This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Check for computer problems

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A previous topic of mine was recently closed. Therefore I would like to hear if there are any problems with my computer, since I didn't find out. I have attached logs from five different programs, which I was instructed to in my previous topic.

GMER log:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-30 15:10:21
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\Steffen\AppData\Local\Temp\kwddrfob.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Dynamisk WDF/Microsoft Corporation)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0021860bd92f
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xE6 0x22 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xAD 0x0B 0xA6 0xE1 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x40 0x66 0xCA 0x20 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x7F 0x24 0xD5 0xFC …
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0021860bd92f (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xE6 0x22 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xAD 0x0B 0xA6 0xE1 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x40 0x66 0xCA 0x20 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x7F 0x24 0xD5 0xFC …

—- EOF - GMER 1.0.15 —-



Malwarebytes' Anti-Malware log:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4054

Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

30-04-2010 16:41:32
mbam-log-2010-04-30 (16-41-32).txt

Skanningstype: Hurtig skanning
Objekter skannet: 125351
Tid gået: 9 minut(ter), 2 sekund(er)

Hukommelses Processorer Inficeret: 0
Hukommelses Moduler Inficeret: 0
Registreringsdatabasenøgler Inficeret: 4
Registreringsdatabaseværdier Inficeret: 0
Registreringsdatabasedata Objekter Inficeret: 0
Inficerede Mapper: 0
Inficerede Filer: 3

Hukommelses Processorer Inficeret:
(Ingen skadelige objekter blev fundet)

Hukommelses Moduler Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabasenøgler Inficeret:
HKEY_CURRENT_USER\Software\YVIBBBHA8C (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\QZAIB7KITK (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registreringsdatabaseværdier Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabasedata Objekter Inficeret:
(Ingen skadelige objekter blev fundet)

Inficerede Mapper:
(Ingen skadelige objekter blev fundet)

Inficerede Filer:
C:\Users\Steffen\AppData\Local\temp\amowcxsren.exe (Adware.AdRotator) -> Quarantined and deleted successfully.
C:\Users\Steffen\AppData\Local\temp\stp4cf45.exe (Trojan.FraudTool) -> Quarantined and deleted successfully.
C:\Users\Steffen\AppData\Local\temp\Vlz.exe (Trojan.Fraudpack) -> Quarantined and deleted successfully.


Combofix log

ComboFix 10-05-01.01 - Steffen 01-05-2010 19:52:45.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.45.1030.18.3070.2024 [GMT 2:00]
Kører fra: c:\users\Steffen\Desktop\ComboFix.exe
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((( Filer skabt fra 2010-04-01 til 2010-05-01 )))))))))))))))))))))))))))))))))))
.

2010-05-01 18:10 . 2010-05-01 18:11 ——– d—–w- c:\users\Steffen\AppData\Local\temp
2010-05-01 18:10 . 2010-05-01 18:10 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-05-01 18:10 . 2010-05-01 18:10 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-04-30 14:25 . 2010-04-30 14:25 6153352 —-a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-04-29 22:11 . 2010-04-29 22:11 ——– d—–w- c:\program files\Foosball
2010-04-29 22:09 . 2010-04-29 22:09 ——– d—–w- c:\program files\Rats!
2010-04-27 06:25 . 2010-04-27 06:25 563712 —-a-w- c:\program files\OTL.exe
2010-04-26 09:40 . 2010-04-26 09:40 388096 —-a-r- c:\users\Steffen\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-04-25 18:49 . 2010-04-25 18:49 730624 —-a-w- c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156\newupdate1142C.exe
2010-04-25 18:49 . 2010-04-25 18:49 ——– d—–w- c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156
2010-04-23 06:32 . 2006-12-14 08:00 110592 —-a-w- c:\users\Steffen\AppData\Roaming\U3\temp\cleanup.exe
2010-04-23 06:31 . 2007-02-12 15:46 3096576 —ha-w- c:\users\Steffen\AppData\Roaming\U3\temp\Launchpad Removal.exe
2010-04-23 06:31 . 2010-04-23 06:32 ——– d—–w- c:\users\Steffen\AppData\Roaming\U3
2010-04-22 05:23 . 2010-04-22 05:23 ——– d—–w- c:\users\Steffen\AppData\Local\Adobe
2010-04-19 19:46 . 2010-04-19 19:46 ——– d—–w- c:\users\Steffen\AppData\Roaming\Malwarebytes
2010-04-19 19:46 . 2010-04-29 13:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-19 19:46 . 2010-04-19 19:46 ——– d—–w- c:\programdata\Malwarebytes
2010-04-19 19:46 . 2010-04-30 14:29 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-19 19:46 . 2010-04-29 13:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-18 11:14 . 2010-04-18 23:09 ——– d—–w- c:\program files\Musikprogrammer
2010-04-18 10:39 . 2010-04-18 10:39 ——– d—–w- c:\program files\Trend Micro
2010-04-15 15:30 . 2010-04-15 15:30 ——– d—–w- c:\programdata\{87784988-8668-411D-B26A-0C946ED2BE3C}
2010-04-15 15:30 . 2009-03-31 16:02 575004 —-a-w- c:\programdata\{87784988-8668-411D-B26A-0C946ED2BE3C}\mia.dll
2010-04-15 15:30 . 2009-03-31 16:02 2131640 —-a-w- c:\programdata\{87784988-8668-411D-B26A-0C946ED2BE3C}\printer og drev (sct. knuds gymnasium).exe
2010-04-15 15:30 . 2010-04-15 15:30 ——– d—–w- c:\program files\Skoleprinter
2010-04-15 10:12 . 2010-04-15 10:12 ——– d—–w- c:\program files\Grafværktøj
2010-04-15 10:11 . 1999-03-23 06:12 299520 —-a-w- c:\windows\uninst.exe
2010-04-14 05:23 . 2010-03-04 17:33 430080 —-a-w- c:\windows\system32\vbscript.dll
2010-04-14 05:23 . 2010-02-23 11:10 79360 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-14 05:23 . 2010-02-23 11:10 212992 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-14 05:23 . 2010-02-23 11:10 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-14 05:23 . 2010-02-18 14:07 3600776 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-14 05:23 . 2010-02-18 14:07 3548040 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-04-14 05:22 . 2009-12-23 11:33 172032 —-a-w- c:\windows\system32\wintrust.dll
2010-04-14 05:22 . 2010-02-18 14:07 904576 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-14 05:22 . 2010-02-18 13:30 200704 —-a-w- c:\windows\system32\iphlpsvc.dll
2010-04-14 05:22 . 2010-02-18 11:28 25088 —-a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-14 05:19 . 2010-01-13 17:34 98304 —-a-w- c:\windows\system32\cabview.dll
2010-04-11 14:18 . 2010-04-11 14:19 ——– d—–w- C:\a0c698d600d463d0cf
2010-04-09 10:59 . 2010-04-19 14:06 ——– d-sh–w- c:\programdata\SysWoW32
2010-04-09 10:58 . 2010-04-09 10:58 203776 –sh–w- c:\programdata\unrar.exe
2010-04-05 15:47 . 2010-04-05 15:47 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-04-05 15:43 . 2010-04-05 22:16 ——– d—–w- c:\programdata\Lavasoft
2010-04-05 15:43 . 2010-04-05 15:44 ——– d—–w- c:\program files\Lavasoft
2010-04-02 21:14 . 2010-04-02 21:15 ——– d—–w- c:\program files\GIMP-2.0
2010-04-02 21:12 . 2010-04-02 21:12 ——– d—–w- c:\program files\Common Files\GTK
2010-04-02 15:52 . 2010-03-29 07:59 52224 —-a-w- c:\users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
2010-04-02 15:52 . 2010-03-29 07:59 101376 —-a-w- c:\users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-01 17:43 . 2008-12-26 20:54 32061 —-a-w- c:\programdata\nvModes.dat
2010-05-01 10:18 . 2008-05-21 04:08 12 —-a-w- c:\windows\bthservsdp.dat
2010-05-01 10:15 . 2008-02-26 01:47 82814 —-a-w- c:\windows\system32\perfc006.dat
2010-05-01 10:15 . 2008-02-26 01:47 479574 —-a-w- c:\windows\system32\perfh006.dat
2010-04-28 16:17 . 2010-04-28 16:17 78808 —-a-w- c:\program files\Extras.Txt
2010-04-28 16:16 . 2010-04-28 16:16 110164 —-a-w- c:\program files\OTL.Txt
2010-04-19 07:54 . 2009-07-10 09:44 ——– d—–w- c:\program files\Microsoft Silverlight
2010-04-18 23:05 . 2009-08-03 10:44 ——– d—–w- c:\users\Steffen\AppData\Roaming\vlc
2010-04-18 21:12 . 2008-11-26 20:05 ——– d—–w- c:\users\Steffen\AppData\Roaming\LimeWire
2010-04-17 20:55 . 2009-12-27 11:58 ——– d—–w- c:\program files\Google
2010-04-15 10:12 . 2010-04-15 10:12 ——– d—–w- c:\program files\Grafværktøj
2010-04-14 06:08 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-04-14 05:36 . 2008-10-27 17:38 ——– d—–w- c:\programdata\Microsoft Help
2010-04-09 10:46 . 2008-11-26 20:04 ——– d—–w- c:\program files\LimeWire
2010-04-02 11:55 . 2010-03-28 17:47 ——– d—–w- c:\users\Steffen\AppData\Roaming\uTorrent
2010-03-28 17:50 . 2010-03-28 17:50 ——– d—–w- c:\program files\uTorrent
2010-03-26 16:25 . 2008-05-21 04:35 ——– d—–w- c:\programdata\NVIDIA
2010-03-26 10:31 . 2008-10-10 11:44 ——– d—–w- c:\program files\CCleaner
2010-03-19 16:35 . 2010-03-08 19:34 439816 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\setup.exe
2010-03-19 16:35 . 2010-03-19 16:35 5971968 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\chr\ChromeInstaller.exe
2010-03-19 16:34 . 2010-03-19 16:34 79368 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\vista.exe
2010-03-19 16:34 . 2010-03-19 16:34 64000 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\gcapi_dll.dll
2010-03-19 16:34 . 2010-03-19 16:34 52288 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\gtapi.dll
2010-03-19 16:34 . 2010-03-19 16:34 50688 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\fftbapi.dll
2010-03-19 16:34 . 2010-03-19 16:34 118784 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\compat.dll
2010-03-19 16:34 . 2010-03-19 16:34 49152 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\CarboniteCompatibility.dll
2010-03-18 17:33 . 2010-03-18 17:27 ——– d—–w- c:\users\Steffen\AppData\Roaming\Teleca
2010-03-18 17:32 . 2010-03-18 17:32 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
2010-03-18 17:26 . 2010-03-18 17:26 ——– d—–w- c:\program files\Common Files\Teleca Shared
2010-03-18 17:26 . 2010-03-18 17:26 ——– d—–w- c:\programdata\HTC
2010-03-18 17:26 . 2010-03-18 17:26 ——– d—–w- c:\programdata\Teleca
2010-03-18 17:26 . 2010-03-18 17:24 ——– d—–w- c:\program files\HTC
2010-03-18 17:24 . 2010-03-18 17:24 ——– d—–w- c:\program files\Spirent Communications
2010-03-12 15:40 . 2010-03-12 15:39 ——– d—–w- c:\program files\Common Files\DVDVideoSoft
2010-03-12 15:39 . 2010-03-12 15:39 ——– d—–w- c:\program files\DVDVideoSoft
2010-03-12 15:31 . 2010-03-12 15:30 ——– d—–w- c:\program files\YouTube Downloader
2010-03-11 18:47 . 2010-03-11 18:47 444952 —-a-w- c:\windows\system32\wrap_oal.dll
2010-03-11 18:47 . 2010-03-11 18:47 109080 —-a-w- c:\windows\system32\OpenAL32.dll
2010-03-11 18:47 . 2010-03-11 18:47 ——– d—–w- c:\program files\OpenAL
2010-03-11 18:46 . 2010-03-11 18:46 ——– d—–w- c:\program files\Prodigium Game Studios
2010-03-11 07:17 . 2010-02-15 14:13 64164264 —-a-w- c:\users\Steffen\AppData\Roaming\Nokia\Ovi Suite\Software Updater\NokiaOviSuite2Installer.exe
2010-03-09 16:25 . 2010-04-01 15:39 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-03-09 15:42 . 2010-04-01 15:39 834048 —-a-w- c:\windows\system32\wininet.dll
2010-02-26 16:13 . 2010-03-16 16:35 17160 —-a-w- c:\windows\Help\OEM\scripts\HPHCDisableObject.exe
2010-02-24 19:55 . 2008-08-29 17:17 121072 —-a-w- c:\users\Steffen\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-24 08:16 . 2009-10-03 14:37 181632 ——w- c:\windows\system32\MpSigStub.exe
2010-02-22 18:16 . 2008-11-13 12:44 680 —-a-w- c:\users\Steffen\AppData\Local\d3d9caps.dat
2010-02-22 12:28 . 2010-03-09 09:47 1282824 —-a-w- c:\windows\Help\OEM\scripts\SamsungHDDFW1HC.exe
2010-02-20 23:06 . 2010-03-10 11:18 24064 —-a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:05 . 2010-03-10 11:17 30720 —-a-w- c:\windows\system32\httpapi.dll
2010-02-20 20:53 . 2010-03-10 11:17 411648 —-a-w- c:\windows\system32\drivers\http.sys
2010-02-12 10:32 . 2010-03-05 08:52 293376 —-a-w- c:\windows\system32\browserchoice.exe
2010-02-05 13:45 . 2010-02-05 13:45 72488 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-04 15:51 . 2010-03-09 09:47 49152 —-a-w- c:\windows\Help\OEM\scripts\Interop.TaskScheduler.dll
2008-02-26 02:57 . 2008-02-26 02:37 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2007-09-20 671744]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-10-03 13826664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~3\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Steffen^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Screen Clipper and Launcher til OneNote 2007.lnk]
path=c:\users\Steffen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Screen Clipper and Launcher til OneNote 2007.lnk
backup=c:\windows\pss\Screen Clipper and Launcher til OneNote 2007.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CamSpace]
2009-09-08 16:41 1404928 —-a-w- c:\program files\CamSpace\CamSpaceAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
2009-12-18 10:24 427328 —-a-w- c:\program files\DAEMON Tools Pro\DTProAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-19 07:33 125952 —-a-w- c:\windows\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2010-02-21 20:45 30192 —-a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-09-28 17:45 133104 —-atw- c:\users\Steffen\AppData\Local\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 09:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
2008-10-09 05:58 75008 —-a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 14:24 54840 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-01-22 18:16 141608 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2007-08-23 15:36 455968 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-04-29 13:39 1090952 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mobile Connectivity Suite]
2009-11-19 15:19 598016 —-a-r- c:\program files\HTC\HTC Sync\Application Launcher\Application Launcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2009-10-03 10:40 13826664 —-a-w- c:\windows\System32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2009-10-03 10:40 92776 —-a-w- c:\windows\System32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OnScreenDisplay]
2007-09-04 20:54 554320 —-a-w- c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2007-10-01 02:34 181544 —-a-w- c:\program files\HP\QuickPlay\QPService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 22:08 417792 —-a-w- c:\program files\QuickTime & Real Alternative\QuickTime Alternative\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-07-31 13:23 149280 —-a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-02-15 18:12 198160 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
2007-08-17 06:13 218408 ——w- c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WAWifiMessage]
2007-01-08 23:53 311296 —-a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-07-01 16:37 37888 —-a-w- c:\program files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-19 07:33 202240 —-a-w- c:\program files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(:8d,99,72,53,18,00,ca,01

R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-01-23 691696]
R2 appdrvrem01;Application Driver Auto Removal Service (01);c:\windows\System32\appdrvrem01.exe svc [x]
R2 gupdate;Tjenesten Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-12-27 133104]
R3 GoogleDesktopManager-110309-193829;Google Desktop-administrator 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-02-21 30192]
R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-06-10 24576]
S1 appdrv01;Application Driver (01);c:\windows\system32\Drivers\appdrv01.sys [2009-07-19 2915944]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2009-12-02 42368]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 15:34 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Indhold af mappen 'Planlagte Opgaver'

2010-05-01 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-27 05:56]

2010-05-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-27 11:59]

2010-05-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-27 11:59]

2010-04-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-142386170-2914611657-1622844314-1000Core.job
- c:\users\Steffen\AppData\Local\Google\Update\GoogleUpdate.exe [2009-09-28 17:45]

2010-05-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-142386170-2914611657-1622844314-1000UA.job
- c:\users\Steffen\AppData\Local\Google\Update\GoogleUpdate.exe [2009-09-28 17:45]

2010-04-06 c:\windows\Tasks\HPCeeScheduleForSteffen.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-02-26 19:58]
.
.
——- Yderligere scanning ——-
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_dk&c=81&bd=Pavilion&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_dk&c=81&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send billede til &Bluetooth-enhed… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send siden til &Bluetooth-enhed… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: danskebank.dk
DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} - hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
FF - ProfilePath - c:\users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\s0kfb21q.default\
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\program files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\components\FirefoxExtension.dll
FF - component: c:\users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
FF - component: c:\users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLITIKKER —-
c:\program files\Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-01 20:11
Windows 6.0.6002 Service Pack 2 NTFS

scanner skjulte processer …

scanner skjulte autostarter …

scanner skjulte filer …


c:\users\Steffen\AppData\Local\Temp\catchme.dll 53248 bytes executable

scanning gennemført med succes
skjulte filer: 1

**************************************************************************
.
——————— LÅSTE REGISTRERINGS NØGLER ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs startet under kørende Processer ———————

- - - - - - - > 'lsass.exe'(696)
c:\windows\system32\DPPWDFLT.dll

- - - - - - - > 'Explorer.exe'(1728)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
c:\program files\MediaMonkey\DeskPlayer.dll
.
Gennemført tid: 2010-05-01 20:17:14
ComboFix-quarantined-files.txt 2010-05-01 18:17
ComboFix2.txt 2010-04-20 15:08

Pre-Kørsel: 64.812.265.472 byte ledig
Post-Kørsel: 64.842.977.280 byte ledig

- - End Of File - - FCCD9EFAC68644D9CFF46240FFB4956E



VirusTotal


Searched for following file: C:\ProgramData\1925965306

File 1925965306 received on 2010.05.02 11:43:19 (UTC)
Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.05.02 -
AhnLab-V3 2010.05.02.00 2010.05.01 -
AntiVir 8.2.1.224 2010.04.30 -
Antiy-AVL 2.0.3.7 2010.04.30 -
Authentium 5.2.0.5 2010.05.01 -
Avast 4.8.1351.0 2010.05.02 -
Avast5 5.0.332.0 2010.05.02 -
AVG 9.0.0.787 2010.05.02 -
BitDefender 7.2 2010.05.02 -
CAT-QuickHeal 10.00 2010.05.01 -
ClamAV 0.96.0.3-git 2010.05.02 -
Comodo 4739 2010.05.02 -
DrWeb 5.0.2.03300 2010.05.02 -
eSafe 7.0.17.0 2010.04.29 -
eTrust-Vet 35.2.7462 2010.04.30 -
F-Prot 4.5.1.85 2010.05.01 -
F-Secure 9.0.15370.0 2010.05.02 -
Fortinet 4.0.14.0 2010.05.01 -
GData 21 2010.05.02 -
Ikarus T3.1.1.80.0 2010.05.02 -
Jiangmin 13.0.900 2010.05.02 -
Kaspersky 7.0.0.125 2010.05.02 -
McAfee 5.400.0.1158 2010.05.02 -
McAfee-GW-Edition 6.8.5 2010.05.01 -
Microsoft 1.5703 2010.05.02 -
NOD32 5079 2010.05.02 -
Norman 6.04.12 2010.05.01 -
nProtect 2010-05-02.01 2010.05.02 -
Panda 10.0.2.7 2010.05.01 -
PCTools 7.0.3.5 2010.05.02 -
Prevx 3.0 2010.05.02 -
Rising 22.45.04.03 2010.04.30 -
Sophos 4.53.0 2010.05.02 -
Sunbelt 6249 2010.05.02 -
Symantec 20091.2.0.41 2010.05.02 -
TheHacker 6.5.2.0.275 2010.05.02 -
TrendMicro 9.120.0.1004 2010.05.01 -
TrendMicro-HouseCall 9.120.0.1004 2010.05.02 -
VBA32 3.12.12.4 2010.04.30 -
ViRobot 2010.5.1.2299 2010.05.02 -
VirusBuster 5.0.27.0 2010.05.01 -
Additional information
File size: 817 bytes
MD5…: 672c1e7e48e2884aadf5a1007d4eadfc
SHA1..: 6199b1c92cbcdcd95a8b0d7540f8dc02d910d454
SHA256: 3db65629d26f99c9e67b64ef561ede0a484facf5d1726caf2f1d86ade01a7a84
ssdeep: 12:5ZEbTKLz+eSG9vh3J9nJQoiSu5n9W8UFlRRVPPPjIhO0cuE:3EbTC+CX9JQb/
U3RRNIhO0cn

PEiD..: -
PEInfo: -
RDS…: NSRL Reference Data Set
-
pdfid.: -
trid..: MP3 audio (100.0%)
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned


Searched for following file: C:\ProgramData\580629930

File 580629930 received on 2010.05.02 11:40:54 (UTC)
Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.05.02 -
AhnLab-V3 2010.05.02.00 2010.05.01 -
AntiVir 8.2.1.224 2010.04.30 -
Antiy-AVL 2.0.3.7 2010.04.30 -
Authentium 5.2.0.5 2010.05.01 -
Avast 4.8.1351.0 2010.05.02 -
Avast5 5.0.332.0 2010.05.02 -
AVG 9.0.0.787 2010.05.02 -
BitDefender 7.2 2010.05.02 -
CAT-QuickHeal 10.00 2010.05.01 -
ClamAV 0.96.0.3-git 2010.05.02 -
Comodo 4739 2010.05.02 -
DrWeb 5.0.2.03300 2010.05.02 -
eSafe 7.0.17.0 2010.04.29 -
eTrust-Vet 35.2.7462 2010.04.30 -
F-Prot 4.5.1.85 2010.05.01 -
F-Secure 9.0.15370.0 2010.05.02 -
Fortinet 4.0.14.0 2010.05.01 -
GData 21 2010.05.02 -
Ikarus T3.1.1.80.0 2010.05.02 -
Jiangmin 13.0.900 2010.05.02 -
Kaspersky 7.0.0.125 2010.05.02 -
McAfee 5.400.0.1158 2010.05.02 -
McAfee-GW-Edition 6.8.5 2010.05.01 -
Microsoft 1.5703 2010.05.02 -
NOD32 5079 2010.05.02 -
Norman 6.04.12 2010.05.01 -
nProtect 2010-05-02.01 2010.05.02 -
Panda 10.0.2.7 2010.05.01 -
PCTools 7.0.3.5 2010.05.02 -
Prevx 3.0 2010.05.02 -
Rising 22.45.04.03 2010.04.30 -
Sophos 4.53.0 2010.05.02 -
Sunbelt 6249 2010.05.02 -
Symantec 20091.2.0.41 2010.05.02 -
TheHacker 6.5.2.0.275 2010.05.02 -
TrendMicro 9.120.0.1004 2010.05.01 -
TrendMicro-HouseCall 9.120.0.1004 2010.05.02 -
VBA32 3.12.12.4 2010.04.30 -
ViRobot 2010.5.1.2299 2010.05.02 -
VirusBuster 5.0.27.0 2010.05.01 -
Additional information
File size: 1023 bytes
MD5…: 5f65b01c59c8b3c331d1f8c058fb2d96
SHA1..: 9809dbf3a54085f85c1a18c25d0e4c1262568793
SHA256: 999e3d3ef27f2a9e7c3be6a1059f98f91aedbcda006955389c239751bf62cbaf
ssdeep: 12:JKAL/Oji16Q6jH3tr42NmNbfXr+Y6NLWreNfDMkwk08w69O8QS8/vNKjs:oDi
AQ6T3t8gQbfSppop8QS8nNKjs

PEiD..: -
PEInfo: -
RDS…: NSRL Reference Data Set
-
pdfid.: -
trid..: file seems to be plain text/ASCII (0.0%)
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned


Searched for following file: C:\ProgramData\sl1132078904

File sl1132078904 received on 2010.05.02 11:47:48 (UTC)
Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.05.02 -
AhnLab-V3 2010.05.02.00 2010.05.01 -
AntiVir 8.2.1.224 2010.04.30 -
Antiy-AVL 2.0.3.7 2010.04.30 -
Authentium 5.2.0.5 2010.05.01 -
Avast 4.8.1351.0 2010.05.02 -
Avast5 5.0.332.0 2010.05.02 -
AVG 9.0.0.787 2010.05.02 -
BitDefender 7.2 2010.05.02 -
CAT-QuickHeal 10.00 2010.05.01 -
ClamAV 0.96.0.3-git 2010.05.02 -
Comodo 4739 2010.05.02 -
DrWeb 5.0.2.03300 2010.05.02 -
eSafe 7.0.17.0 2010.04.29 -
eTrust-Vet 35.2.7462 2010.04.30 -
F-Prot 4.5.1.85 2010.05.01 -
F-Secure 9.0.15370.0 2010.05.02 -
Fortinet 4.0.14.0 2010.05.01 -
GData 21 2010.05.02 -
Ikarus T3.1.1.80.0 2010.05.02 -
Jiangmin 13.0.900 2010.05.02 -
Kaspersky 7.0.0.125 2010.05.02 -
McAfee 5.400.0.1158 2010.05.02 -
McAfee-GW-Edition 6.8.5 2010.05.01 -
Microsoft 1.5703 2010.05.02 -
NOD32 5079 2010.05.02 -
Norman 6.04.12 2010.05.01 -
nProtect 2010-05-02.01 2010.05.02 -
Panda 10.0.2.7 2010.05.01 -
PCTools 7.0.3.5 2010.05.02 -
Prevx 3.0 2010.05.02 -
Rising 22.45.04.03 2010.04.30 -
Sophos 4.53.0 2010.05.02 -
Sunbelt 6249 2010.05.02 -
Symantec 20091.2.0.41 2010.05.02 -
TheHacker 6.5.2.0.275 2010.05.02 -
TrendMicro 9.120.0.1004 2010.05.01 -
TrendMicro-HouseCall 9.120.0.1004 2010.05.02 -
VBA32 3.12.12.4 2010.04.30 -
ViRobot 2010.5.1.2299 2010.05.02 -
VirusBuster 5.0.27.0 2010.05.01 -
Additional information
File size: 113 bytes
MD5…: ca140f2455b62bcc84b95128a6ca05a4
SHA1..: 04f9ebf37742816dc3a4505633ec33ba333c7d3a
SHA256: 408722726b2023cd8bc54c8d12cec6db09c56ae78df1ab98cdaf77fbc92e50b4
ssdeep: 3:9eoxBuPv7+9uoxMJm7FyyvHnthv3vknvHnthSj:iXa9VI6vB

PEiD..: -
PEInfo: -
RDS…: NSRL Reference Data Set
-
pdfid.: -
trid..: Unknown!
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned




In the code box in OTL, i was instructed to write:

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
[2010-04-25 20:50:11 | 000,223,232 | -HS- | C] () – C:\Users\Steffen\AppData\Local\ave.exe
[2010-04-25 20:50:11 | 000,009,952 | -HS- | C] () – C:\Users\Steffen\AppData\Local\UJ0QRjYY
[2010-04-25 20:50:11 | 000,009,952 | -HS- | C] () – C:\ProgramData\UJ0QRjYY
[2010-04-09 12:59:07 | 000,000,000 | -HSD | C] – C:\ProgramData\SysWoW32
[2010-04-19 22:06:25 | 000,000,817 | —- | M] () – C:\ProgramData\1925965306
[2010-04-19 16:05:58 | 000,001,023 | -HS- | M] () – C:\ProgramData\580629930
[2010-04-09 12:59:07 | 000,000,113 | —- | M] () – C:\ProgramData\sl1132078904
:Files
c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156\newupdate1142C.exe
c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

After pressing Run Fix with the inserted code, this is the log I got out of it:

OTL log:

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
File C:\Users\Steffen\AppData\Local\ave.exe not found.
C:\Users\Steffen\AppData\Local\UJ0QRjYY moved successfully.
C:\ProgramData\UJ0QRjYY moved successfully.
C:\ProgramData\SysWoW32 folder moved successfully.
C:\ProgramData\1925965306 moved successfully.
C:\ProgramData\580629930 moved successfully.
C:\ProgramData\sl1132078904 moved successfully.
========== FILES ==========
c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156\newupdate1142C.exe moved successfully.
c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156 folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: Steffen
->Temp folder emptied: 211566 bytes
->Temporary Internet Files folder emptied: 20703588 bytes
->Java cache emptied: 1568560 bytes
->FireFox cache emptied: 67359042 bytes
->Google Chrome cache emptied: 429100018 bytes
->Flash cache emptied: 279874 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 26324 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 495,00 mb


OTL by OldTimer - Version 3.2.3.0 log created on 05042010_101245

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…
Welcome back Bro. Let's pick up where we left off in the last thread. We're almost there so just hang in there for a few more steps.

Please do a scan with Kaspersky Online Scanner
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
  • Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:
  • Text file [*.txt] Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply.
——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Thursday, May 13, 2010 Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, May 12, 2010 17:18:03 Records in database: 4100928 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Scan statistics: Objects scanned: 257472 Threats found: 3 Infected objects found: 3 Suspicious objects found: 0 Scan duration: 09:40:14 File name / Threat / Threats count C:\_OTL\MovedFiles\05042010_101245\C_ProgramData\SysWoW32\_u680640416v1 Infected: Trojan-Dropper.Win32.Agent.bxsi 1 C:\_OTL\MovedFiles\05042010_101245\C_ProgramData\SysWoW32\_u680640416v2 Infected: Trojan-Dropper.Win32.Agent.bxsj 1 C:\_OTL\MovedFiles\05042010_101245\C_ProgramData\SysWoW32\_u680640416v3 Infected: Trojan-Dropper.Win32.Agent.bxsl 1 Selected area has been scanned. The reason why i was hesitant to run this scan, is because of the scan duration. It's not a very user friendly scanner, since it takes 9.40 hours to scan…
Some scans can be quite lengthy, so I understand. I usually set long ones up to run overnight and then just grab the results in the morning.

The following will implement some cleanup procedures as well as reset System Restore points:
  • Click Start > Run
  • Now type Combofix /uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]


Now to remove most of the other tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.

If you notice any remaining tools or files you can delete them by right clicking and choosing delete.

If you ran DeFogger

To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.

Great job! Your logs appear to be malware free and you do not appear to be experiencing any malware related problems.
Please follow these simple steps in order to keep your computer malware free and secure:

Set a New Restore Point to prevent possible reinfection from an old one.
Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
* Go to Start > Programs > Accessories > System Tools
* Click "System Restore"
* Choose the radio button marked "Create a Restore Point" on the first screen then click "Next"
* Give the Restore Point a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
* Then go to Start > Run and type: Cleanmgr
* Click "OK"
* Click the "More Options" Tab.
* Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.

Visit Microsoft's Windows Update Site Frequently
It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Use and Update your Microsoft Security Essentals AntiVirus Software
It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall

Your log doesn't appear to show a third-party software firewall installed - if you have one, and I've missed it, please ignore this. I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this. Simply using a Firewall in its default configuration can lower your risk greatly.

If you are relying the firewall that comes with Windows, then you need to install one. While the Windows firewall is better than nothing, it doesn't monitor outgoing traffic, so anything malicious on your computer can 'phone home' at will. If you are using a wireless router that comes with a NAT hardware firewall, this also doesn't monitor outgoing connections.

Below are links to some free options:
Sunbelt Kerio OutPost
PC Tools Firewall Plus
Online Armor Free

After installing one of these, confirm your Windows Firewall is disabled by doing the following:
  • Click Start, click Run, type Firewall.cpl, and then click OK.
  • On the General tab, click Off (not recommended)
  • Click OK.

For a tutorial on Firewalls and a listing of some other available ones see the link below:
Understanding and Using Firewalls



Make your Internet Explorer more secure
This can be done by following these simple instructions:

1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click once on the Security tab
3. Click once on the Internet icon so it becomes highlighted.
4. Click once on the Custom Level button.

1. Change the Download signed ActiveX controls to Prompt
2. Change theDownload unsigned ActiveX controls to Disable
3. Change the Initialise and script ActiveX controls not marked as safe to Disable
4. Change the Installation of desktop items to Prompt
5. Change the Launching programs and files in an IFRAME to Prompt
6. Change the Navigate sub-frames across different domains to Prompt
7. When all these settings have been made, click on the OK button.
8. If it prompts you as to whether or not you want to save the settings, press the Yes button.

Next press the Apply button and then the OK to exit the Internet Properties page.

You should update your version of the Adobe Flash to the newest version:
You should update your version of the Sun Java Platform (JRE) to the newest version:
  • Download and install the latest version of Java
  • Next, remove all older versions of the Sun Java Platform using the Control Panel's Add/Remove Program feature (as they may contain security vulnerabilities).
Install SpywareBlaster
SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

The download and tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

Update and Run Malwarebytes Anti-Malware
Update and scan your computer with this program on a regular basis just as you would an antivirus software in conjunction with SuperAntiSpyware.

Install SUPERAntiSpyware Home Edition (free edition)
You should also scan your computer with this program on a regular basis just as you would an antivirus software in conjunction with Malwarebytes.

Perform an online virus scan
Every so often, also perform an online virus scan.
AntiVirus scanners use databases which are not identical, and one may find malware that another does not.

Some online scanners:
TrendMicro HouseCall: http://uk.trendmicro-europe.com/consumer/h…call_launch.php
Panda ActiveScan: http://www.pandasoftware.com/products/activescan.htm
Kaspersky Online Scanner (using Internet Explorer): http://www.kaspersky.com/virusscanner
BitDefender: http://www.bitdefender.com/scan8/

To simplify making sure you have the latest version of many of your security programs and applications, you may want to consider:
Secunia's Personal Software Inspector (PSI). It is a free utility that scans your computer for installed applications and checks to see if they have the latest security patches and updates. If it finds any applications with possible security issues, links and/or instructions are provided for the necessariy updates.

Filehippo's Update Checker. It is free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see if there are any newer releases. Available software updates are displayed and you can decide which ones to download and install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated from within the programs themselves. The Update Checker look for newer versions of the software program, not definition files.

Update all these programs regularly
Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Please also read Tony Klein's excellent article: How I got Infected in the First Place

Follow this list and your potential for being infected again will reduce dramatically.

Hopefully this should take care of your problems! Good luck & Happy surfing!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI