Gå til innhold

Poster utskilt fra veiledningestråden


Anbefalte innlegg

Videoannonse
Annonse

Logg fra ComboFix;

 

Klikk for å se/fjerne innholdet nedenfor
"monapona" - 2007-05-11 0:00:55 Service Pack 2

ComboFix 07-05.09.V - Running from: "C:\Documents and Settings\monapona\Skrivebord\"

 

 

(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

C:\WINDOWS\system32\jkkjg.dll

C:\WINDOWS\system32\owwgnglr.dll

C:\WINDOWS\system32\gjkkj.ini

C:\WINDOWS\system32\ijllm.bak1

C:\WINDOWS\system32\ijllm.ini2

C:\WINDOWS\system32\ijllm.tmp

C:\WINDOWS\system32\rlgngwwo.ini

C:\WINDOWS\system32\mllji.dll

C:\WINDOWS\system32\ddcddaa.dll

 

 

* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

 

 

 

((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-11 ))))))))))))))))))))))))))))))))))

 

 

2007-05-10 23:58 <DIR> dr-h----- C:\DOCUME~1\monapona\Siste

2007-05-10 23:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\Yahoo! Companion

2007-05-10 23:41 <DIR> d-------- C:\Programfiler\Yahoo!

2007-05-10 23:41 <DIR> d-------- C:\Programfiler\CCleaner

2007-05-10 07:24 604,102 ---hs---- C:\WINDOWS\system32\klnmp.bak1

2007-05-09 19:15 598,077 ---hs---- C:\WINDOWS\system32\klnmp.ini2

2007-05-09 07:24 592,516 ---hs---- C:\WINDOWS\system32\klnmp.bak2

2007-05-08 21:49 595,074 ---hs---- C:\WINDOWS\system32\dgjlm.ini2

2007-05-08 21:00 596,530 ---hs---- C:\WINDOWS\system32\dgjlm.bak2

2007-05-07 21:00 591,723 ---hs---- C:\WINDOWS\system32\dgjlm.bak1

2007-05-07 01:48 592,977 ---hs---- C:\WINDOWS\system32\mlnmp.ini2

2007-05-07 00:40 212 --a------ C:\delete.bat

2007-05-07 00:10 593,625 ---hs---- C:\WINDOWS\system32\mlnmp.bak1

2007-05-06 23:29 586,586 ---hs---- C:\WINDOWS\system32\qqtwa.ini2

2007-05-06 22:50 587,976 ---hs---- C:\WINDOWS\system32\qqtwa.bak1

2007-05-06 22:41 22,313 --a------ C:\Programfiler\serial.dat

2007-05-05 15:48 31,277 --a------ C:\WINDOWS\dr.exe

2007-04-27 20:07 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\SUPERAntiSpyware.com

2007-04-27 16:45 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware

2007-04-27 16:45 <DIR> d-------- C:\DOCUME~1\monapona\PROGRA~1\SUPERAntiSpyware.com

2007-04-27 16:43 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard

2007-04-27 00:09 <DIR> d-------- C:\NoLopBackups

2007-04-26 00:14 <DIR> d-------- C:\DOCUME~1\monapona\PROGRA~1\Opera

2007-04-26 00:11 <DIR> d-------- C:\Programfiler\Opera

2007-04-25 23:15 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll

2007-04-12 22:26 <DIR> d-------- C:\Programfiler\LimeWire

2007-04-11 22:52 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys

2007-04-11 22:52 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys

2007-04-11 22:52 19,328 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS

2007-04-11 22:52 17,024 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys

2007-04-11 22:52 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys

2007-04-11 22:52 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys

2007-04-11 22:52 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys

2007-04-11 22:51 91,577 --a------ C:\WINDOWS\system32\drivers\P0620Vid.sys

2007-04-11 22:51 81,920 --a------ C:\WINDOWS\CtDrvIns.exe

2007-04-11 22:51 69,632 --a------ C:\WINDOWS\system32\p0620sti.dll

2007-04-11 22:51 65,536 --a------ C:\WINDOWS\system32\CtCamMgr.dll

2007-04-11 22:51 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll

2007-04-11 22:51 40,960 --a------ C:\WINDOWS\system32\P0620Hwx.dll

2007-04-11 22:51 32,768 --a------ C:\WINDOWS\system32\P0620Pin.dll

2007-04-11 22:51 20,480 --a------ C:\WINDOWS\system32\P0620Srv.exe

2007-04-11 22:51 20,480 --a------ C:\WINDOWS\P0620Cfg.exe

2007-04-11 22:51 126,976 --a------ C:\WINDOWS\system32\P0620Vfw.dll

2007-04-11 22:51 <DIR> d-------- C:\WCamInst

 

 

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

2007-05-10 20:08:12 -------- d-----w C:\Programfiler\Fellesfiler\Symantec Shared

2007-04-17 21:33:00 -------- d-----w C:\Programfiler\MSN Messenger

2007-04-10 15:16:15 -------- d-----w C:\Programfiler\Windows Media Connect 2

2007-04-10 15:14:38 -------- d-----w C:\Programfiler\Skype

2007-04-10 15:14:20 -------- d-----w C:\DOCUME~1\monapona\PROGRA~1\Skype

2007-04-10 08:47:40 -------- d-----w C:\DOCUME~1\monapona\PROGRA~1\Screenshot Sender

2007-04-07 23:11:28 -------- d-----w C:\Programfiler\Picasa2

2007-04-03 02:35:27 -------- d-----w C:\Programfiler\Norton Internet Security

2007-04-02 20:05:04 -------- d-----w C:\Programfiler\hopecreativesecond

2007-04-02 20:04:39 -------- d-----w C:\Programfiler\Messenger Plus! Live

2007-03-28 19:54:05 71,104 ----a-w C:\WINDOWS\system32\perfc014.dat

2007-03-28 19:54:05 405,492 ----a-w C:\WINDOWS\system32\perfh014.dat

2007-03-17 13:45:38 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll

2007-03-14 08:51:05 -------- d-----w C:\Programfiler\Dell_HostCD

2007-03-11 20:46:18 -------- d-----w C:\DOCUME~1\monapona\PROGRA~1\AdobeUM

2007-03-11 20:16:09 -------- d-----w C:\DOCUME~1\monapona\PROGRA~1\Starware349

2007-03-11 01:13:55 69,698 ----a-w C:\WINDOWS\distro_uPlayMe_stub_973387.exe

2007-03-11 00:17:28 -------- d-----w C:\Programfiler\Starware349

2007-03-08 15:39:11 577,536 ----a-w C:\WINDOWS\system32\user32.dll

2007-03-08 15:39:11 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll

2007-03-08 15:39:11 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll

2007-03-08 15:38:06 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys

2007-03-07 02:01:05 -------- d-----w C:\Programfiler\MSXML 4.0

2007-03-06 23:24:29 -------- d-----w C:\DOCUME~1\monapona\PROGRA~1\Teleca

2007-03-06 23:16:58 -------- d-----w C:\Programfiler\Fellesfiler\Teleca Shared

2007-03-06 23:16:03 -------- d-----w C:\Programfiler\Sony Ericsson

2007-03-06 21:09:55 -------- d-----w C:\DOCUME~1\monapona\PROGRA~1\AdobeAUM

2007-02-05 20:19:38 185,344 ----a-w C:\WINDOWS\system32\upnphost.dll

 

 

(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

 

 

*Note* empty entries & legit default entries are not shown

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

"{02478D38-C3F9-4EFB-9B51-7695ECA05670}"="C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll"

"{1E8A6170-7264-4D0F-BEAE-D42A53123C75}"="C:\Programfiler\Fellesfiler\Symantec Shared\coShared\Browser\1.0\NppBho.dll"

"{2F85D76C-0569-466F-A488-493E6BD0E955}"="C:\Programfiler\Windows Desktop Search\dsWebAllow.dll"

"{53707962-6F74-2D53-2644-206D7942484F}"="C:\Programfiler\Spybot - Search & Destroy\SDHelper.dll"

"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"="C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll"

"{9030D464-4C02-4ABF-8ECC-5164760863C6}"="C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll"

"{AA58ED58-01DD-4d91-8333-CF10577473F7}"="c:\programfiler\google\googletoolbar3.dll"

"{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}"="C:\Programfiler\MSN Toolbar Suite\msntb.dll"

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]

"ATIPTA"="\"C:\\Programfiler\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""

"RTHDCPL"="RTHDCPL.EXE"

"SkyTel"="SkyTel.EXE"

"AGRSMMSG"="AGRSMMSG.exe"

"SynTPEnh"="C:\\Programfiler\\Synaptics\\SynTP\\SynTPEnh.exe"

"Toshiba Hotkey Utility"="\"C:\\Programfiler\\Toshiba\\Windows Utilities\\Hotkey.exe\" /lang NO"

"TPSMain"="TPSMain.exe"

"NDSTray.exe"="NDSTray.exe"

"SmoothView"="C:\\Programfiler\\TOSHIBA\\TOSHIBA zoom\\SmoothView.exe"

"PadTouch"="C:\\Programfiler\\TOSHIBA\\Touch and Launch\\PadExe.exe"

"DDWMon"="C:\\Programfiler\\TOSHIBA\\TOSHIBA Direct Disc Writer\\\\ddwmon.exe"

"ccApp"="\"C:\\Programfiler\\Fellesfiler\\Symantec Shared\\ccApp.exe\""

"osCheck"="\"C:\\Programfiler\\Norton Internet Security\\osCheck.exe\""

"SunJavaUpdateSched"="C:\\Programfiler\\Java\\jre1.5.0_07\\bin\\jusched.exe"

"Adobe Photo Downloader"="\"C:\\Programfiler\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""

"Sony Ericsson PC Suite"="\"C:\\Programfiler\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions"

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]

"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"

"TOSCDSPD"="C:\\Programfiler\\TOSHIBA\\TOSCDSPD\\toscdspd.exe"

"swg"="C:\\Programfiler\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"

"SUPERAntiSpyware"="C:\\Programfiler\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"

"msnmsgr"="\"C:\\Programfiler\\MSN Messenger\\msnmsgr.exe\" /background"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

"{56F9679E-7826-4C84-81F3-532071A8BCC5}"="C:\Programfiler\Windows Desktop Search\MSNLNamespaceMgr.dll"

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL"

 

 

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon

 

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa

Authentication Packages msv1_0\0\0

Security Packages kerberos\0msv1_0\0schannel\0wdigest\0\0

Notification Packages scecli\0\0

 

 

 

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]

HTTPFilter HTTPFilter\0\0

LocalService Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0

NetworkService DnsCache\0\0

DcomLaunch DcomLaunch\0TermService\0\0

rpcss RpcSs\0\0

imgsvc StiSvc\0\0

termsvcs TermService\0\0

WudfServiceGroup WUDFSvc\0\0

 

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost

 

*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_COMHOST

 

 

Contents of the 'Scheduled Tasks' folder

C:\WINDOWS\tasks\At1.job

C:\WINDOWS\tasks\At2.job

C:\WINDOWS\tasks\At3.job

C:\WINDOWS\tasks\At4.job

C:\WINDOWS\tasks\At5.job

C:\WINDOWS\tasks\At6.job

C:\WINDOWS\tasks\Norton Internet Security - Kj›r fullstendig systems›k - monapona.job

 

********************************************************************

 

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net

Rootkit scan 2007-05-11 00:09:03

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden services ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 0

 

 

********************************************************************

 

Completion time: 2007-05-11 0:14:06 - machine was rebooted

C:\ComboFix-quarantined-files.txt ... 2007-05-11 00:14

Lenke til kommentar

mona14:

 

Hent VBG, legg det på skrivebordet.

Lukk alle andre programmer, dobbeltklikk på VirtumundoBeGone.exe på skrivebordet,

klikk på Continue, klikk på Start.

Klikk på Yes for at kjøre fixet.

Klikk så på 'Save log'.

 

Det kan skje at fixet avslutter med "BSOD"(blå skjerm og frosset PC). Ta bare å restart (bruk evt. av/på-knappen på pc'n).

 

På skrivebordet vil det komme en tekstfil som heter VBG.TXT

 

Kjør deretter på ny Combofix.

 

Post begge loggene.

Lenke til kommentar

VBG;

Klikk for å se/fjerne innholdet nedenfor

[05/11/2007, 22:37:31] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\monapona\Skrivebord\VirtumundoBeGone.exe" )

[05/11/2007, 22:37:35] - Detected System Information:

[05/11/2007, 22:37:35] - Windows Version: 5.1.2600, Service Pack 2

[05/11/2007, 22:37:36] - Current Username: monapona (Admin)

[05/11/2007, 22:37:36] - Windows is in NORMAL mode.

[05/11/2007, 22:37:36] - Searching for Browser Helper Objects:

[05/11/2007, 22:37:36] - BHO 1: {02478D38-C3F9-4EFB-9B51-7695ECA05670} (Yahoo! Toolbar Helper)

[05/11/2007, 22:37:36] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)

[05/11/2007, 22:37:36] - BHO 3: {1E8A6170-7264-4D0F-BEAE-D42A53123C75} ()

[05/11/2007, 22:37:36] - WARNING: BHO has no default name. Checking for Winlogon reference.

[05/11/2007, 22:37:36] - Checking for HKLM\...\Winlogon\Notify\NppBho

[05/11/2007, 22:37:36] - Key not found: HKLM\...\Winlogon\Notify\NppBho, continuing.

[05/11/2007, 22:37:36] - BHO 4: {2F85D76C-0569-466F-A488-493E6BD0E955} (dsWebAllowBHO Class)

[05/11/2007, 22:37:36] - BHO 5: {307E66C5-0042-4FC9-8BB8-5FE4F188641A} ()

[05/11/2007, 22:37:36] - WARNING: BHO has no default name. Checking for Winlogon reference.

[05/11/2007, 22:37:36] - No filename found. Continuing.

[05/11/2007, 22:37:36] - BHO 6: {4121B3A2-6706-460A-96E1-B8E57AE902BA} ()

[05/11/2007, 22:37:36] - WARNING: BHO has no default name. Checking for Winlogon reference.

[05/11/2007, 22:37:36] - No filename found. Continuing.

[05/11/2007, 22:37:36] - BHO 7: {53707962-6F74-2D53-2644-206D7942484F} ()

[05/11/2007, 22:37:36] - WARNING: BHO has no default name. Checking for Winlogon reference.

[05/11/2007, 22:37:36] - Checking for HKLM\...\Winlogon\Notify\SDHelper

[05/11/2007, 22:37:36] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.

[05/11/2007, 22:37:36] - BHO 8: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)

[05/11/2007, 22:37:36] - BHO 9: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()

[05/11/2007, 22:37:36] - WARNING: BHO has no default name. Checking for Winlogon reference.

[05/11/2007, 22:37:36] - No filename found. Continuing.

[05/11/2007, 22:37:36] - BHO 10: {8B593A4C-B045-4E5C-B930-2B7DD5F78B40} ()

[05/11/2007, 22:37:36] - WARNING: BHO has no default name. Checking for Winlogon reference.

[05/11/2007, 22:37:36] - No filename found. Continuing.

[05/11/2007, 22:37:36] - BHO 11: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)

[05/11/2007, 22:37:36] - BHO 12: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)

[05/11/2007, 22:37:36] - BHO 13: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (MSN Search Toolbar Helper)

[05/11/2007, 22:37:36] - BHO 14: {C4C151F9-87CA-4793-A79E-5EBF0A97BA5F} ()

[05/11/2007, 22:37:36] - WARNING: BHO has no default name. Checking for Winlogon reference.

[05/11/2007, 22:37:36] - No filename found. Continuing.

[05/11/2007, 22:37:36] - Finished Searching Browser Helper Objects

[05/11/2007, 22:37:36] - Finishing up...

[05/11/2007, 22:37:36] - Nothing found! Exiting...

 

 

ComboFix;

Klikk for å se/fjerne innholdet nedenfor
"monapona" - 2007-05-11 22:40:41 Service Pack 2

ComboFix 07-05.09.V - Running from: "C:\Documents and Settings\monapona\Skrivebord\"

 

 

((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-11 ))))))))))))))))))))))))))))))))))

 

 

2007-05-11 00:45 <DIR> dr-h----- C:\DOCUME~1\monapona\Siste

2007-05-11 00:14 49,152 --a------ C:\WINDOWS\nircmd.exe

2007-05-10 23:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\Yahoo! Companion

2007-05-10 23:41 <DIR> d-------- C:\Programfiler\Yahoo!

2007-05-10 23:41 <DIR> d-------- C:\Programfiler\CCleaner

2007-05-10 07:24 604,102 ---hs---- C:\WINDOWS\system32\klnmp.bak1

2007-05-09 19:15 598,077 ---hs---- C:\WINDOWS\system32\klnmp.ini2

2007-05-09 07:24 592,516 ---hs---- C:\WINDOWS\system32\klnmp.bak2

2007-05-08 21:49 595,074 ---hs---- C:\WINDOWS\system32\dgjlm.ini2

2007-05-08 21:00 596,530 ---hs---- C:\WINDOWS\system32\dgjlm.bak2

2007-05-07 21:00 591,723 ---hs---- C:\WINDOWS\system32\dgjlm.bak1

2007-05-07 01:48 592,977 ---hs---- C:\WINDOWS\system32\mlnmp.ini2

2007-05-07 00:40 212 --a------ C:\delete.bat

2007-05-07 00:10 593,625 ---hs---- C:\WINDOWS\system32\mlnmp.bak1

2007-05-06 23:29 586,586 ---hs---- C:\WINDOWS\system32\qqtwa.ini2

2007-05-06 22:50 587,976 ---hs---- C:\WINDOWS\system32\qqtwa.bak1

2007-05-06 22:41 22,313 --a------ C:\Programfiler\serial.dat

2007-05-05 15:48 31,277 --a------ C:\WINDOWS\dr.exe

2007-04-27 20:07 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\SUPERAntiSpyware.com

2007-04-27 16:45 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware

2007-04-27 16:45 <DIR> d-------- C:\DOCUME~1\monapona\PROGRA~1\SUPERAntiSpyware.com

2007-04-27 16:43 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard

2007-04-27 00:09 <DIR> d-------- C:\NoLopBackups

2007-04-26 00:14 <DIR> d-------- C:\DOCUME~1\monapona\PROGRA~1\Opera

2007-04-26 00:11 <DIR> d-------- C:\Programfiler\Opera

2007-04-25 23:15 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll

2007-04-12 22:26 <DIR> d-------- C:\Programfiler\LimeWire

2007-04-11 22:52 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys

2007-04-11 22:52 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys

2007-04-11 22:52 19,328 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS

2007-04-11 22:52 17,024 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys

2007-04-11 22:52 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys

2007-04-11 22:52 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys

2007-04-11 22:52 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys

2007-04-11 22:51 91,577 --a------ C:\WINDOWS\system32\drivers\P0620Vid.sys

2007-04-11 22:51 81,920 --a------ C:\WINDOWS\CtDrvIns.exe

2007-04-11 22:51 69,632 --a------ C:\WINDOWS\system32\p0620sti.dll

2007-04-11 22:51 65,536 --a------ C:\WINDOWS\system32\CtCamMgr.dll

2007-04-11 22:51 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll

2007-04-11 22:51 40,960 --a------ C:\WINDOWS\system32\P0620Hwx.dll

2007-04-11 22:51 32,768 --a------ C:\WINDOWS\system32\P0620Pin.dll

2007-04-11 22:51 20,480 --a------ C:\WINDOWS\system32\P0620Srv.exe

2007-04-11 22:51 20,480 --a------ C:\WINDOWS\P0620Cfg.exe

2007-04-11 22:51 126,976 --a------ C:\WINDOWS\system32\P0620Vfw.dll

2007-04-11 22:51 <DIR> d-------- C:\WCamInst

 

 

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

2007-05-11 20:34:36 -------- d-----w C:\Programfiler\Fellesfiler\Symantec Shared

2007-04-17 21:33:00 -------- d-----w C:\Programfiler\MSN Messenger

2007-04-10 15:16:15 -------- d-----w C:\Programfiler\Windows Media Connect 2

2007-04-10 15:14:38 -------- d-----w C:\Programfiler\Skype

2007-04-10 15:14:20 -------- d-----w C:\DOCUME~1\monapona\PROGRA~1\Skype

2007-04-10 08:47:40 -------- d-----w C:\DOCUME~1\monapona\PROGRA~1\Screenshot Sender

2007-04-07 23:11:28 -------- d-----w C:\Programfiler\Picasa2

2007-04-03 02:35:27 -------- d-----w C:\Programfiler\Norton Internet Security

2007-04-02 20:05:04 -------- d-----w C:\Programfiler\hopecreativesecond

2007-04-02 20:04:39 -------- d-----w C:\Programfiler\Messenger Plus! Live

2007-03-28 19:54:05 71,104 ----a-w C:\WINDOWS\system32\perfc014.dat

2007-03-28 19:54:05 405,492 ----a-w C:\WINDOWS\system32\perfh014.dat

2007-03-17 13:45:38 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll

2007-03-14 08:51:05 -------- d-----w C:\Programfiler\Dell_HostCD

2007-03-11 20:46:18 -------- d-----w C:\DOCUME~1\monapona\PROGRA~1\AdobeUM

2007-03-11 20:16:09 -------- d-----w C:\DOCUME~1\monapona\PROGRA~1\Starware349

2007-03-11 01:13:55 69,698 ----a-w C:\WINDOWS\distro_uPlayMe_stub_973387.exe

2007-03-11 00:17:28 -------- d-----w C:\Programfiler\Starware349

2007-03-08 15:39:11 577,536 ----a-w C:\WINDOWS\system32\user32.dll

2007-03-08 15:39:11 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll

2007-03-08 15:39:11 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll

2007-03-08 15:38:06 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys

2007-03-07 02:01:05 -------- d-----w C:\Programfiler\MSXML 4.0

2007-03-06 23:24:29 -------- d-----w C:\DOCUME~1\monapona\PROGRA~1\Teleca

2007-03-06 23:16:58 -------- d-----w C:\Programfiler\Fellesfiler\Teleca Shared

2007-03-06 23:16:03 -------- d-----w C:\Programfiler\Sony Ericsson

2007-03-06 21:09:55 -------- d-----w C:\DOCUME~1\monapona\PROGRA~1\AdobeAUM

2007-02-05 20:19:38 185,344 ----a-w C:\WINDOWS\system32\upnphost.dll

 

 

(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

 

 

*Note* empty entries & legit default entries are not shown

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

"{02478D38-C3F9-4EFB-9B51-7695ECA05670}"="C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll"

"{1E8A6170-7264-4D0F-BEAE-D42A53123C75}"="C:\Programfiler\Fellesfiler\Symantec Shared\coShared\Browser\1.0\NppBho.dll"

"{2F85D76C-0569-466F-A488-493E6BD0E955}"="C:\Programfiler\Windows Desktop Search\dsWebAllow.dll"

"{53707962-6F74-2D53-2644-206D7942484F}"="C:\Programfiler\Spybot - Search & Destroy\SDHelper.dll"

"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"="C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll"

"{9030D464-4C02-4ABF-8ECC-5164760863C6}"="C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll"

"{AA58ED58-01DD-4d91-8333-CF10577473F7}"="c:\programfiler\google\googletoolbar3.dll"

"{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}"="C:\Programfiler\MSN Toolbar Suite\msntb.dll"

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]

"ATIPTA"="\"C:\\Programfiler\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""

"RTHDCPL"="RTHDCPL.EXE"

"SkyTel"="SkyTel.EXE"

"AGRSMMSG"="AGRSMMSG.exe"

"SynTPEnh"="C:\\Programfiler\\Synaptics\\SynTP\\SynTPEnh.exe"

"Toshiba Hotkey Utility"="\"C:\\Programfiler\\Toshiba\\Windows Utilities\\Hotkey.exe\" /lang NO"

"TPSMain"="TPSMain.exe"

"NDSTray.exe"="NDSTray.exe"

"SmoothView"="C:\\Programfiler\\TOSHIBA\\TOSHIBA zoom\\SmoothView.exe"

"PadTouch"="C:\\Programfiler\\TOSHIBA\\Touch and Launch\\PadExe.exe"

"DDWMon"="C:\\Programfiler\\TOSHIBA\\TOSHIBA Direct Disc Writer\\\\ddwmon.exe"

"ccApp"="\"C:\\Programfiler\\Fellesfiler\\Symantec Shared\\ccApp.exe\""

"osCheck"="\"C:\\Programfiler\\Norton Internet Security\\osCheck.exe\""

"SunJavaUpdateSched"="C:\\Programfiler\\Java\\jre1.5.0_07\\bin\\jusched.exe"

"Adobe Photo Downloader"="\"C:\\Programfiler\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""

"Sony Ericsson PC Suite"="\"C:\\Programfiler\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions"

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]

"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"

"TOSCDSPD"="C:\\Programfiler\\TOSHIBA\\TOSCDSPD\\toscdspd.exe"

"swg"="C:\\Programfiler\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"

"SUPERAntiSpyware"="C:\\Programfiler\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"

"msnmsgr"="\"C:\\Programfiler\\MSN Messenger\\msnmsgr.exe\" /background"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

"{56F9679E-7826-4C84-81F3-532071A8BCC5}"="C:\Programfiler\Windows Desktop Search\MSNLNamespaceMgr.dll"

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL"

 

 

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon

 

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa

Authentication Packages msv1_0\0\0

Security Packages kerberos\0msv1_0\0schannel\0wdigest\0\0

Notification Packages scecli\0\0

 

 

 

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]

HTTPFilter HTTPFilter\0\0

LocalService Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0

NetworkService DnsCache\0\0

DcomLaunch DcomLaunch\0TermService\0\0

rpcss RpcSs\0\0

imgsvc StiSvc\0\0

termsvcs TermService\0\0

WudfServiceGroup WUDFSvc\0\0

 

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost

 

 

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6eed47e5-9375-11db-a737-806d6172696f}]

Shell\AutoRun\command D:\setupSNK.exe

*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_COMHOST

 

 

Contents of the 'Scheduled Tasks' folder

C:\WINDOWS\tasks\At1.job

C:\WINDOWS\tasks\At2.job

C:\WINDOWS\tasks\At3.job

C:\WINDOWS\tasks\At4.job

C:\WINDOWS\tasks\At5.job

C:\WINDOWS\tasks\At6.job

C:\WINDOWS\tasks\Norton Internet Security - Kj›r fullstendig systems›k - monapona.job

 

********************************************************************

 

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net

Rootkit scan 2007-05-11 22:43:42

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden services ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 0

 

 

********************************************************************

 

Completion time: 2007-05-11 22:43:53

C:\ComboFix-quarantined-files.txt ... 2007-05-11 22:43

C:\ComboFix2.txt ... 2007-05-11 00:14

Endret av mona14
Lenke til kommentar

Hvis mulig, avinstallerer du fra legg til /fjern programmer:

Messenger Plus! Live

 

AVENGER

 

Hent Avenger og pakk det ut.

 

Start programmet, sett prikk i "Input Script Manually" og klikk på lupen.

I vinduet som kommer opp kopierer du og limer inn det som er i fet skrift under:

 

 

Files to delete:

C:\WINDOWS\system32\klnmp.bak1

C:\WINDOWS\system32\klnmp.ini2

C:\WINDOWS\system32\klnmp.bak2

C:\WINDOWS\system32\dgjlm.ini2

C:\WINDOWS\system32\dgjlm.bak2

C:\WINDOWS\system32\dgjlm.bak1

C:\WINDOWS\system32\mlnmp.ini2

C:\WINDOWS\system32\mlnmp.bak1

C:\WINDOWS\system32\qqtwa.ini2

C:\WINDOWS\system32\qqtwa.bak1

 

Folders to delete:

C:\NoLopBackups

C:\Programfiler\Messenger Plus! Live

 

Klikk på Trafikklyset. Restart pc'n.

Etter restart vil det komme en loggfil som forteller hva som har skjedd.

 

Sannsynlig er filene allerede fjernet men det skader ikke sjekke.

 

Restart pc og fortell hvordan pc'n kjører.

Endret av norbat
Lenke til kommentar

Avenger;

Klikk for å se/fjerne innholdet nedenfor
Logfile of The Avenger version 1, by Swandog46

Running from registry key:

\Registry\Machine\System\CurrentControlSet\Services\boyeetpg

 

*******************

 

Script file located at: \??\C:\sipbcftg.txt

Script file opened successfully.

 

Script file read successfully

 

Backups directory opened successfully at C:\Avenger

 

*******************

 

Beginning to process script file:

 

File C:\WINDOWS\system32\klnmp.bak1 deleted successfully.

File C:\WINDOWS\system32\klnmp.ini2 deleted successfully.

File C:\WINDOWS\system32\klnmp.bak2 deleted successfully.

File C:\WINDOWS\system32\dgjlm.ini2 deleted successfully.

File C:\WINDOWS\system32\dgjlm.bak2 deleted successfully.

File C:\WINDOWS\system32\dgjlm.bak1 deleted successfully.

File C:\WINDOWS\system32\mlnmp.ini2 deleted successfully.

File C:\WINDOWS\system32\mlnmp.bak1 deleted successfully.

File C:\WINDOWS\system32\qqtwa.ini2 deleted successfully.

File C:\WINDOWS\system32\qqtwa.bak1 deleted successfully.

Folder C:\NoLopBackups deleted successfully.

Folder C:\Programfiler\Messenger Plus! Live deleted successfully.

 

Completed script processing.

 

*******************

 

Finished! Terminate.

 

Stod at msn var sletta når jeg fjerna den gjennom legg til/fjern programmer, men når jeg restarta kom den opp igjen. ar sånn at den logger seg på automatisk når jeg skrur på dataen. Hm..

Lenke til kommentar
Du skal ikke avinstallere Windows Live Messenger (om det er den versjonen du har), men Messenger Plus Live, om den ligger på lista.

8592179[/snapback]

 

Tror jeg sletta begge jeg, men da kan jeg bare laste ned igjen Windows Live Messenger. Enkel link?

Lenke til kommentar

HJK;

 

Klikk for å se/fjerne innholdet nedenfor
Logfile of HijackThis v1.99.1

Scan saved at 18:59:30, on 19.05.2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe

C:\Programfiler\Fellesfiler\Symantec Shared\AppCore\AppSvc32.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\acs.exe

C:\Programfiler\Symantec\LiveUpdate\ALUSchedulerSvc.exe

C:\Programfiler\TOSHIBA\ConfigFree\CFSvcs.exe

C:\Programfiler\Norton GoBack\GBPoll.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\TODDSrv.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\AGRSMMSG.exe

C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe

C:\Programfiler\Toshiba\Windows Utilities\Hotkey.exe

C:\WINDOWS\system32\TPSMain.exe

C:\Programfiler\TOSHIBA\ConfigFree\NDSTray.exe

C:\Programfiler\TOSHIBA\TOSHIBA zoom\SmoothView.exe

C:\Programfiler\TOSHIBA\Touch and Launch\PadExe.exe

C:\Programfiler\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe

C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe

C:\WINDOWS\System32\svchost.exe

C:\Programfiler\Java\jre1.5.0_07\bin\jusched.exe

C:\Programfiler\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

C:\Programfiler\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\TOSHIBA\TOSCDSPD\toscdspd.exe

C:\Programfiler\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Programfiler\MSN Messenger\MsnMsgr.Exe

C:\Programfiler\Fellesfiler\Teleca Shared\CapabilityManager.exe

C:\WINDOWS\system32\TPSBattM.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Programfiler\Norton GoBack\GBTray.exe

C:\Programfiler\Microsoft Office\OFFICE11\ONENOTEM.EXE

C:\Programfiler\Fellesfiler\Teleca Shared\Generic.exe

C:\Programfiler\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe

C:\Programfiler\MSN Messenger\usnsvc.exe

C:\Programfiler\Java\jre1.5.0_07\bin\jucheck.exe

C:\Programfiler\Fellesfiler\Symantec Shared\CCPD-LC\symlcsvc.exe

C:\Programfiler\LimeWire\LimeWire.exe

C:\Documents and Settings\monapona\Skrivebord\Hijackthis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Programfiler\Fellesfiler\Symantec Shared\coShared\Browser\1.0\NppBho.dll

O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Programfiler\Windows Desktop Search\dsWebAllow.dll

O2 - BHO: (no name) - {307E66C5-0042-4FC9-8BB8-5FE4F188641A} - (no file)

O2 - BHO: (no name) - {4121B3A2-6706-460A-96E1-B8E57AE902BA} - (no file)

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programfiler\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: (no name) - {8B593A4C-B045-4E5C-B930-2B7DD5F78B40} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiler\google\googletoolbar3.dll

O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\MSN Toolbar Suite\msntb.dll

O2 - BHO: (no name) - {C4C151F9-87CA-4793-A79E-5EBF0A97BA5F} - (no file)

O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\MSN Toolbar Suite\msntb.dll

O3 - Toolbar: Norton-verktøylinjen - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Programfiler\Fellesfiler\Symantec Shared\coShared\Browser\1.0\UIBHO.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programfiler\google\googletoolbar3.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [ATIPTA] "C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe"

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "C:\Programfiler\Toshiba\Windows Utilities\Hotkey.exe" /lang NO

O4 - HKLM\..\Run: [TPSMain] TPSMain.exe

O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe

O4 - HKLM\..\Run: [smoothView] C:\Programfiler\TOSHIBA\TOSHIBA zoom\SmoothView.exe

O4 - HKLM\..\Run: [PadTouch] C:\Programfiler\TOSHIBA\Touch and Launch\PadExe.exe

O4 - HKLM\..\Run: [DDWMon] C:\Programfiler\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe

O4 - HKLM\..\Run: [ccApp] "C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [osCheck] "C:\Programfiler\Norton Internet Security\osCheck.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Programfiler\Java\jre1.5.0_07\bin\jusched.exe

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programfiler\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"

O4 - HKLM\..\Run: [sony Ericsson PC Suite] "C:\Programfiler\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [TOSCDSPD] C:\Programfiler\TOSHIBA\TOSCDSPD\toscdspd.exe

O4 - HKCU\..\Run: [swg] C:\Programfiler\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background

O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Programfiler\Microsoft Office\OFFICE11\ONENOTEM.EXE

O4 - Global Startup: Hurtigstart for Adobe Reader.lnk = C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Norton GoBack.lnk = C:\Programfiler\Norton GoBack\GBTray.exe

O4 - Global Startup: PC-søk i Windows.lnk = C:\Programfiler\Windows Desktop Search\WindowsSearch.exe

O8 - Extra context menu item: &MSN Search - res://C:\Programfiler\MSN Toolbar Suite\msntb.dll/search.htm

O8 - Extra context menu item: Åpne i ny bakgrunnsflik - res://C:\Programfiler\MSN Toolbar Suite\nb-no\msntabres.dll.mui/229?54bfac8f2c764fcd9f35fdface417280

O8 - Extra context menu item: Åpne i ny forgrunnsflik - res://C:\Programfiler\MSN Toolbar Suite\nb-no\msntabres.dll.mui/230?54bfac8f2c764fcd9f35fdface417280

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll

O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programfiler\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab55762.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: Automatisk LiveUpdate-planlegging - Symantec Corporation - C:\Programfiler\Symantec\LiveUpdate\ALUSchedulerSvc.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programfiler\TOSHIBA\ConfigFree\CFSvcs.exe

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\VAScanner\comHost.exe

O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Programfiler\Norton GoBack\GBPoll.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Programfiler\Norton Internet Security\isPwdSvc.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\CCPD-LC\symlcsvc.exe

O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\AppCore\AppSvc32.exe

O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\WINDOWS\system32\TODDSrv.exe

 

Lenke til kommentar

Noe opprydding,

Kjør HJT, sett merke framfor følgende linje og klikk 'Fix checked':

O2 - BHO: (no name) - {307E66C5-0042-4FC9-8BB8-5FE4F188641A} - (no file)

O2 - BHO: (no name) - {4121B3A2-6706-460A-96E1-B8E57AE902BA} - (no file)

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: (no name) - {8B593A4C-B045-4E5C-B930-2B7DD5F78B40} - (no file)

O2 - BHO: (no name) - {C4C151F9-87CA-4793-A79E-5EBF0A97BA5F} - (no file)

 

Har du mistanke om noe eller var det kun en sjekk?

Lenke til kommentar

Bare en sjekk, hvordan det?

 

Sånn?

Klikk for å se/fjerne innholdet nedenfor
Logfile of HijackThis v1.99.1

Scan saved at 23:51:28, on 19.05.2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe

C:\Programfiler\Fellesfiler\Symantec Shared\AppCore\AppSvc32.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\acs.exe

C:\Programfiler\Symantec\LiveUpdate\ALUSchedulerSvc.exe

C:\Programfiler\TOSHIBA\ConfigFree\CFSvcs.exe

C:\Programfiler\Norton GoBack\GBPoll.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\TODDSrv.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\AGRSMMSG.exe

C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe

C:\Programfiler\Toshiba\Windows Utilities\Hotkey.exe

C:\WINDOWS\system32\TPSMain.exe

C:\Programfiler\TOSHIBA\ConfigFree\NDSTray.exe

C:\Programfiler\TOSHIBA\TOSHIBA zoom\SmoothView.exe

C:\Programfiler\TOSHIBA\Touch and Launch\PadExe.exe

C:\Programfiler\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe

C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe

C:\WINDOWS\System32\svchost.exe

C:\Programfiler\Java\jre1.5.0_07\bin\jusched.exe

C:\Programfiler\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

C:\Programfiler\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\TOSHIBA\TOSCDSPD\toscdspd.exe

C:\Programfiler\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Programfiler\MSN Messenger\MsnMsgr.Exe

C:\Programfiler\Fellesfiler\Teleca Shared\CapabilityManager.exe

C:\WINDOWS\system32\TPSBattM.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Programfiler\Norton GoBack\GBTray.exe

C:\Programfiler\Microsoft Office\OFFICE11\ONENOTEM.EXE

C:\Programfiler\Fellesfiler\Teleca Shared\Generic.exe

C:\Programfiler\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe

C:\Programfiler\MSN Messenger\usnsvc.exe

C:\Programfiler\Java\jre1.5.0_07\bin\jucheck.exe

C:\Programfiler\Fellesfiler\Symantec Shared\CCPD-LC\symlcsvc.exe

C:\Programfiler\LimeWire\LimeWire.exe

C:\Programfiler\Internet Explorer\iexplore.exe

C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Documents and Settings\monapona\Skrivebord\Hijackthis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Programfiler\Fellesfiler\Symantec Shared\coShared\Browser\1.0\NppBho.dll

O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Programfiler\Windows Desktop Search\dsWebAllow.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiler\google\googletoolbar3.dll

O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\MSN Toolbar Suite\msntb.dll

O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\MSN Toolbar Suite\msntb.dll

O3 - Toolbar: Norton-verktøylinjen - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Programfiler\Fellesfiler\Symantec Shared\coShared\Browser\1.0\UIBHO.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programfiler\google\googletoolbar3.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [ATIPTA] "C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe"

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "C:\Programfiler\Toshiba\Windows Utilities\Hotkey.exe" /lang NO

O4 - HKLM\..\Run: [TPSMain] TPSMain.exe

O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe

O4 - HKLM\..\Run: [smoothView] C:\Programfiler\TOSHIBA\TOSHIBA zoom\SmoothView.exe

O4 - HKLM\..\Run: [PadTouch] C:\Programfiler\TOSHIBA\Touch and Launch\PadExe.exe

O4 - HKLM\..\Run: [DDWMon] C:\Programfiler\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe

O4 - HKLM\..\Run: [ccApp] "C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [osCheck] "C:\Programfiler\Norton Internet Security\osCheck.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Programfiler\Java\jre1.5.0_07\bin\jusched.exe

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programfiler\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"

O4 - HKLM\..\Run: [sony Ericsson PC Suite] "C:\Programfiler\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [TOSCDSPD] C:\Programfiler\TOSHIBA\TOSCDSPD\toscdspd.exe

O4 - HKCU\..\Run: [swg] C:\Programfiler\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background

O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Programfiler\Microsoft Office\OFFICE11\ONENOTEM.EXE

O4 - Global Startup: Hurtigstart for Adobe Reader.lnk = C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Norton GoBack.lnk = C:\Programfiler\Norton GoBack\GBTray.exe

O4 - Global Startup: PC-søk i Windows.lnk = C:\Programfiler\Windows Desktop Search\WindowsSearch.exe

O8 - Extra context menu item: &MSN Search - res://C:\Programfiler\MSN Toolbar Suite\msntb.dll/search.htm

O8 - Extra context menu item: Åpne i ny bakgrunnsflik - res://C:\Programfiler\MSN Toolbar Suite\nb-no\msntabres.dll.mui/229?54bfac8f2c764fcd9f35fdface417280

O8 - Extra context menu item: Åpne i ny forgrunnsflik - res://C:\Programfiler\MSN Toolbar Suite\nb-no\msntabres.dll.mui/230?54bfac8f2c764fcd9f35fdface417280

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll

O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programfiler\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab55762.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: Automatisk LiveUpdate-planlegging - Symantec Corporation - C:\Programfiler\Symantec\LiveUpdate\ALUSchedulerSvc.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programfiler\TOSHIBA\ConfigFree\CFSvcs.exe

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\VAScanner\comHost.exe

O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Programfiler\Norton GoBack\GBPoll.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Programfiler\Norton Internet Security\isPwdSvc.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\CCPD-LC\symlcsvc.exe

O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\AppCore\AppSvc32.exe

O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\WINDOWS\system32\TODDSrv.exe

 

Endret av mona14
Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
×
×
  • Opprett ny...