Kvikksølv Skrevet 25. desember 2008 Del Skrevet 25. desember 2008 (endret) Etter å ha hatt sikkerhetsproblemer med brukerkontoen min til WoW, bestemte jeg meg for å ta en skikkelig opprenskning på PC'n. Trend Micro fant ingen ting, SUPERANTI SPYWARE fant noen cookies, men Spybot S&D fant en trojaner som heter Win32.flux.fm. Fant en guide på Spybot sitt forum om hvordan man kan fjærne den manuelt (den dukker opp igjen etter hver scan), men finner ikke filene som guiden sier jeg skal slette. Kjørte også F-Secure sin online scan som også fant noen keyloggere ( het noe med gametheif) som også dukker oppigjen. Her er HJT logg: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:32:30, on 25.12.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16762) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe D:\Programfiler\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\nvsvc32.exe C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\System32\svchost.exe C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Programfiler\ANI\ANIWZCS2 Service\WZCSLDR2.exe D:\Programfiler\D-Link\D-Link Wireless N DWA-140\AirNCFG.exe C:\WINDOWS\System32\svchost.exe C:\Programfiler\Java\jre1.6.0_07\bin\jusched.exe C:\Programfiler\Fellesfiler\Logitech\QCDriver3\LVCOMS.EXE C:\WINDOWS\system32\ctfmon.exe C:\Programfiler\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe D:\Programfiler\DAEMON Tools\daemon.exe D:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe D:\Programfiler\Logitech\SetPoint\SetPoint.exe C:\Programfiler\Fellesfiler\Logishrd\KHAL2\KHALMNPR.EXE C:\Programfiler\Java\jre1.6.0_07\bin\jucheck.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\explorer.exe D:\Programfiler\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.no/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [pccguide.exe] "C:\Programfiler\Trend Micro\Internet Security 2007\pccguide.exe" O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [amd_dc_opt] C:\Programfiler\AMD\Dual-Core Optimizer\amd_dc_opt.exe O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Programfiler\ANI\ANIWZCS2 Service\WZCSLDR2.exe O4 - HKLM\..\Run: [D-Link D-Link Wireless N DWA-140] d:\Programfiler\D-Link\D-Link Wireless N DWA-140\AirNCFG.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [LVCOMS] C:\Programfiler\Fellesfiler\Logitech\QCDriver3\LVCOMS.EXE O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [OE] "C:\Programfiler\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe" O4 - HKCU\..\Run: [DAEMON Tools] "d:\Programfiler\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKCU\..\Run: [igndlm.exe] d:\Programfiler\Download Manager\DLM.exe /windowsstart /startifwork O4 - HKCU\..\Run: [sUPERAntiSpyware] D:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: Adobe Gamma.lnk = C:\Programfiler\Fellesfiler\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Logitech SetPoint.lnk = D:\Programfiler\Logitech\SetPoint\SetPoint.exe O4 - Global Startup: Microsoft Office.lnk = D:\Programfiler\Microsoft Office\Office\OSA9.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing) O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://a1540.g.akamai.net/7/1540/52/200705...ex/qtplugin.cab O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab3.cab O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1173478481781 O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1174028390703 O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_a...asyInstallX.CAB O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab O20 - Winlogon Notify: !SASWinLogon - D:\Programfiler\SUPERAntiSpyware\SASWINLO.DLL O23 - Service: 24F82B7C - Unknown owner - C:\WINDOWS\Fonts\14E750A0.EXE O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Programfiler\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Programfiler\Fellesfiler\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Programfiler\ANI\ANIWZCS2 Service\ANIWZCSdS.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod-tjeneste (iPod Service) - Unknown owner - C:\Programfiler\iPod\bin\iPodService.exe (file missing) O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Programfiler\Fellesfiler\Logishrd\Bluetooth\LBTServ.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe O23 - Service: Spionprogrambeskyttelse fra Trend Micro (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: ServiceLayer - Nokia. - C:\Programfiler\PC Connectivity Solution\ServiceLayer.exe O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe -- End of file - 8978 bytes Og her er Combifix log: ComboFix 08-12-24.01 - VKA 2008-12-25 15:12:47.3 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1044.18.2047.1329 [GMT 1:00] Kjører fra: c:\documents and settings\VKA\Mine dokumenter\ComboFix.exe . ((((((((((((((((((((((((((( Filer Opprettet Fra 2008-11-25 til 2008-12-25 ))))))))))))))))))))))))))))))))) . 2008-12-25 13:42 . 2008-12-25 13:42 dr-h----- c:\documents and settings\VKA\Siste 2008-12-24 21:36 . 2008-12-24 21:36 682,280 --a------ c:\windows\system32\pbsvc.exe 2008-12-24 06:28 . 2008-12-24 06:36 d-------- c:\windows\BDOSCAN8 2008-12-23 18:01 . 2008-12-23 18:01 d-------- c:\programfiler\Panda Security 2008-12-23 18:01 . 2008-06-19 17:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys 2008-12-23 17:14 . 2008-12-23 17:14 d-------- C:\fsaua.data 2008-12-23 16:27 . 2008-12-23 16:27 d-------- c:\programfiler\Malwarebytes' Anti-Malware 2008-12-23 16:27 . 2008-12-23 16:27 d-------- c:\documents and settings\VKA\Programdata\Malwarebytes 2008-12-23 16:27 . 2008-12-23 16:27 d-------- c:\documents and settings\All Users\Programdata\Malwarebytes 2008-12-23 16:27 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2008-12-23 16:27 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2008-12-23 15:43 . 2008-12-23 15:43 d--h----- c:\windows\system32\GroupPolicy 2008-12-22 18:55 . 2008-12-22 20:16 0 --a------ c:\windows\2.ini 2008-12-22 12:35 . 2008-12-22 12:36 d-------- c:\documents and settings\All Users\Programdata\Lavasoft 2008-12-22 10:57 . 2008-12-22 11:01 241 --a------ c:\windows\QSync.INI 2008-12-22 10:56 . 2008-12-22 11:01 d--h----- c:\windows\msdownld.tmp 2008-12-22 10:56 . 2008-12-22 10:56 d-------- c:\programfiler\Windows Media Components 2008-12-22 10:56 . 2008-12-22 10:57 d-------- c:\programfiler\Fellesfiler\Logitech 2008-12-22 10:56 . 2008-12-22 10:57 756 --a------ c:\windows\_delis32.ini 2008-12-22 10:53 . 2008-12-22 10:53 d-------- c:\programfiler\Logitech 2008-12-14 18:25 . 2008-12-23 10:38 33 --a------ c:\windows\1.ini 2008-12-14 17:44 . 2008-12-14 17:44 20 --a------ c:\windows\syscheck . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-25 13:17 36,864 ----a-w c:\windows\Fonts\B3349BD0.DLL 2008-12-25 11:31 202,000 ----a-w c:\windows\system32\PnkBstrB.exe 2008-12-25 11:31 139,280 ----a-w c:\windows\system32\drivers\PnkBstrK.sys 2008-12-25 00:04 --------- d-----w c:\documents and settings\VKA\Programdata\dvdcss 2008-12-24 20:37 22,328 ----a-w c:\documents and settings\VKA\Programdata\PnkBstrK.sys 2008-12-24 20:36 --------- d--h--w c:\programfiler\InstallShield Installation Information 2008-12-23 14:49 --------- d-----w c:\documents and settings\All Users\Programdata\Spybot - Search & Destroy 2008-12-22 20:34 66,872 ----a-w c:\windows\system32\PnkBstrA.exe 2008-12-22 11:35 --------- d-----w c:\programfiler\Fellesfiler\Wise Installation Wizard 2008-12-14 18:53 --------- d-----w c:\documents and settings\VKA\Programdata\OpenOffice.org2 2008-11-12 19:55 --------- d-----w c:\documents and settings\All Users\Programdata\TrackMania 2008-11-12 16:48 --------- d-----w c:\programfiler\Google 2008-11-07 12:20 --------- d-----w c:\programfiler\Western Digital 2008-11-07 12:19 --------- d-----w c:\programfiler\Western Digital Technologies 2008-11-04 20:35 --------- d-----w c:\documents and settings\VKA\Programdata\U3 2008-11-03 14:25 --------- d-----w c:\programfiler\Windows Live Safety Center 2008-10-27 17:21 30 ----a-w c:\documents and settings\VKA\jagex_runescape_preferences.dat 2008-10-25 15:43 --------- d-----w c:\documents and settings\VKA\Programdata\Leadertech 2008-10-23 13:01 283,648 ----a-w c:\windows\system32\gdi32.dll 2008-10-16 20:33 826,368 ----a-w c:\windows\system32\wininet.dll 2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll 2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll 2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll 2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll 2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll 2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe 2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll 2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll 2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll 2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll 2008-10-03 10:17 247,326 ----a-w c:\windows\system32\strmdll.dll 2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll . (((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret ))))))))))))))))))))))))))))))))))))))))))))) . . *Merk* tomme oppføringer & gyldige standardoppføringer vises ikke REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] "OE"="c:\programfiler\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe" [2006-09-27 315392] "DAEMON Tools"="d:\programfiler\DAEMON Tools\daemon.exe" [2006-11-12 157592] "igndlm.exe"="d:\programfiler\Download Manager\DLM.exe" [2007-03-05 1103480] "SUPERAntiSpyware"="d:\programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-12-22 1809648] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "pccguide.exe"="c:\programfiler\Trend Micro\Internet Security 2007\pccguide.exe" [2007-01-15 3112960] "Adobe Reader Speed Launcher"="c:\programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "amd_dc_opt"="c:\programfiler\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2007-07-23 77824] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016] "ANIWZCS2Service"="c:\programfiler\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152] "D-Link D-Link Wireless N DWA-140"="d:\programfiler\D-Link\D-Link Wireless N DWA-140\AirNCFG.exe" [2007-03-14 1388544] "SunJavaUpdateSched"="c:\programfiler\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784] "LVCOMS"="c:\programfiler\Fellesfiler\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 127022] "RTHDCPL"="RTHDCPL.EXE" [2007-04-05 c:\windows\RTHDCPL.exe] "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-11-29 c:\windows\KHALMNPR.Exe] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-11-29 c:\windows\KHALMNPR.Exe] "nwiz"="nwiz.exe" [2008-05-16 c:\windows\system32\nwiz.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360] c:\documents and settings\VKA\Start-meny\Programmer\Oppstart\ Adobe Gamma.lnk - c:\programfiler\Fellesfiler\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664] c:\documents and settings\All Users\Start-meny\Programmer\Oppstart\ Logitech SetPoint.lnk - d:\programfiler\Logitech\SetPoint\SetPoint.exe [2008-08-09 789008] Microsoft Office.lnk - d:\programfiler\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\programfiler\SUPERAntiSpyware\SASSEH.DLL" [2008-12-22 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 20:10 352256 d:\programfiler\SUPERAntiSpyware\SASWINLO.DLL [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn] 2008-01-09 11:30 72208 c:\programfiler\Fellesfiler\Logishrd\Bluetooth\LBTWLgn.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "d:\\Programfiler\\LimeWire\\LimeWire.exe"= "d:\\Programfiler\\World of Warcraft\\Launcher.exe"= "c:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Programfiler\\Windows Live\\Messenger\\livecall.exe"= "d:\\Programfiler\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "d:\\Programfiler\\Activision\\Call of Duty - World at War\\CoDWaW.exe"= "d:\\Programfiler\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"= R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-12-23 28544] R1 SASDIFSV;SASDIFSV;\??\d:\programfiler\SUPERAntiSpyware\SASDIFSV.SYS [2006-10-10 8944] R1 SASKUTIL;SASKUTIL;\??\d:\programfiler\SUPERAntiSpyware\SASKUTIL.sys [2007-02-27 55024] R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\TRENDM~1\INTERN~1\Tmntsrv.exe [2007-01-15 503808] R2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [2006-09-14 933952] R2 Tmpreflt;Tmpreflt;c:\windows\system32\drivers\Tmpreflt.sys [2006-08-16 36368] R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\TRENDM~1\INTERN~1\tmproxy.exe [2006-09-14 561223] R3 SASENUM;SASENUM;\??\d:\programfiler\SUPERAntiSpyware\SASENUM.SYS [2006-02-16 4096] R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\DRIVERS\TM_CFW.sys [2006-09-14 281600] S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys [2008-12-23 38496] S3 PciCon;PciCon;\??\D:\PciCon.sys [] S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\DRIVERS\rt2870.sys [2008-08-14 476416] S3 T5100_usb;LGE USB driver;c:\windows\system32\Drivers\T5100.sys [2007-05-22 29568] S3 XDva064;XDva064;\??\c:\windows\system32\XDva064.sys [] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs wowsystemcode123 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H] \Shell\AutoRun\command - H:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38e042ca-acc6-11dd-a627-00508d951983}] \Shell\AutoRun\command - h:\wd_windows_tools\WDSetup.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9898108a-76d9-11dd-a5d9-00508d951983}] \Shell\AutoRun\command - H:\LaunchU3.exe -a . . ------- Tilleggsskanning ------- . uStart Page = hxxp://www.google.no/ uSearchURL,(Default) = hxxp://www.google.com/keyword/%s c:\windows\Downloaded Program Files\sysreqlab3.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E} hxxp://www.srtest.com/srl_bin/sysreqlab3.cab c:\windows\Downloaded Program Files\SysReqLab3.osd FF - ProfilePath - c:\documents and settings\VKA\Programdata\Mozilla\Firefox\Profiles\ag6nuw2m.default\ FF - prefs.js: browser.search.selectedEngine - Wikipedia FF - prefs.js: browser.startup.homepage - hxxp://google.com . . ------- Filassosiasjoner ------- . JSEFile=NOTEPAD.EXE %1 VBEFile=NOTEPAD.EXE %1 VBSFile=NOTEPAD.EXE %1 . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-25 15:13:49 Windows 5.1.2600 Service Pack 2 NTFS skanner skjulte prosesser ... skanner skjulte autostart-oppføringer ... skanner skjulte filer ... skanning vellykket skjulte filer: 0 ************************************************************************** . --------------------- DLL'er Lastet Av Kjørende Prosesser --------------------- - - - - - - - > 'winlogon.exe'(1064) d:\programfiler\SUPERAntiSpyware\SASWINLO.DLL c:\programfiler\fellesfiler\logishrd\bluetooth\LBTWlgn.dll c:\programfiler\fellesfiler\logishrd\bluetooth\LBTServ.dll . Tidspunkt ferdig: 2008-12-25 15:16:52 ComboFix-quarantined-files.txt 2008-12-25 14:16:50 ComboFix2.txt 2008-12-25 13:28:40 ComboFix3.txt 2007-12-29 10:14:32 Pre-Run: 97 081 143 296 byte ledig Post-Run: 97,067,241,472 byte ledig 185 --- E O F --- 2008-12-25 10:59:29 Vil selvsagt bli kvitt disse før jeg logger inn på WoW-accounten igjen. All hjelp verdsettes til det fulle EDIT: skriveleif Endret 26. desember 2008 av Almeida Lenke til kommentar
r2d290 Skrevet 25. desember 2008 Del Skrevet 25. desember 2008 (endret) Ønsker at du kjører et scan til før vi fortsetter: Last ned Malwarebytes' Anti-Malware Her eller Her.''' Lagre den på Skrivebordet. Kjør fila og installer programmet. Velg Norsk språkdrakt. Sett en hake ved siden av Oppdater Malwarebytes' Anti-Malware og Kjør Malwarebytes' Anti-Malware, og trykk Ferdig.La programmet oppdatere seg og velg Utfør full systemskann. Du får en meldingsboks når programmet er ferdigkjørt Klikk deretter på Vis resultat-knappen. Hvis det er funnet malware, vil du nå se hva som er funnet. Klikk så på Fjern valgt -knappen for å fjerne malwaren som evt. ble funnet. Notis: Hvis MBAM finner en fil som er vanskelig å fjerne, vil du bli spurt om to spørsmål. Trykk OK på begge, og la MBAM gjøre seg ferdig med desinfeksjonen. Hvis du blir spurt om å restarte maskinen, gjør du det med en gang. Når MBAM er ferdig med å fjerne det den har funnet, vil det bli åpnet en logg i notisblokk. Den poster du hvis den finner annet enn cookies Hvis MBAM finner annet enn cookies, poster du også ny combofix-logg Forresten: Kan du fortelle nøyaktig adresse til filene som Spybot s&d og F-secure finner, så vet vi hva vi skal jobbe ut ifra. Endret 25. desember 2008 av r2d290 Lenke til kommentar
Kvikksølv Skrevet 26. desember 2008 Forfatter Del Skrevet 26. desember 2008 F-Secure online-scan fant: -Backdoor.Win32.Popwin.bzf (C:\WINDOWS\FONTS\B3349BD0.DLL) -Trojan-GameTheif.Win32.Magania ( står bare "System") MBAM scan logg: Malwarebytes' Anti-Malware 1.31 Databaseversjon: 1546 Windows 5.1.2600 Service Pack 2 26.12.2008 01:12:57 mbam-log-2008-12-26 (01-12-57).txt Skanntype: Full Skann (C:\|D:\|) Objekter skannet: 142169 Tid tilbakelagt: 1 hour(s), 46 minute(s), 50 second(s) Minneprosesser infisert: 0 Minnemoduler infisert: 0 Registernøkler infisert: 0 Registerverdier infisert: 0 Registerfiler infisert: 0 Mapper infisert: 0 Filer infisert: 0 Minneprosesser infisert: (Ingen mistenkelige filer funnet) Minnemoduler infisert: (Ingen mistenkelige filer funnet) Registernøkler infisert: (Ingen mistenkelige filer funnet) Registerverdier infisert: (Ingen mistenkelige filer funnet) Registerfiler infisert: (Ingen mistenkelige filer funnet) Mapper infisert: (Ingen mistenkelige filer funnet) Filer infisert: (Ingen mistenkelige filer funnet) Prøvde også å gå inn i sikkermodus, men da fikk jeg bluescreen før windows startet opp som sa at jeg måtte scanne pc'n for virus. Spybot S&D fant: Win32.Flux.fm: [sBI $7DB768C5] Settings (Registry value, fixed) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\ReportBootOk DoubleClick: Tracking cookie (Firefox: default) (Cookie, fixed) Tradedoubler: Tracking cookie (Firefox: default) (Cookie, fixed) Tradedoubler: Tracking cookie (Firefox: default) (Cookie, fixed) Lenke til kommentar
r2d290 Skrevet 26. desember 2008 Del Skrevet 26. desember 2008 Gå til http://virusscan.jotti.org , trykk på Browse, og last opp følgende fil til analyse: C:\WINDOWS\FONTS\B3349BD0.DLL Deretter trykker du på Submit. Godta at filen blir scannet. Til slutt kopierer du resultatet, og limer det inn i din neste post, så jeg kan se på den, og vurdere hva som må gjøres videre. Nå blir jeg borte noen timer... Lenke til kommentar
Kvikksølv Skrevet 26. desember 2008 Forfatter Del Skrevet 26. desember 2008 Fant ikke filen med Windows Explorer, måtte søke etter den og kopiere den til skrivebordet først. A-Squared Found Backdoor.Win32.Popwin!IK AntiVir Found TR/Spy.Gen ArcaVir Found nothing Avast Found Win32:Spyware-gen AVG Antivirus Found Downloader.Generic7.AFDF BitDefender Found Win32.Worm.Winko.I ClamAV Found nothing CPsecure Found BackDoor.W32.Agent.dwj Dr.Web Found nothing F-Prot Antivirus Found W32/Downloader.C.gen!Eldorado F-Secure Anti-Virus Found Backdoor.Win32.Popwin.bzf G DATA Found Win32:Spyware-gen Ikarus Found Backdoor.Win32.Popwin.bzf Kaspersky Anti-Virus Found Backdoor.Win32.Popwin.bzf NOD32 Found probably a variant of Win32/TrojanDownloader.Flux (probable variant) Norman Virus Control Found nothing Panda Antivirus Found Trj/Downloader.MDW Sophos Antivirus Found Mal/Behav-024 VirusBuster Found nothing VBA32 Found Backdoor.Win32.Popwin.bzf Lenke til kommentar
r2d290 Skrevet 26. desember 2008 Del Skrevet 26. desember 2008 Trykk Start - Alle Programmer - Tilbehør - Notisblokk Kopier og Lim inn teksten i kodeboksen nedenfor, inn i Notisblokken: File:: C:\WINDOWS\FONTS\B3349BD0.DLL SKRIVEBORDET\B3349BD0.dll (Bytt ut "SKRIVEBORDET" med adressen til skrivebordet, så fjerner man også den filen som du flyttet til skrivebordet. Alternativet er å slette den på vanlig måte (hvis det fungerer). Lagre det som CFScript på Skrivebordet Dra CFScript over ComboFix.exe som ligger på Skrivebordet, slik animasjonen nedenfor viser. Dette vil starte ComboFix igjen. Hvis maskinen ber om en omstart, lar du den gjøre det med én gang. Post innholdet til ComboFix.txt inn i ditt neste svar på forumet. Lenke til kommentar
Kvikksølv Skrevet 26. desember 2008 Forfatter Del Skrevet 26. desember 2008 ComboFix 08-12-26.02 - VKA 2008-12-26 21:47:25.4 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1044.18.2047.1305 [GMT 1:00] Kjører fra: c:\documents and settings\VKA\Mine dokumenter\ComboFix.exe Command switches brukt :: c:\documents and settings\VKA\Skrivebord\CFScript.txt AV: Trend Micro PC-cillin Internet Security 2007 *On-access scanning disabled* (Outdated) FW: Trend Micro PC-cillin Internet Security *disabled* FILE :: c:\windows\FONTS\B3349BD0.DLL . ((((((((((((((((((((((((((((((((((((((( Andre slettinger ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\FONTS\B3349BD0.DLL . ((((((((((((((((((((((((((( Filer Opprettet Fra 2008-11-26 til 2008-12-26 ))))))))))))))))))))))))))))))))) . 2008-12-26 13:24 . 2008-12-26 21:46 dr-h----- c:\documents and settings\VKA\Siste 2008-12-24 21:36 . 2008-12-24 21:36 682,280 --a------ c:\windows\system32\pbsvc.exe 2008-12-24 06:28 . 2008-12-24 06:36 d-------- c:\windows\BDOSCAN8 2008-12-23 18:01 . 2008-12-23 18:01 d-------- c:\programfiler\Panda Security 2008-12-23 18:01 . 2008-06-19 17:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys 2008-12-23 17:14 . 2008-12-23 17:14 d-------- C:\fsaua.data 2008-12-23 16:27 . 2008-12-23 16:27 d-------- c:\programfiler\Malwarebytes' Anti-Malware 2008-12-23 16:27 . 2008-12-23 16:27 d-------- c:\documents and settings\VKA\Programdata\Malwarebytes 2008-12-23 16:27 . 2008-12-23 16:27 d-------- c:\documents and settings\All Users\Programdata\Malwarebytes 2008-12-23 16:27 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2008-12-23 16:27 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2008-12-23 15:43 . 2008-12-23 15:43 d--h----- c:\windows\system32\GroupPolicy 2008-12-22 18:55 . 2008-12-22 20:16 0 --a------ c:\windows\2.ini 2008-12-22 12:35 . 2008-12-22 12:36 d-------- c:\documents and settings\All Users\Programdata\Lavasoft 2008-12-22 10:57 . 2008-12-22 11:01 241 --a------ c:\windows\QSync.INI 2008-12-22 10:56 . 2008-12-22 11:01 d--h----- c:\windows\msdownld.tmp 2008-12-22 10:56 . 2008-12-22 10:56 d-------- c:\programfiler\Windows Media Components 2008-12-22 10:56 . 2008-12-22 10:57 d-------- c:\programfiler\Fellesfiler\Logitech 2008-12-22 10:56 . 2008-12-22 10:57 756 --a------ c:\windows\_delis32.ini 2008-12-22 10:53 . 2008-12-22 10:53 d-------- c:\programfiler\Logitech 2008-12-14 18:25 . 2008-12-23 10:38 33 --a------ c:\windows\1.ini 2008-12-14 17:44 . 2008-12-14 17:44 20 --a------ c:\windows\syscheck . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-26 13:31 202,000 ----a-w c:\windows\system32\PnkBstrB.exe 2008-12-26 13:31 139,280 ----a-w c:\windows\system32\drivers\PnkBstrK.sys 2008-12-25 00:04 --------- d-----w c:\documents and settings\VKA\Programdata\dvdcss 2008-12-24 20:37 22,328 ----a-w c:\documents and settings\VKA\Programdata\PnkBstrK.sys 2008-12-24 20:36 --------- d--h--w c:\programfiler\InstallShield Installation Information 2008-12-23 14:49 --------- d-----w c:\documents and settings\All Users\Programdata\Spybot - Search & Destroy 2008-12-22 20:34 66,872 ----a-w c:\windows\system32\PnkBstrA.exe 2008-12-22 11:35 --------- d-----w c:\programfiler\Fellesfiler\Wise Installation Wizard 2008-12-14 18:53 --------- d-----w c:\documents and settings\VKA\Programdata\OpenOffice.org2 2008-11-12 19:55 --------- d-----w c:\documents and settings\All Users\Programdata\TrackMania 2008-11-12 16:48 --------- d-----w c:\programfiler\Google 2008-11-07 12:20 --------- d-----w c:\programfiler\Western Digital 2008-11-07 12:19 --------- d-----w c:\programfiler\Western Digital Technologies 2008-11-04 20:35 --------- d-----w c:\documents and settings\VKA\Programdata\U3 2008-11-03 14:25 --------- d-----w c:\programfiler\Windows Live Safety Center 2008-10-27 17:21 30 ----a-w c:\documents and settings\VKA\jagex_runescape_preferences.dat 2008-10-23 13:01 283,648 ----a-w c:\windows\system32\gdi32.dll 2008-10-16 20:33 826,368 ----a-w c:\windows\system32\wininet.dll 2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll 2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll 2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll 2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll 2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll 2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe 2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll 2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll 2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll 2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll 2008-10-03 10:17 247,326 ----a-w c:\windows\system32\strmdll.dll 2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll . (((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret ))))))))))))))))))))))))))))))))))))))))))))) . . *Merk* tomme oppføringer & gyldige standardoppføringer vises ikke REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] "OE"="c:\programfiler\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe" [2006-09-27 315392] "DAEMON Tools"="d:\programfiler\DAEMON Tools\daemon.exe" [2006-11-12 157592] "igndlm.exe"="d:\programfiler\Download Manager\DLM.exe" [2007-03-05 1103480] "SUPERAntiSpyware"="d:\programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-12-22 1809648] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "pccguide.exe"="c:\programfiler\Trend Micro\Internet Security 2007\pccguide.exe" [2007-01-15 3112960] "Adobe Reader Speed Launcher"="c:\programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "amd_dc_opt"="c:\programfiler\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2007-07-23 77824] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016] "ANIWZCS2Service"="c:\programfiler\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152] "D-Link D-Link Wireless N DWA-140"="d:\programfiler\D-Link\D-Link Wireless N DWA-140\AirNCFG.exe" [2007-03-14 1388544] "SunJavaUpdateSched"="c:\programfiler\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784] "LVCOMS"="c:\programfiler\Fellesfiler\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 127022] "RTHDCPL"="RTHDCPL.EXE" [2007-04-05 c:\windows\RTHDCPL.exe] "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-11-29 c:\windows\KHALMNPR.Exe] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-11-29 c:\windows\KHALMNPR.Exe] "nwiz"="nwiz.exe" [2008-05-16 c:\windows\system32\nwiz.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360] c:\documents and settings\VKA\Start-meny\Programmer\Oppstart\ Adobe Gamma.lnk - c:\programfiler\Fellesfiler\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664] c:\documents and settings\All Users\Start-meny\Programmer\Oppstart\ Logitech SetPoint.lnk - d:\programfiler\Logitech\SetPoint\SetPoint.exe [2008-08-09 789008] Microsoft Office.lnk - d:\programfiler\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\programfiler\SUPERAntiSpyware\SASSEH.DLL" [2008-12-22 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 20:10 352256 d:\programfiler\SUPERAntiSpyware\SASWINLO.DLL [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn] 2008-01-09 11:30 72208 c:\programfiler\Fellesfiler\Logishrd\Bluetooth\LBTWLgn.dll SafeBoot registernøkkel må repareres. Denne maskinen kan ikke startes i sikkerhetsmodus. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system] @="Driver Group" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}] @="DiskDrive" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}] @="Hdc" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}] @="Keyboard" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}] @="Mouse" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}] @="System" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] @="Volume" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "d:\\Programfiler\\LimeWire\\LimeWire.exe"= "d:\\Programfiler\\World of Warcraft\\Launcher.exe"= "c:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Programfiler\\Windows Live\\Messenger\\livecall.exe"= "d:\\Programfiler\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "d:\\Programfiler\\Activision\\Call of Duty - World at War\\CoDWaW.exe"= "d:\\Programfiler\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"= R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-12-23 28544] R1 SASDIFSV;SASDIFSV;\??\d:\programfiler\SUPERAntiSpyware\SASDIFSV.SYS [2006-10-10 8944] R1 SASKUTIL;SASKUTIL;\??\d:\programfiler\SUPERAntiSpyware\SASKUTIL.sys [2007-02-27 55024] R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\TRENDM~1\INTERN~1\Tmntsrv.exe [2007-01-15 503808] R2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [2006-09-14 933952] R2 Tmpreflt;Tmpreflt;c:\windows\system32\drivers\Tmpreflt.sys [2006-08-16 36368] R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\TRENDM~1\INTERN~1\tmproxy.exe [2006-09-14 561223] R3 SASENUM;SASENUM;\??\d:\programfiler\SUPERAntiSpyware\SASENUM.SYS [2006-02-16 4096] R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\DRIVERS\TM_CFW.sys [2006-09-14 281600] S3 PciCon;PciCon;\??\D:\PciCon.sys [] S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\DRIVERS\rt2870.sys [2008-08-14 476416] S3 T5100_usb;LGE USB driver;c:\windows\system32\Drivers\T5100.sys [2007-05-22 29568] S3 XDva064;XDva064;\??\c:\windows\system32\XDva064.sys [] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs wowsystemcode123 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H] \Shell\AutoRun\command - H:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38e042ca-acc6-11dd-a627-00508d951983}] \Shell\AutoRun\command - h:\wd_windows_tools\WDSetup.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9898108a-76d9-11dd-a5d9-00508d951983}] \Shell\AutoRun\command - H:\LaunchU3.exe -a . . ------- Tilleggsskanning ------- . uStart Page = hxxp://www.google.no/ uSearchURL,(Default) = hxxp://www.google.com/keyword/%s c:\windows\Downloaded Program Files\sysreqlab3.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E} hxxp://www.srtest.com/srl_bin/sysreqlab3.cab c:\windows\Downloaded Program Files\SysReqLab3.osd FF - ProfilePath - c:\documents and settings\VKA\Programdata\Mozilla\Firefox\Profiles\ag6nuw2m.default\ FF - prefs.js: browser.search.selectedEngine - Wikipedia FF - prefs.js: browser.startup.homepage - hxxp://google.com . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-26 21:48:57 Windows 5.1.2600 Service Pack 2 NTFS skanner skjulte prosesser ... skanner skjulte autostart-oppføringer ... skanner skjulte filer ... skanning vellykket skjulte filer: 0 ************************************************************************** . --------------------- DLL'er Lastet Av Kjørende Prosesser --------------------- - - - - - - - > 'winlogon.exe'(1060) d:\programfiler\SUPERAntiSpyware\SASWINLO.DLL c:\programfiler\fellesfiler\logishrd\bluetooth\LBTWlgn.dll c:\programfiler\fellesfiler\logishrd\bluetooth\LBTServ.dll . Tidspunkt ferdig: 2008-12-26 21:52:37 ComboFix-quarantined-files.txt 2008-12-26 20:52:33 ComboFix2.txt 2008-12-25 14:16:53 Pre-Run: 97 093 238 784 byte ledig Post-Run: 97,080,287,232 byte ledig 198 --- E O F --- 2008-12-26 14:45:44 Lenke til kommentar
r2d290 Skrevet 27. desember 2008 Del Skrevet 27. desember 2008 Trykk Start - Alle Programmer - Tilbehør - Notisblokk Kopier og Lim inn teksten i kodeboksen nedenfor, inn i Notisblokken: File:: c:\windows\2.ini c:\windows\1.ini Lagre det som CFScript på Skrivebordet Dra CFScript over ComboFix.exe som ligger på Skrivebordet, slik animasjonen nedenfor viser. Dette vil starte ComboFix igjen. Hvis maskinen ber om en omstart, lar du den gjøre det med én gang. Trenger ikke flere logger. Er det noen problemer med PC-en etter dette, eller er alt som det skal? Lenke til kommentar
Kvikksølv Skrevet 27. desember 2008 Forfatter Del Skrevet 27. desember 2008 F-Secure online scan fant fortsatt disse: Backdoor.Win32.Popwin.bzf Trojan-GameTheif.Win32.Magania Spybot S&D fant fortsatt Win32.flux.fm Altså, problemet er langt i fra fikset Lenke til kommentar
snippsat Skrevet 27. desember 2008 Del Skrevet 27. desember 2008 Kan du ta med korrekt plassering,av det f-scure,spybot finner. Dette er noe logger skal vise eller i gui til f-secure,spybot. Tenker da på eksp: c:\windows\system32\<navn på en fil> Lenke til kommentar
Kvikksølv Skrevet 27. desember 2008 Forfatter Del Skrevet 27. desember 2008 (endret) Dette står om Win32.flux.fm: Win32.Flux.fm: [sBI $7DB768C5] Settings (Registry value, fixed) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\ReportBootOk F-Secure loggen viser bare "System" men er ikke sikker på om dette er en path eller ikke. EDIT: F-Secure fant også; (etter jeg restarta pc'n) Backdoor.Win32.Popwin.bzf (C:\WINDOWS\FONTS\B3349BD0.DLL) Endret 27. desember 2008 av Almeida Lenke til kommentar
snippsat Skrevet 27. desember 2008 Del Skrevet 27. desember 2008 (endret) REGEDIT4 [-KEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\ReportBootOk] Kopiere tekst inne i kodebox,lim inn i notisblokk. Lagre på skrivebordet som Reportremove.reg Dobbelklikk svar ja til og legg inn i register. Start->kjør->regedit Bla deg fram og se om du finner disse nøkkler og slett dem. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_7FBDAFA3 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\7FBDAFA3 HKEY_CURRENT_USER\SYSTEM\CurrentControlSet\Services\7FBDAFA3 Last ned kjør CCleaner 'Valg'->'Avansert'. Fjern avkryssingen framfor: "bare slett midlertidige filer som er eldere enn 48 t. Kjør register-renser "svar ja til og reparere" --> backup svar ja når du blir spørt. Kjør register-renser et par ganger til alle feil er borte. Restart. http://rapidshare.com/files/177337957/Safe...XP-SP2.reg.html Last ned til skrivebordet dobbelklikk,svar ja til og legge inn i register. Backdoor.Win32.Popwin.bzf(C:\WINDOWS\FONTS\B3349BD0.DLL) Gå til den mappe og slett B3349BD0.DLL Ta en ny scan med f-Secure,oppdatere og kjøre en ny scan med MBAM. Spybot er jeg ikke så inntrisert hva finner,kan godt fjerne den og bruke MBAM som er en god del bedere. Endret 28. desember 2008 av SNIPPSAT Lenke til kommentar
Kvikksølv Skrevet 28. desember 2008 Forfatter Del Skrevet 28. desember 2008 Tror nok noe av poenget med din siste post forsvant mtp at jeg ikke fant nøkklene og når jeg prøvde å slette B3349BD0.DLL, sier windows at filen er i bruk. F-Secure fant fortsatt Backdoor.Win32.Popwin.bzf og Trojan-GameTheif.Win32.Magania MBAM fant ingen ting. Lenke til kommentar
norbat Skrevet 28. desember 2008 Del Skrevet 28. desember 2008 (endret) Hent Dr.Web, lagre det på skrivebordet. Kjør drweb-cureit.exe og klikk Start. Det kjøres nå en ekspresskann. Når dette er ferdig klikker du på Innstillinger -> Endre innstillinger Under fanearket Skann, fjerner du haken ved Heuristic analysis. Under fanearket Actions/Avgjørelser, skal alle punkt under Malware settes til Endre. Klikk OK Sett deretter merke framfor Full skann. Du starter skanningne ved å klikke på den 'grønne pila'. Velg "yes to all" når det finner noe for første gang. Når scanningen er ferdig, gå til "file" – Trykk på- "Save Report list". En fil med navn "drweb.csv" vil da ligge på skrivebordet. Den poster du sammen med en ny Combofix-logg (kjør altså combofix på nytt etter DrWeb) Endret 28. desember 2008 av norbat Lenke til kommentar
Kvikksølv Skrevet 28. desember 2008 Forfatter Del Skrevet 28. desember 2008 DrWeb: 14e750a0.exe;c:\windows\fonts;Sannsynligvis MULDROP.Trojan;; RegUBP2b-VKA.reg;C:\Documents and Settings\All Users\Programdata\Spybot - Search & Destroy\Snapshots2;Trojan.StartPage.1505;Slettet.; data002\32788R22FWJFW\psexec.cfexe;C:\Documents and Settings\VKA\Mine dokumenter\ComboFix.exe\data002;Program.PsExec.171;; data002;C:\Documents and Settings\VKA\Mine dokumenter\ComboFix.exe;Arkiv inneholder infiserte objekter;; ComboFix.exe;C:\Documents and Settings\VKA\Mine dokumenter;Arkiv inneholder infiserte objekter;Flyttet.; A0017612.exe;C:\System Volume Information\_restore{57461A0C-0E0E-4607-93D5-CC63ED06F863}\RP236;Trojan.Spambot.4099;Slettet.; A0036369.exe\20.6036.exe;C:\System Volume Information\_restore{57461A0C-0E0E-4607-93D5-CC63ED06F863}\RP405\A0036369.exe;Trojan.DownLoad.4257;; A0036369.exe;C:\System Volume Information\_restore{57461A0C-0E0E-4607-93D5-CC63ED06F863}\RP405;Arkiv inneholder infiserte objekter;Flyttet.; A0044800.EXE;C:\System Volume Information\_restore{57461A0C-0E0E-4607-93D5-CC63ED06F863}\RP885;Program.PsExec.170;Endret.; A0045391.reg;C:\System Volume Information\_restore{57461A0C-0E0E-4607-93D5-CC63ED06F863}\RP897;Trojan.StartPage.1505;Slettet.; A0036333.exe\20.6036.exe;D:\System Volume Information\_restore{57461A0C-0E0E-4607-93D5-CC63ED06F863}\RP405\A0036333.exe;Trojan.DownLoad.4257;; A0036333.exe;D:\System Volume Information\_restore{57461A0C-0E0E-4607-93D5-CC63ED06F863}\RP405;Arkiv inneholder infiserte objekter;Flyttet.; Combofix logg: ComboFix 08-12-26.03 - VKA 2008-12-28 19:30:48.6 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1044.18.2047.1319 [GMT 1:00] Kjører fra: c:\documents and settings\VKA\DoctorWeb\Quarantine\ComboFix.exe AV: Trend Micro PC-cillin Internet Security 2007 *On-access scanning disabled* (Outdated) FW: Trend Micro PC-cillin Internet Security *disabled* . ((((((((((((((((((((((((((( Filer Opprettet Fra 2008-11-28 til 2008-12-28 ))))))))))))))))))))))))))))))))) . 2008-12-27 17:43 . 2008-12-28 15:46 dr-h----- c:\documents and settings\VKA\Siste 2008-12-27 01:22 . 2008-12-27 01:22 d-------- c:\programfiler\Fellesfiler\PCSuite 2008-12-27 01:22 . 2008-12-27 01:22 d-------- c:\programfiler\Fellesfiler\Nokia 2008-12-24 21:36 . 2008-12-24 21:36 682,280 --a------ c:\windows\system32\pbsvc.exe 2008-12-24 06:28 . 2008-12-24 06:36 d-------- c:\windows\BDOSCAN8 2008-12-23 18:01 . 2008-12-23 18:01 d-------- c:\programfiler\Panda Security 2008-12-23 18:01 . 2008-06-19 17:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys 2008-12-23 17:14 . 2008-12-23 17:14 d-------- C:\fsaua.data 2008-12-23 16:27 . 2008-12-23 16:27 d-------- c:\programfiler\Malwarebytes' Anti-Malware 2008-12-23 16:27 . 2008-12-23 16:27 d-------- c:\documents and settings\VKA\Programdata\Malwarebytes 2008-12-23 16:27 . 2008-12-23 16:27 d-------- c:\documents and settings\All Users\Programdata\Malwarebytes 2008-12-23 16:27 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2008-12-23 16:27 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2008-12-23 15:43 . 2008-12-23 15:43 d--h----- c:\windows\system32\GroupPolicy 2008-12-22 12:35 . 2008-12-22 12:36 d-------- c:\documents and settings\All Users\Programdata\Lavasoft 2008-12-22 10:57 . 2008-12-22 11:01 241 --a------ c:\windows\QSync.INI 2008-12-22 10:56 . 2008-12-22 11:01 d--h----- c:\windows\msdownld.tmp 2008-12-22 10:56 . 2008-12-22 10:56 d-------- c:\programfiler\Windows Media Components 2008-12-22 10:56 . 2008-12-22 10:57 d-------- c:\programfiler\Fellesfiler\Logitech 2008-12-22 10:56 . 2008-12-22 10:57 756 --a------ c:\windows\_delis32.ini 2008-12-22 10:53 . 2008-12-22 10:53 d-------- c:\programfiler\Logitech 2008-12-14 17:44 . 2008-12-14 17:44 20 --a------ c:\windows\syscheck . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-28 15:10 139,280 ----a-w c:\windows\system32\drivers\PnkBstrK.sys 2008-12-28 15:09 202,000 ----a-w c:\windows\system32\PnkBstrB.exe 2008-12-28 14:57 36,864 ----a-w c:\windows\Fonts\B3349BD0.DLL 2008-12-27 01:23 --------- d-----w c:\documents and settings\VKA\Programdata\Nokia 2008-12-27 00:34 --------- d-----w c:\documents and settings\VKA\Programdata\PC Suite 2008-12-27 00:21 --------- d-----w c:\documents and settings\All Users\Programdata\Installations 2008-12-25 00:04 --------- d-----w c:\documents and settings\VKA\Programdata\dvdcss 2008-12-24 20:37 22,328 ----a-w c:\documents and settings\VKA\Programdata\PnkBstrK.sys 2008-12-24 20:36 --------- d--h--w c:\programfiler\InstallShield Installation Information 2008-12-23 14:49 --------- d-----w c:\documents and settings\All Users\Programdata\Spybot - Search & Destroy 2008-12-22 20:34 66,872 ----a-w c:\windows\system32\PnkBstrA.exe 2008-12-22 11:35 --------- d-----w c:\programfiler\Fellesfiler\Wise Installation Wizard 2008-12-14 18:53 --------- d-----w c:\documents and settings\VKA\Programdata\OpenOffice.org2 2008-11-12 19:55 --------- d-----w c:\documents and settings\All Users\Programdata\TrackMania 2008-11-12 16:48 --------- d-----w c:\programfiler\Google 2008-11-07 12:20 --------- d-----w c:\programfiler\Western Digital 2008-11-07 12:19 --------- d-----w c:\programfiler\Western Digital Technologies 2008-11-04 20:35 --------- d-----w c:\documents and settings\VKA\Programdata\U3 2008-11-03 14:25 --------- d-----w c:\programfiler\Windows Live Safety Center 2008-10-27 17:21 30 ----a-w c:\documents and settings\VKA\jagex_runescape_preferences.dat 2008-10-23 13:01 283,648 ----a-w c:\windows\system32\gdi32.dll 2008-10-16 20:33 826,368 ----a-w c:\windows\system32\wininet.dll 2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll 2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll 2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll 2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll 2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll 2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe 2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll 2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll 2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll 2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll 2008-10-03 10:17 247,326 ----a-w c:\windows\system32\strmdll.dll 2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll . ((((((((((((((((((((((((((((( snapshot@2008-12-26_21.49.29,95 ))))))))))))))))))))))))))))))))))))))))) . + 2008-12-27 00:22:33 3,262 ----a-r c:\windows\Installer\{11964613-805F-432D-A12B-169554B793E7}\ARPPRODUCTICON.exe + 2008-12-27 00:23:03 15,086 ----a-r c:\windows\Installer\{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}\ARPPRODUCTICON.exe + 2003-03-18 18:05:50 89,088 ----a-w c:\windows\system32\atl71.dll + 2007-03-29 22:00:40 203,264 ----a-r c:\windows\system32\CddbCdda.dll + 2007-02-22 10:15:56 137,216 -c--a-w c:\windows\system32\DRVSTORE\nmwcd_F3FA2468AF360A65811B287DD7A88CB715CF7275\nmwcd.sys + 2007-02-22 10:15:12 90,624 -c--a-w c:\windows\system32\DRVSTORE\nmwcd_F3FA2468AF360A65811B287DD7A88CB715CF7275\nmwcdcls.dll + 2007-02-22 10:15:12 65,536 -c--a-w c:\windows\system32\DRVSTORE\nmwcd_F3FA2468AF360A65811B287DD7A88CB715CF7275\nmwcdcocls.dll + 2007-02-22 10:15:14 8,320 -c--a-w c:\windows\system32\DRVSTORE\nmwcdc_F3FA2468AF360A65811B287DD7A88CB715CF7275\nmwcdc.sys + 2007-02-22 10:15:14 12,288 -c--a-w c:\windows\system32\DRVSTORE\nmwcdcj_F3FA2468AF360A65811B287DD7A88CB715CF7275\nmwcdcj.sys + 2007-02-22 10:15:14 12,288 -c--a-w c:\windows\system32\DRVSTORE\nmwcdm2k_F3FA2468AF360A65811B287DD7A88CB715CF7275\nmwcdcm.sys + 2003-03-18 20:20:00 1,060,864 ----a-w c:\windows\system32\mfc71.dll + 2003-03-18 20:12:12 1,047,552 ----a-w c:\windows\system32\mfc71u.dll + 2003-03-18 19:14:52 499,712 ----a-w c:\windows\system32\msvcp71.dll + 2003-02-21 03:42:22 348,160 ----a-w c:\windows\system32\msvcr71.dll - 2007-11-29 08:32:38 48,128 ----a-w c:\windows\system32\nmwcdcls.dll + 2007-02-22 10:15:12 90,624 ----a-w c:\windows\system32\nmwcdcls.dll . (((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret ))))))))))))))))))))))))))))))))))))))))))))) . . *Merk* tomme oppføringer & gyldige standardoppføringer vises ikke REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] "OE"="c:\programfiler\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe" [2006-09-27 315392] "DAEMON Tools"="d:\programfiler\DAEMON Tools\daemon.exe" [2006-11-12 157592] "igndlm.exe"="d:\programfiler\Download Manager\DLM.exe" [2007-03-05 1103480] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "pccguide.exe"="c:\programfiler\Trend Micro\Internet Security 2007\pccguide.exe" [2007-01-15 3112960] "Adobe Reader Speed Launcher"="c:\programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "amd_dc_opt"="c:\programfiler\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2007-07-23 77824] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016] "ANIWZCS2Service"="c:\programfiler\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152] "D-Link D-Link Wireless N DWA-140"="d:\programfiler\D-Link\D-Link Wireless N DWA-140\AirNCFG.exe" [2007-03-14 1388544] "SunJavaUpdateSched"="c:\programfiler\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784] "LVCOMS"="c:\programfiler\Fellesfiler\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 127022] "PCSuiteTrayApplication"="d:\programfiler\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 271360] "RTHDCPL"="RTHDCPL.EXE" [2007-04-05 c:\windows\RTHDCPL.exe] "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-11-29 c:\windows\KHALMNPR.Exe] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-11-29 c:\windows\KHALMNPR.Exe] "nwiz"="nwiz.exe" [2008-05-16 c:\windows\system32\nwiz.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360] "Nokia.PCSync"="d:\programfiler\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 1241088] c:\documents and settings\VKA\Start-meny\Programmer\Oppstart\ Adobe Gamma.lnk - c:\programfiler\Fellesfiler\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664] c:\documents and settings\All Users\Start-meny\Programmer\Oppstart\ Logitech SetPoint.lnk - d:\programfiler\Logitech\SetPoint\SetPoint.exe [2008-08-09 789008] Microsoft Office.lnk - d:\programfiler\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\programfiler\SUPERAntiSpyware\SASSEH.DLL" [2008-12-22 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 20:10 352256 d:\programfiler\SUPERAntiSpyware\SASWINLO.DLL [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn] 2008-01-09 11:30 72208 c:\programfiler\Fellesfiler\Logishrd\Bluetooth\LBTWLgn.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "d:\\Programfiler\\LimeWire\\LimeWire.exe"= "d:\\Programfiler\\World of Warcraft\\Launcher.exe"= "c:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Programfiler\\Windows Live\\Messenger\\livecall.exe"= "d:\\Programfiler\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "d:\\Programfiler\\Activision\\Call of Duty - World at War\\CoDWaW.exe"= "d:\\Programfiler\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"= R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-12-23 28544] R1 SASDIFSV;SASDIFSV;\??\d:\programfiler\SUPERAntiSpyware\SASDIFSV.SYS [2006-10-10 8944] R1 SASKUTIL;SASKUTIL;\??\d:\programfiler\SUPERAntiSpyware\SASKUTIL.sys [2007-02-27 55024] R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\TRENDM~1\INTERN~1\Tmntsrv.exe [2007-01-15 503808] R2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [2006-09-14 933952] R2 Tmpreflt;Tmpreflt;c:\windows\system32\drivers\Tmpreflt.sys [2006-08-16 36368] R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\TRENDM~1\INTERN~1\tmproxy.exe [2006-09-14 561223] R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\DRIVERS\TM_CFW.sys [2006-09-14 281600] S3 PciCon;PciCon;\??\D:\PciCon.sys [] S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\DRIVERS\rt2870.sys [2008-08-14 476416] S3 SASENUM;SASENUM;\??\d:\programfiler\SUPERAntiSpyware\SASENUM.SYS [2006-02-16 4096] S3 T5100_usb;LGE USB driver;c:\windows\system32\Drivers\T5100.sys [2007-05-22 29568] S3 XDva064;XDva064;\??\c:\windows\system32\XDva064.sys [] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs wowsystemcode123 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H] \Shell\AutoRun\command - H:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38e042ca-acc6-11dd-a627-00508d951983}] \Shell\AutoRun\command - h:\wd_windows_tools\WDSetup.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9898108a-76d9-11dd-a5d9-00508d951983}] \Shell\AutoRun\command - H:\LaunchU3.exe -a . . ------- Tilleggsskanning ------- . uStart Page = hxxp://www.google.no/ uSearchURL,(Default) = hxxp://www.google.com/keyword/%s c:\windows\Downloaded Program Files\sysreqlab3.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E} hxxp://www.srtest.com/srl_bin/sysreqlab3.cab c:\windows\Downloaded Program Files\SysReqLab3.osd FF - ProfilePath - c:\documents and settings\VKA\Programdata\Mozilla\Firefox\Profiles\ag6nuw2m.default\ FF - prefs.js: browser.search.selectedEngine - Wikipedia FF - prefs.js: browser.startup.homepage - hxxp://google.com . . ------- Filassosiasjoner ------- . JSEFile=NOTEPAD.EXE %1 VBEFile=NOTEPAD.EXE %1 VBSFile=NOTEPAD.EXE %1 . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-28 19:32:33 Windows 5.1.2600 Service Pack 2 NTFS skanner skjulte prosesser ... skanner skjulte autostart-oppføringer ... skanner skjulte filer ... skanning vellykket skjulte filer: 0 ************************************************************************** . --------------------- DLL'er Lastet Av Kjørende Prosesser --------------------- - - - - - - - > 'winlogon.exe'(1060) d:\programfiler\SUPERAntiSpyware\SASWINLO.DLL c:\programfiler\fellesfiler\logishrd\bluetooth\LBTWlgn.dll c:\programfiler\fellesfiler\logishrd\bluetooth\LBTServ.dll . Tidspunkt ferdig: 2008-12-28 19:36:10 ComboFix-quarantined-files.txt 2008-12-28 18:36:08 ComboFix2.txt 2008-12-27 01:43:24 ComboFix3.txt 2008-12-26 20:52:39 ComboFix4.txt 2008-12-25 14:16:53 Pre-Run: 96 725 659 648 byte ledig Post-Run: 96,845,529,088 byte ledig 209 --- E O F --- 2008-12-28 11:37:45 Lenke til kommentar
Kvikksølv Skrevet 29. desember 2008 Forfatter Del Skrevet 29. desember 2008 (endret) Da ser det ut som om vi er på rett vei . Kan nå starte PC'n i sikkermodus uten bluescreen og hverken F-secure eller Spybot fant noe. Kjører nå div scans i sikkermodus. Dersom dere ikke ser noen store trussler i loggene er vel problemet løst... Gir lyd fra meg hvis det dukker opp noe på scannene. Endret 29. desember 2008 av Almeida Lenke til kommentar
snippsat Skrevet 29. desember 2008 Del Skrevet 29. desember 2008 (endret) Ja noe som har blitt glemt,var med i første hjt-logg. Dukket opp igjen i dr.web "14e750a0.exe" Start->kjør->cmd Skriv inn fet tekst. Sc stop 24F82B7C sc delete 24F82B7C Gå til fonts og slett "14E750A0.EXE" Prøv igjen og slette "B3349BD0.DLL" Se også om det ligger flere dll-exe filer i fonts mappen. Skal stort sett bare være fonts-typer. Får du ikke slettet dem bruker du Killbox Da avslutter vi etter dette viss norbat ikke har noe og tillegge. Endret 29. desember 2008 av SNIPPSAT Lenke til kommentar
Kvikksølv Skrevet 29. desember 2008 Forfatter Del Skrevet 29. desember 2008 Fikk slettet "B3349BD0.DLL" men ikke "14E750A0.EXE". Når jeg skriver inn teksten i cmd står det "Tjenesten er ikke installert". Finner heller ikke filen med Killbox Lenke til kommentar
snippsat Skrevet 29. desember 2008 Del Skrevet 29. desember 2008 Kan tenkes at dr.web fjernet "14E750A0.EXE". Det kan være grunnen til at du fikk slette "B3349BD0.DLL"nå. Du kan søke "14E750A0.EXE" er den borte er det bra. Hijackthis kan du kjøre selv og se etter denne linjen. O23 - Service: 24F82B7C - Unknown owner - C:\WINDOWS\Fonts\14E750A0.EXE Er den borte er vi ferdig. Lenke til kommentar
Kvikksølv Skrevet 29. desember 2008 Forfatter Del Skrevet 29. desember 2008 (endret) Da må jeg bare si tusen takk! Dere gjør en kjempebra jobb for folk her på forumet Endret 29. desember 2008 av Almeida Lenke til kommentar
Anbefalte innlegg
Opprett en konto eller logg inn for å kommentere
Du må være et medlem for å kunne skrive en kommentar
Opprett konto
Det er enkelt å melde seg inn for å starte en ny konto!
Start en kontoLogg inn
Har du allerede en konto? Logg inn her.
Logg inn nå