker 6.5.2.0.275 2010.05.02 -
TrendMicro 9.120.0.1004 2010.05.01 -
TrendMicro-HouseCall 9.120.0.1004 2010.05.02 -
VBA32 3.12.12.4 2010.04.30 -
ViRobot 2010.5.1.2299 2010.05.02 -
VirusBuster 5.0.27.0 2010.05.01 -
Additional information
File size: 113 bytes
MD5…: ca140f2455b62bcc84b95128a6ca05a4
SHA1..: 04f9ebf37742816dc3a4505633ec33ba333c7d3a
SHA256: 408722726b2023cd8bc54c8d12cec6db09c56ae78df1ab98cdaf77fbc92e50b4
ssdeep: 3:9eoxBuPv7+9uoxMJm7FyyvHnthv3vknvHnthSj:iXa9VI6vB
PEiD..: -
PEInfo: -
RDS…: NSRL Reference Data Set
-
pdfid.: -
trid..: Unknown!
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned
In the code box in OTL, i was instructed to write:
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
[2010-04-25 20:50:11 | 000,223,232 | -HS- | C] () – C:\Users\Steffen\AppData\Local\ave.exe
[2010-04-25 20:50:11 | 000,009,952 | -HS- | C] () – C:\Users\Steffen\AppData\Local\UJ0QRjYY
[2010-04-25 20:50:11 | 000,009,952 | -HS- | C] () – C:\ProgramData\UJ0QRjYY
[2010-04-09 12:59:07 | 000,000,000 | -HSD | C] – C:\ProgramData\SysWoW32
[2010-04-19 22:06:25 | 000,000,817 | —- | M] () – C:\ProgramData\1925965306
[2010-04-19 16:05:58 | 000,001,023 | -HS- | M] () – C:\ProgramData\580629930
[2010-04-09 12:59:07 | 000,000,113 | —- | M] () – C:\ProgramData\sl1132078904
:Files
c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156\newupdate1142C.exe
c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
After pressing Run Fix with the inserted code, this is the log I got out of it:
OTL log:
All processes killed
========== OTL ==========
No active process named explorer.exe was found!
File C:\Users\Steffen\AppData\Local\ave.exe not found.
C:\Users\Steffen\AppData\Local\UJ0QRjYY moved successfully.
C:\ProgramData\UJ0QRjYY moved successfully.
C:\ProgramData\SysWoW32 folder moved successfully.
C:\ProgramData\1925965306 moved successfully.
C:\ProgramData\580629930 moved successfully.
C:\ProgramData\sl1132078904 moved successfully.
========== FILES ==========
c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156\newupdate1142C.exe moved successfully.
c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156 folder moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
User: Steffen
->Temp folder emptied: 211566 bytes
->Temporary Internet Files folder emptied: 20703588 bytes
->Java cache emptied: 1568560 bytes
->FireFox cache emptied: 67359042 bytes
->Google Chrome cache emptied: 429100018 bytes
->Flash cache emptied: 279874 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 26324 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 495,00 mb
OTL by OldTimer - Version 3.2.3.0 log created on 05042010_101245
Files\Folders moved on Reboot…
Registry entries deleted on Reboot…