ComboFix 08-11-18.A2 - anam 11/19/2008 22:00:57.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.45.1030.18.1033 [GMT 1:00]
Kører fra: c:\users\anam\Desktop\Documents\??????\ComboFix.exe
* Dannede nyt systemgendannelsespunkt
.
/wow section - STAGE 1
Adgang nægtet.
((((((((((((((((((((((((((((( Filer skabt fra 2008-10-19 til 2008-11-19 )))))))))))))))))))))))))))))))))))
.
Ingen nye filer dannet i denne periode
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-19 20:40 --------- d---a-w c:\programdata\TEMP
2008-11-19 18:41 --------- d-----w c:\program files\Spyware Doctor
2008-11-19 18:16 --------- d-----w c:\programdata\Acronis
2008-11-18 23:42 --------- d-----w c:\programdata\Symantec
2008-11-18 22:13 971,232 ----a-w c:\windows\system32\drivers\tdrpm147.sys
2008-11-18 22:13 540,000 ----a-w c:\windows\system32\drivers\timntr.sys
2008-11-18 22:13 134,272 ----a-w c:\windows\system32\drivers\snman380.sys
2008-11-18 22:09 44,704 ----a-w c:\windows\system32\drivers\tifsfilt.sys
2008-11-18 22:08 --------- d-----w c:\program files\Common Files\Acronis
2008-11-18 22:08 --------- d-----w c:\program files\Acronis
2008-11-15 10:23 --------- d-----w c:\program files\Yahoo!
2008-11-12 13:10 --------- d-----w c:\users\anam\AppData\Roaming\PC Tools
2008-11-06 11:04 --------- d-----w c:\users\anam\AppData\Roaming\Windows Live Writer
2008-11-06 11:04 --------- d-----w c:\program files\Windows Live
2008-11-06 10:54 --------- d-----w c:\programdata\WLInstaller
2008-10-24 16:34 --------- d-----w c:\users\anam\AppData\Roaming\DesktopSMS
2008-10-21 20:24 --------- d-----w c:\programdata\Messenger Plus!
2008-10-21 16:49 --------- d-----w c:\program files\Messenger Plus! Live
2008-10-20 10:17 --------- d-----w c:\program files\Norton Internet Security
2008-10-19 18:24 805 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2008-10-19 18:24 123,952 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2008-10-19 18:24 10,671 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2008-10-19 18:24 --------- d-----w c:\program files\Symantec
2008-10-19 18:22 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-10-17 21:34 --------- d-----w c:\program files\Real
2008-10-17 21:34 --------- d-----w c:\program files\Common Files\xing shared
2008-10-17 21:34 --------- d-----w c:\program files\Common Files\Real
2008-10-17 21:33 --------- d-----w c:\program files\Google
2008-10-17 18:51 --------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller
2008-10-17 18:31 --------- d-----w c:\users\anam\AppData\Roaming\TOSHIBA
2008-10-17 18:22 --------- d-----w c:\users\anam\AppData\Roaming\ATI
2008-10-17 18:22 --------- d-----w c:\program files\Common Files\Toshiba Shared
2008-10-17 18:21 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-17 18:21 --------- d-----w c:\users\anam\AppData\Roaming\InstallShield
2008-10-17 18:21 --------- d-----w c:\program files\TOSHIBA
2008-10-17 18:19 --------- d-----w c:\programdata\ToshibaEurope
2008-10-17 18:15 --------- d-sh--w c:\programdata\Skrivebord
2008-10-17 18:15 --------- d-sh--w c:\programdata\Skabeloner
2008-10-17 18:15 --------- d-sh--w c:\programdata\Menuen Start
2008-10-17 18:15 --------- d-sh--w c:\programdata\Favoritter
2008-10-17 18:15 --------- d-sh--w c:\programdata\Dokumenter
2008-10-17 18:15 --------- d-sh--w c:\program files\Fælles filer
2008-10-17 18:10 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf
2008-10-17 18:10 --------- d-----w c:\program files\Synaptics
2008-10-17 18:09 0 --sha-r c:\windows\system32\drivers\TOSHIBA_Satellite P200D_06041-N5_PSPBQE-01S00.MRK
2008-10-17 18:06 --------- d-----w c:\program files\ATI Technologies
2008-10-17 18:05 --------- d-----w c:\program files\ATI
2008-10-03 12:14 39,984 ----a-w c:\windows\system32\drivers\symids.sys
2008-10-03 12:14 37,936 ----a-w c:\windows\system32\drivers\symndisv.sys
2008-10-03 12:14 27,696 ----a-w c:\windows\system32\drivers\symredrv.sys
2008-10-03 12:14 187,952 ----a-w c:\windows\system32\drivers\symtdi.sys
2008-10-03 12:14 146,096 ----a-w c:\windows\system32\drivers\symfw.sys
2008-10-03 12:14 12,848 ----a-w c:\windows\system32\drivers\symdns.sys
2008-10-03 12:14 10,804 ----a-w c:\windows\system32\drivers\SymRedir.cat
2008-10-03 12:14 1,358 ----a-w c:\windows\system32\drivers\SymRedir.inf
2008-09-16 20:12 222,488 ----a-w c:\windows\System32\snapapi.dll
2006-11-02 12:50 174 --sha-w c:\program files\desktop.ini
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [11/02/2006 01:35 PM 1196032]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [06/27/2007 12:28 PM 436088]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [10/18/2007 11:34 AM 5724184]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [10/17/2008 10:33 PM 120320]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [10/17/2008 10:33 PM 171448]
"WindowsWelcomeCenter"="oobefldr.dll" [11/02/2006 01:34 PM 2159104 c:\windows\System32\oobefldr.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [05/22/2007 10:50 AM 413696]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [03/29/2007 10:39 AM 411192]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [12/07/2006 04:49 PM 55416]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [04/03/2007 04:52 PM 509496]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [05/22/2007 04:32 PM 538744]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [11/06/2006 05:14 PM 34352]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [03/22/2006 08:42 PM 438272]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [01/09/2007 10:59 PM 115816]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [07/10/2007 09:24 AM 581632]
"Desktop SMS"="c:\program files\IDM\Desktop SMS\DesktopSMS.exe" [06/18/2007 10:51 AM 1507328]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [11/10/2006 12:35 PM 90112]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [06/08/2007 09:53 AM 894512]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaRegistration.exe" [05/04/2007 12:05 PM 571024]
"fssui"="c:\program files\Windows Live\Familiesikkerhed\fssui.exe" [10/17/2007 12:53 PM 243240]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [10/17/2008 10:34 PM 185872]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [01/29/2008 04:38 PM 583048]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [08/25/2008 12:36 PM 1168264]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [10/13/2008 12:00 PM 4344472]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [10/13/2008 12:22 PM 960376]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [10/13/2008 12:16 PM 165144]
"NDSTray.exe"="NDSTray.exe" [BU]
"RtHDVCpl"="RtHDVCpl.exe" [09/03/2007 05:39 PM 4702208 c:\windows\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\vio\dvacm.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{B5E64A05-A457-4AEB-B12B-1D9701DEEDB7}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{15AE34A4-8042-4AE4-8F5C-4545755FC6C0}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{5D665B96-A789-4815-A8C6-3272DEFD297A}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{264E9957-9EA9-4356-AE97-2EF8F3126074}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{E27D6692-2A1E-4098-AEFF-3EC2FF9DE46E}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{1762AA09-1623-48A8-AF83-497D052F84AC}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{FF8B10A7-42DD-4B99-B539-EB02AB870072}"= UDP:c:\program files\Microsoft Games\Solitaire\Solitaire.exe:7-kabale
"{57A74231-E7EF-45AE-BF92-2BC878190549}"= TCP:c:\program files\Microsoft Games\Solitaire\Solitaire.exe:7-kabale
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 AtiPcie;ATI PCI Express (3GIO) Filter;c:\windows\system32\DRIVERS\AtiPcie.sys [2007-09-10 7680]
R0 CplIR;Embedded IR Driver;c:\windows\system32\DRIVERS\CplIR.SYS [2007-03-06 14848]
R0 snapman380;Acronis Snapshots Manager (Build 380);c:\windows\system32\DRIVERS\snman380.sys [2008-11-18 134272]
R0 tdrpman147;Acronis Try&Decide and Restore Points filter (build 147);c:\windows\system32\DRIVERS\tdrpm147.sys [2008-11-18 971232]
R1 IDSvix86;Symantec Intrusion Prevention Driver;\??\c:\progra~2\Symantec\DEFINI~1\SymcData\idsdefs\20081118.001\IDSvix86.sys [2008-11-19 270384]
R2 fssfltr;FssFltr;c:\windows\system32\DRIVERS\fssfltr.sys [2008-10-17 43816]
R3 atikmdag;atikmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2007-10-08 2600960]
R3 SYMNDISV;SYMNDISV;c:\windows\system32\Drivers\SYMNDISV.SYS [2008-10-03 37936]
*Newly Created Service* - COMHOST
*Newly Created Service* - PROCEXP90
.
Indhold af mappen 'Planlagte Opgaver'
2008-11-10 c:\windows\Tasks\Norton Internet Security - Kør fuld systemskanning - anam.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [01/14/2007 02:09 AM]
.
- - - - TOMME GENVEJE FJERNET - - - -
HKLM-Run-HWSetup - \HWSetup.exe
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-19 22:05:09
Windows 6.0.6000 NTFS
detected NTDLL code modification:
ZwClose
scanner skjulte processer ...
scanner skjulte autostarter ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
TOSCDSPD = c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe?/i????????s????????????0???p?????
scanner skjulte filer ...
c:\users\anam\AppData\Local\Temp\~DF8EC2.tmp 393216 bytes
**************************************************************************
.
Gennemført tid: 11/19/2008 22:07:53
ComboFix-quarantined-files.txt 2008-11-19 21:07:49
Pre-Kørsel: 52,133,367,808 byte ledig
Post-Kørsel: 51,943,964,672 byte ledig
170