Hmmm - nu har jeg forsøgt mig 3. gang OG jeg HAR gjort som foreskevet (altså ligesom 2. gang)
Jeg trækker filen hen over ikonet til combofix.exe og programmet går i gang - se log nederst i dette indlæg.
MEN noget er sket siden jeg i går begyndte med ombofix.
Jeg kan ikke starte nogen som helst programmer - heller ikke malwarebytes
Jeg har forsøgt at tilgå kontrolpanelet - det har jeg kunnet da jeg afinstallerede min antivrus før 1. kørsel af combofix. Uanset hvilke programmer jeg forsøger at starte så får jeg beskeden:
“C:\Program Files\programnavn\navn.exe
Der blev forsøgt en ugyldig handling på en registreringsdatabasenøgle, som er blevet mærket til sletning”
Jeg kan slet ikke starte combofix ved at dobbeltklikke - KUN ved at trække CFScript.txt hen over den
LOG:
ComboFix 10-03-08.01 - Sanne & Lenike 09-03-2010 10:39:09.4.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.45.1030.18.3071.2070 [GMT 1:00]
Kører fra: c:\users\Sanne & Lenike\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((( Filer skabt fra 2010-02-09 til 2010-03-09 )))))))))))))))))))))))))))))))))))
.
2010-03-09 09:46 . 2010-03-09 09:46 ———— d——-w- c:\users\Public\AppData\Local\temp
2010-03-09 09:46 . 2010-03-09 09:46 ———— d——-w- c:\users\Default\AppData\Local\temp
2010-03-08 16:45 . 2010-01-07 15:07 38224 ——a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-08 16:45 . 2010-03-08 16:45 ———— d——-w- c:\program files\Malwarebytes’ Anti-Malware
2010-03-08 16:45 . 2010-01-07 15:07 19160 ——a-w- c:\windows\system32\drivers\mbam.sys
2010-03-07 20:34 . 2010-03-07 20:34 ———— d——-w- c:\users\Sanne & Lenike\AppData\Roaming\Malwarebytes
2010-03-07 20:34 . 2010-03-07 20:34 ———— d——-w- c:\programdata\Malwarebytes
2010-02-28 21:01 . 2010-02-28 21:45 ———— d——-w- c:\users\Sanne & Lenike\AppData\Roaming\LimeWire
2010-02-28 21:00 . 2010-02-28 21:00 ———— d——-w- c:\users\Sanne & Lenike\Shared
2010-02-28 20:59 . 2010-02-28 21:00 ———— d——-w- c:\program files\360Share Pro
2010-02-10 12:48 . 2009-12-11 11:43 302080 ——a-w- c:\windows\system32\drivers\srv.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-08 16:56 . 2008-05-12 19:38 ———— d——-w- c:\programdata\avg8
2010-03-08 14:24 . 2006-11-21 04:49 82592 ——a-w- c:\windows\system32\perfc006.dat
2010-03-08 14:24 . 2006-11-21 04:49 474454 ——a-w- c:\windows\system32\perfh006.dat
2010-02-28 21:49 . 2008-02-24 16:05 ———— d——-w- c:\users\Sanne & Lenike\AppData\Roaming\BitTorrent
2010-02-25 11:02 . 2008-02-12 17:01 99024 ——a-w- c:\users\Sanne & Lenike\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-24 08:16 . 2009-10-02 17:19 181632 ———w- c:\windows\system32\MpSigStub.exe
2010-02-11 07:36 . 2006-11-02 11:18 ———— d——-w- c:\program files\Windows Mail
2010-02-02 20:45 . 2009-10-16 09:07 ———— d——-w- c:\programdata\DVD Shrink
2010-01-27 08:22 . 2008-02-12 16:50 ———— d——-w- c:\program files\Google
2010-01-27 07:25 . 2010-01-27 07:25 509552 ——a-w- c:\programdata\Google\Google Toolbar\Update\gtbBE03.tmp.exe
2010-01-25 12:00 . 2010-02-24 17:33 471552 ——a-w- c:\windows\system32\secproc_isv.dll
2010-01-25 12:00 . 2010-02-24 17:33 152576 ——a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-25 12:00 . 2010-02-24 17:33 152064 ——a-w- c:\windows\system32\secproc_ssp.dll
2010-01-25 12:00 . 2010-02-24 17:33 471552 ——a-w- c:\windows\system32\secproc.dll
2010-01-25 11:58 . 2010-02-24 17:33 332288 ——a-w- c:\windows\system32\msdrm.dll
2010-01-25 08:21 . 2010-02-24 17:33 526336 ——a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-25 08:21 . 2010-02-24 17:33 346624 ——a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-25 08:21 . 2010-02-24 17:33 518144 ——a-w- c:\windows\system32\RMActivate.exe
2010-01-25 08:21 . 2010-02-24 17:33 347136 ——a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-23 09:26 . 2010-02-24 17:33 2048 ——a-w- c:\windows\system32\tzres.dll
2010-01-22 11:49 . 2010-01-22 11:49 ———— d——-w- c:\programdata\WindowsSearch
2010-01-22 06:14 . 2009-02-25 21:29 ———— d——-w- c:\program files\Microsoft Silverlight
2010-01-06 15:39 . 2010-02-24 17:33 1696256 ——a-w- c:\windows\system32\gameux.dll
2010-01-06 15:38 . 2010-02-24 17:33 28672 ——a-w- c:\windows\system32\Apphlpdm.dll
2010-01-06 15:38 . 2010-02-24 17:33 173056 ——a-w- c:\windows\AppPatch\AcXtrnal.dll
2010-01-06 15:38 . 2010-02-24 17:33 458752 ——a-w- c:\windows\AppPatch\AcSpecfc.dll
2010-01-06 15:38 . 2010-02-24 17:33 2159616 ——a-w- c:\windows\AppPatch\AcGenral.dll
2010-01-06 15:38 . 2010-02-24 17:33 542720 ——a-w- c:\windows\AppPatch\AcLayers.dll
2010-01-06 13:30 . 2010-02-24 17:33 4240384 ——a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-01-02 06:38 . 2010-01-22 07:01 916480 ——a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-22 07:01 109056 ——a-w- c:\windows\system32\iesysprep.dll
2010-01-02 06:32 . 2010-01-22 07:01 71680 ——a-w- c:\windows\system32\iesetup.dll
2010-01-02 04:57 . 2010-01-22 07:01 133632 ——a-w- c:\windows\system32\ieUnatt.exe
2009-12-19 19:20 . 2009-12-19 19:20 396552 ——a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-17 19:14 . 2009-12-17 19:14 79144 ——a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-12-11 11:43 . 2010-02-10 12:48 98816 ——a-w- c:\windows\system32\drivers\srvnet.sys
2007-11-14 20:27 . 2007-09-11 07:57 8192 —sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Sidebar”=“c:\program files\Windows Sidebar\sidebar.exe” [2009-04-11 1233920]
“ehTray.exe”=“c:\windows\ehome\ehTray.exe” [2008-01-19 125952]
“BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}”=“c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe” [2007-10-15 202024]
“swg”=“c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2009-05-23 39408]
“WMPNSCFG”=“c:\program files\Windows Media Player\WMPNSCFG.exe” [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Windows Defender”=“c:\program files\Windows Defender\MSASCui.exe” [2008-01-19 1008184]
“NeroFilterCheck”=“c:\program files\Common Files\Nero\Lib\NeroCheck.exe” [2007-03-01 153136]
“RtHDVCpl”=“RtHDVCpl.exe” [2007-11-14 4706304]
“Google Desktop Search”=“c:\program files\Google\Google Desktop Search\GoogleDesktop.exe” [2009-12-14 30192]
“HP Software Update”=“c:\program files\HP\HP Software Update\HPWuSchd2.exe” [2007-03-11 49152]
“Adobe Reader Speed Launcher”=“c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe” [2008-01-11 39792]
“hpqSRMon”=“c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe” [2008-06-02 81920]
“Skytel”=“Skytel.exe” [2007-10-11 1826816]
“NvSvc”=“c:\windows\system32\nvsvc.dll” [2007-12-14 86016]
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll” [2007-12-14 8530464]
“NvMediaCenter”=“c:\windows\system32\NvMcTray.dll” [2007-12-14 81920]
“SunJavaUpdateSched”=“c:\program files\Java\jre6\bin\jusched.exe” [2009-03-09 148888]
“QuickTime Task”=“c:\program files\QuickTime\QTTask.exe” [2009-11-10 417792]
“iTunesHelper”=“c:\program files\iTunes\iTunesHelper.exe” [2009-11-12 141600]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“EnableUIADesktopToggle”= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
“AppInit_DLLs”=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=“Service”
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
“VistaSp2”=hex(b):4b,82,9a,82,b0,4a,ca,01
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [x]
R2 gupdate;Tjenesten Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-01-27 135664]
R3 GoogleDesktopManager-110309-193829;Google Desktop-administrator 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2009-12-14 30192]
R3 SE31bus;Sony Ericsson Device 049 Driver driver (WDM);c:\windows\system32\DRIVERS\SE31bus.sys [2006-05-01 61600]
R3 SE31mdfl;Sony Ericsson Device 049 USB WMC Modem Filter;c:\windows\system32\DRIVERS\SE31mdfl.sys [2006-05-01 9360]
R3 SE31mdm;Sony Ericsson Device 049 USB WMC Modem Driver;c:\windows\system32\DRIVERS\SE31mdm.sys [2006-05-01 97184]
R3 SE31mgmt;Sony Ericsson Device 049 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\SE31mgmt.sys [2006-05-01 88688]
R3 se31nd5;Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (NDIS);c:\windows\system32\DRIVERS\se31nd5.sys [2006-05-01 18704]
R3 SE31obex;Sony Ericsson Device 049 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\SE31obex.sys [2006-05-01 86560]
R3 se31unic;Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (WDM);c:\windows\system32\DRIVERS\se31unic.sys [2006-05-01 90800]
R3 USBAAPL;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl.sys [2009-08-28 40448]
S1 RCFOX;SonicWALL IPsec Driver;c:\windows\system32\Drivers\RCFOX.sys [2007-09-27 101528]
S2 litsgt;litsgt;c:\windows\system32\DRIVERS\litsgt.sys [2008-02-18 137344]
S2 tansgt;tansgt;c:\windows\system32\DRIVERS\tansgt.sys [2008-02-18 12032]
S2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [2009-12-16 185640]
S3 3xHybrid;Philips SAA713x PCI Card;c:\windows\system32\DRIVERS\3xHybrid.sys [2007-08-22 1242976]
S3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28u.sys [2007-09-21 554496]
S3 rcvpn;SonicWALL VPN Adapter;c:\windows\system32\DRIVERS\rcvpn.sys [2005-11-08 24876]
S3 X10Hid;X10 Hid Device;c:\windows\system32\Drivers\x10hid.sys [2006-11-17 13976]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Indhold af mappen ‘Planlagte Opgaver’
2010-03-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-27 08:20]
2010-03-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-27 08:20]
.
.
———- Yderligere scanning———-
.
uStart Page = hxxp://www.google.dk/
mSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: E&ksporter; til Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki ... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
Trusted Zone: easycruit.com\dongenergy
DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} - hxxps://www.djs-netbank.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.30.cab
DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} - hxxp://as.photoprintit.de/ips-opdata/layout/default01/activex/IPSUploader.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-09 10:46
Windows 6.0.6002 Service Pack 2 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
——————————- LÅSTE REGISTRERINGS NØGLER——————————-
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
“BlindDial”=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
“BlindDial”=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
“BlindDial”=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
“BlindDial”=dword:00000000
.
Gennemført tid: 2010-03-09 10:47:36
ComboFix-quarantined-files.txt 2010-03-09 09:47
ComboFix2.txt 2010-03-09 06:53
ComboFix3.txt 2010-03-08 19:12
ComboFix4.txt 2010-03-08 17:46
Pre-Kørsel: 312.353.652.736 byte ledig
Post-Kørsel: 312.318.275.584 byte ledig
- - End Of File - - A542C5EC5660DC5CE7943C6F9C2EC81E