norbat Skrevet 3. juli 2008 Forfatter Del Skrevet 3. juli 2008 Kjør en systemgjenoppretting til før problemet oppsto (tilbehør->systemverktøy->systemgjenoppretting) Deretter kjører du en ny scan med SAS, fjerner de toolbarene du ønsker fra legg til / fjern programmer og poster ny hjt-logg. Lenke til kommentar
GLN Skrevet 3. juli 2008 Del Skrevet 3. juli 2008 Fikset, pcen hang seg bare opp, en restart hjalp. HJT log, etter jeg sletta filene du nevnte og kjørte Ccleaner. Mangler å fjerne noen toolbars, men må lukke IE, så poster loggen nå å fjerner de senere: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 20:30:11, on 03.07.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programfiler\Fellesfiler\GtFlashSwitch\GtFlashSwitch.exe C:\Programfiler\Hotspot Shield\bin\openvpnas.exe C:\WINDOWS\System32\svchost.exe C:\Programfiler\Fellesfiler\LightScribe\LSSrvc.exe C:\WINDOWS\system32\lxdicoms.exe C:\Programfiler\Trend Micro\OfficeScan Client\ntrtscan.exe C:\WINDOWS\system32\svchost.exe C:\Programfiler\Trend Micro\OfficeScan Client\tmlisten.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Programfiler\Trend Micro\OfficeScan Client\OfcPfwSvc.exe C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe C:\Programfiler\hpq\HP Wireless Assistant\HP Wireless Assistant.exe C:\Programfiler\iTunes\iTunesHelper.exe C:\Programfiler\QuickTime\qttask.exe C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe C:\Programfiler\Trend Micro\OfficeScan Client\pccntmon.exe C:\WINDOWS\system32\rundll32.exe C:\Programfiler\Lexmark 3500-4500 Series\lxdimon.exe C:\Programfiler\Fellesfiler\LogiShrd\LComMgr\Communications_Helper.exe C:\Programfiler\Logitech\QuickCam10\QuickCam10.exe C:\WINDOWS\system32\ctfmon.exe C:\Programfiler\Windows Media Player\WMPNSCFG.exe C:\WINDOWS\TEMP\GD19BC.EXE C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Programfiler\Hp\Digital Imaging\bin\hpqtra08.exe C:\Programfiler\Telenor\Mobilt Kontor\Mobilt Kontor.exe C:\Programfiler\CASIO\Photo Loader\Plauto.exe C:\Programfiler\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe C:\Programfiler\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe C:\Programfiler\Fellesfiler\LogiShrd\LComMgr\LVComSX.exe C:\Programfiler\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe C:\Programfiler\iPod\bin\iPodService.exe C:\Programfiler\HPQ\SHARED\HPQWMI.exe C:\Programfiler\HP\Digital Imaging\Product Assistant\bin\hprblog.exe C:\Programfiler\Fellesfiler\Logishrd\LQCVFX\COCIManager.exe C:\Programfiler\Trend Micro\OfficeScan Client\pccntupd.exe C:\Programfiler\internet explorer\iexplore.exe C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\wuauclt.exe C:\DOCUME~1\BIRTHE~1\LOKALE~1\Temp\~nsu.tmp\Au_.exe C:\Documents and Settings\Birthe^_^\Mine dokumenter\test.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startsiden.no/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [ATIPTA] "C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [synTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Programfiler\hpq\HP Wireless Assistant\HP Wireless Assistant.exe O4 - HKLM\..\Run: [iTunesHelper] C:\Programfiler\iTunes\iTunesHelper.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programfiler\HPQ\Quick Launch Buttons\EabServr.exe /Start O4 - HKLM\..\Run: [Cpqset] C:\Programfiler\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Programfiler\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [lxdimon.exe] "C:\Programfiler\Lexmark 3500-4500 Series\lxdimon.exe" O4 - HKLM\..\Run: [lxdiamon] "C:\Programfiler\Lexmark 3500-4500 Series\lxdiamon.exe" O4 - HKLM\..\Run: [FaxCenterServer] "C:\Programfiler\\Lexmark Fax Solutions\fm3032.exe" /s O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Programfiler\Fellesfiler\LogiShrd\LComMgr\Communications_Helper.exe" O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Programfiler\Logitech\QuickCam10\QuickCam10.exe" /hide O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [WMPNSCFG] C:\Programfiler\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\isabel\Start-meny\Programmer\IMVU\Run IMVU.lnk O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} (ObjWinNTCheck Class) - http://172.21.15.50:8080/officescan/consol...ll/WinNTChk.cab O16 - DPF: {08D75BB0-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupINICtrl Class) - http://172.21.15.50:8080/officescan/consol...ll/setupini.cab O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupCtrl Class) - http://172.21.15.50:8080/officescan/consol...stall/setup.cab O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file://C:\Programfiler\Forgotten Riddles - The Mayan Princess\Images\stg_drm.ocx O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab O16 - DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} (Encrypt Class) - http://172.21.15.50:8080/officescan/console/html/AtxEnc.cab O16 - DPF: {5EFE8CB1-D095-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class) - http://172.21.15.50:8080/officescan/consol.../RemoveCtrl.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1140028536852 O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Programfiler\Baby Luv\Images\armhelper.ocx O16 - DPF: {E6C4420E-0669-4518-B825-F63CDDEF7D5D} (InitOcx Control) - http://rc.puppyred.com/init.cab O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: GtFlashSwitch - OptionNV - C:\Programfiler\Fellesfiler\GtFlashSwitch\GtFlashSwitch.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Programfiler\Hotspot Shield\bin\openvpnas.exe O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Programfiler\HPQ\SHARED\HPQWMI.exe O23 - Service: iPod-tjeneste (iPodService) - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programfiler\Fellesfiler\LightScribe\LSSrvc.exe O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Programfiler\Fellesfiler\LogiShrd\SrvLnch\SrvLnch.exe O23 - Service: lxdi_device - - C:\WINDOWS\system32\lxdicoms.exe O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Programfiler\Trend Micro\OfficeScan Client\ntrtscan.exe O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Programfiler\Trend Micro\OfficeScan Client\OfcPfwSvc.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Programfiler\Trend Micro\OfficeScan Client\tmlisten.exe -- End of file - 10272 bytes Hvordan ser det ut? Lenke til kommentar
norbat Skrevet 3. juli 2008 Forfatter Del Skrevet 3. juli 2008 Ser flott ut Kjør en ny runde med ccleaner Fjern combofix ved å skrive combofix /u i kjør-feltet (start->kjør). Dette vil også nullstille systemgjenopprettingen slik at du ikke blir infisert ved en evt. gjenoppretting senere. Lenke til kommentar
GLN Skrevet 3. juli 2008 Del Skrevet 3. juli 2008 Takk, takk. Du er enestående norbat! Lenke til kommentar
Raytee Skrevet 7. juli 2008 Del Skrevet 7. juli 2008 (endret) Klikk for å se/fjerne innholdet nedenfor Logfile of Trend Micro HijackThis v2.0.2Scan saved at 02:04:36, on 07.07.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\PROGRA~1\AVG\AVG8\avgfws8.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\AVG\AVG8\avgam.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\PowerISO\PWRISOVM.EXE C:\Program Files\Razer\Tarantula\razerhid.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe C:\WINDOWS\System32\alg.exe C:\Program Files\Steam\Steam.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Razer\Tarantula\razertra.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Program Files\Opera\opera.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sol.no/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O4 - HKLM\..\Run: [startCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE O4 - HKLM\..\Run: [Tarantula] C:\Program Files\Razer\Tarantula\razerhid.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [steam] "C:\Program Files\Steam\Steam.exe" -silent O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab3.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe O23 - Service: Remote Procedure Manager(TPM) (RPCM) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\Speech\csvde.exe (file missing) -- End of file - 5711 bytes Klikk for å se/fjerne innholdet nedenfor ComboFix 08-07-05.1 - Raymond 2008-07-07 1:47:59.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.379 [GMT 2:00] Running from: C:\Documents and Settings\Raymond\Desktop\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((( Files Created from 2008-06-06 to 2008-07-06 ))))))))))))))))))))))))))))))) . 2008-07-07 01:17 . 2008-07-07 01:17 <DIR> d-------- C:\Program Files\SUPERAntiSpyware 2008-07-07 01:17 . 2008-07-07 01:17 <DIR> d-------- C:\Documents and Settings\Raymond\Application Data\SUPERAntiSpyware.com 2008-07-07 01:17 . 2008-07-07 01:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com 2008-07-07 01:15 . 2008-07-07 01:15 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard 2008-07-07 00:58 . 2008-07-07 01:28 <DIR> d--h----- C:\$AVG8.VAULT$ 2008-07-07 00:51 . 2008-07-07 01:03 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg 2008-07-07 00:51 . 2008-07-07 00:57 <DIR> d-------- C:\Documents and Settings\Raymond\Application Data\AVGTOOLBAR 2008-07-07 00:51 . 2008-07-07 00:51 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys 2008-07-07 00:51 . 2008-07-07 00:51 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys 2008-07-07 00:51 . 2008-07-07 00:51 12,424 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys 2008-07-07 00:51 . 2008-07-07 00:51 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll 2008-07-07 00:50 . 2008-07-07 00:50 <DIR> d-------- C:\WINDOWS\LastGood 2008-07-07 00:50 . 2008-07-07 00:50 <DIR> d-------- C:\Program Files\AVG 2008-07-07 00:50 . 2008-07-07 00:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8 2008-07-07 00:50 . 2008-07-07 00:50 45,568 --a------ C:\WINDOWS\system32\avgfwdx.dll 2008-07-07 00:50 . 2008-07-07 00:50 22,528 --a------ C:\WINDOWS\system32\drivers\avgfwdx.sys 2008-07-07 00:22 . 2008-07-07 00:22 58 --a------ C:\QQ¸öÐÔ×Ö»ðÐÇÎÄ,·±Ìå×Öת»»Æ÷.url 2008-07-07 00:22 . 2008-07-07 00:22 51 --a------ C:\¹É³ÇÍø_¹ÉÊÐÐÐÇé_ÈçºÎ³´¹É.url 2008-07-07 00:12 . 2008-07-07 00:12 20,192 ---hs---- C:\WINDOWS\system32\vcrxfileju.dll 2008-07-06 22:33 . 2008-07-06 22:33 <DIR> d-------- C:\WINDOWS\Downloaded Installations 2008-07-06 22:33 . 2008-07-06 22:33 <DIR> d-------- C:\Program Files\GabbaSoft 2008-07-06 22:31 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl 2008-07-06 22:30 . 2008-07-06 22:31 <DIR> d-------- C:\Program Files\Java 2008-07-06 22:29 . 2008-07-06 22:29 <DIR> d-------- C:\Program Files\Common Files\Java 2008-07-06 22:27 . 2008-07-06 22:27 <DIR> d-------- C:\Program Files\Arcus 2008-07-06 14:41 . 2008-07-06 14:41 <DIR> d-------- C:\Logs 2008-07-06 00:46 . 2008-07-06 00:46 <DIR> d-------- C:\Program Files\SystemRequirementsLab 2008-07-05 23:20 . 2008-07-05 23:20 <DIR> d-------- C:\Program Files\Common Files\Blizzard Entertainment 2008-07-05 23:14 . 2008-07-06 15:22 <DIR> d-------- C:\Program Files\World of Warcraft 2008-07-05 20:40 . 2008-07-05 20:40 <DIR> d-------- C:\Program Files\Razer 2008-07-05 20:40 . 2006-07-12 18:31 77,824 --a------ C:\WINDOWS\system32\Tarantula.cpl 2008-07-05 20:40 . 2006-09-27 14:48 44,800 --a------ C:\WINDOWS\system32\drivers\UsbFltr.sys 2008-07-05 20:40 . 2005-12-21 11:23 14,592 --a------ C:\WINDOWS\system32\drivers\Usbicp.sys 2008-07-02 17:23 . 2008-07-02 17:28 139,264 --a------ C:\WINDOWS\War3Unin.exe 2008-07-02 17:23 . 2008-07-02 17:36 76,336 --a------ C:\WINDOWS\War3Unin.dat 2008-07-02 17:23 . 2008-07-02 17:28 2,829 --a------ C:\WINDOWS\War3Unin.pif 2008-07-02 17:22 . 2008-07-06 15:59 <DIR> d-------- C:\Program Files\Warcraft III 2008-07-02 14:38 . 2008-07-02 14:38 <DIR> d-------- C:\Program Files\PowerISO 2008-07-02 00:46 . 2008-07-02 00:46 <DIR> d-------- C:\Program Files\DivX 2008-06-30 14:22 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll 2008-06-30 14:22 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll 2008-06-30 14:22 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui 2008-06-30 13:32 . 2008-06-13 15:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys 2008-06-30 13:32 . 2008-06-13 15:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys 2008-06-30 13:22 . 2008-06-30 13:22 <DIR> d-------- C:\Documents and Settings\Raymond\Application Data\ATI 2008-06-30 13:22 . 2008-06-30 13:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ATI 2008-06-29 21:41 . 2008-07-01 14:15 <DIR> d--h----- C:\WINDOWS\$hf_mig$ 2008-06-29 21:28 . 2008-06-29 21:28 <DIR> d-------- C:\Program Files\Google 2008-06-29 21:00 . 2004-08-04 02:56 21,504 --a------ C:\WINDOWS\system32\hidserv.dll 2008-06-29 21:00 . 2001-08-17 15:59 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys 2008-06-29 19:53 . 2008-06-29 19:53 <DIR> d---s---- C:\Documents and Settings\Raymond\UserData 2008-06-29 19:48 . 2008-07-06 17:53 <DIR> d-------- C:\Program Files\Steam 2008-06-29 19:47 . 2008-06-29 19:47 <DIR> d-------- C:\Documents and Settings\Raymond\Contacts 2008-06-29 19:46 . 2008-06-29 19:46 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE 2008-06-29 19:46 . 2003-05-25 12:11 60,416 --a------ C:\WINDOWS\system32\antiwpa.dll 2008-06-29 19:44 . 2008-06-29 19:45 <DIR> d-------- C:\Program Files\BitLord 2008-06-29 19:42 . 2008-06-29 19:46 <DIR> d-------- C:\Program Files\Windows Live 2008-06-29 19:42 . 2008-06-29 19:45 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller 2008-06-29 19:42 . 2008-06-29 19:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller 2008-06-29 19:35 . 2008-06-29 19:35 <DIR> d-------- C:\Program Files\Opera 2008-06-29 19:31 . 2008-06-29 19:31 <DIR> d-------- C:\WINDOWS\system32\Lang 2008-06-29 19:31 . 2008-06-29 19:31 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav 2008-06-29 19:31 . 2008-06-29 19:31 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav 2008-06-29 19:31 . 2008-06-29 19:31 0 --a------ C:\WINDOWS\ativpsrm.bin 2008-06-29 19:29 . 2008-06-29 19:29 <DIR> d-------- C:\Program Files\AMD 2008-06-29 19:28 . 2008-06-29 19:28 <DIR> d-------- C:\WINDOWS\system32\RTCOM 2008-06-29 19:27 . 2008-06-29 19:27 <DIR> d-------- C:\Program Files\Realtek 2008-06-29 19:23 . 2008-06-29 19:24 <DIR> d-------- C:\Program Files\ATI Technologies 2008-06-29 19:22 . 2008-06-29 19:22 <DIR> d-------- C:\ATI 2008-06-29 19:22 . 2008-06-03 06:05 593,920 --------- C:\WINDOWS\system32\ati2sgag.exe 2008-06-29 19:17 . 2008-07-05 20:40 <DIR> d--h----- C:\Program Files\InstallShield Installation Information 2008-06-29 19:16 . 2008-06-29 19:16 <DIR> d-------- C:\Program Files\VIA 2008-06-29 19:15 . 2008-06-29 19:23 <DIR> d-------- C:\Program Files\Common Files\InstallShield 2008-06-29 19:15 . 2008-06-29 19:27 16,174 --a------ C:\WINDOWS\Ascd_tmp.ini 2008-06-29 19:15 . 2004-04-26 18:00 5,824 --a------ C:\WINDOWS\system32\drivers\ASUSHWIO.SYS 2008-06-29 19:15 . 2004-08-13 04:56 5,810 -ra------ C:\WINDOWS\system32\drivers\ASACPI.sys 2008-06-29 19:11 . 2008-07-06 01:05 <DIR> d-------- C:\Documents and Settings\Raymond 2008-06-18 19:52 . 2008-06-18 19:52 161,096 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe 2008-06-11 02:07 . 2008-06-11 02:07 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll 2008-06-11 02:07 . 2008-06-11 02:07 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe 2008-06-11 02:07 . 2008-06-11 02:07 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb 2008-06-11 02:04 . 2008-06-11 02:04 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll 2008-06-11 02:04 . 2008-06-11 02:04 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-06 22:22 0 --sh--w C:\Program Files\desktoq.ini 2008-07-06 21:33 4,224 ----a-w C:\WINDOWS\system32\drivers\beep.sys 2008-06-30 02:07 --------- d-----w C:\Program Files\microsoft frontpage 2008-06-29 18:20 --------- d-----w C:\Program Files\QuickTime 2008-06-29 18:20 --------- d-----w C:\Program Files\Apple Software Update 2008-06-29 18:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer 2008-06-29 18:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple 2008-06-29 18:03 --------- d-----w C:\Program Files\Windows Media Connect 2 2008-06-11 00:07 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys 2008-06-11 00:07 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys 2008-06-11 00:07 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys 2008-06-11 00:07 129,784 ------w C:\WINDOWS\system32\pxafs.dll 2008-06-11 00:07 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe 2008-06-11 00:07 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe 2008-06-03 06:20 3,100,160 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys 2008-06-03 03:46 10,276,864 ----a-w C:\WINDOWS\system32\atioglx2.dll 2008-06-03 03:22 413,696 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll 2008-06-03 03:21 306,688 ----a-w C:\WINDOWS\system32\ati2dvag.dll 2008-06-03 03:11 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll 2008-06-03 03:11 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe 2008-06-03 03:11 180,224 ----a-w C:\WINDOWS\system32\atipdlxx.dll 2008-06-03 03:11 139,264 ----a-w C:\WINDOWS\system32\Oemdspif.dll 2008-06-03 03:11 139,264 ----a-w C:\WINDOWS\system32\ati2evxx.dll 2008-06-03 03:09 552,960 ----a-w C:\WINDOWS\system32\ati2evxx.exe 2008-06-03 03:08 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL 2008-06-03 03:04 245,760 ----a-w C:\WINDOWS\system32\atiok3x2.dll 2008-06-03 03:02 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll 2008-06-03 02:59 3,500,352 ----a-w C:\WINDOWS\system32\ati3duag.dll 2008-06-03 02:48 2,120,832 ----a-w C:\WINDOWS\system32\ativvaxx.dll 2008-06-03 02:33 48,128 ----a-w C:\WINDOWS\system32\amdpcom32.dll 2008-06-03 02:29 348,160 ----a-w C:\WINDOWS\system32\atikvmag.dll 2008-06-03 02:28 23,040 ----a-w C:\WINDOWS\system32\atiadlxx.dll 2008-06-03 02:28 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll 2008-06-03 02:27 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll 2008-06-03 02:22 5,439,488 ----a-w C:\WINDOWS\system32\atioglxx.dll 2008-06-03 02:21 557,056 ----a-w C:\WINDOWS\system32\ati2cqag.dll 2008-05-22 22:18 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll 2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys 2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll 2008-04-21 07:04 659,456 ----a-w C:\WINDOWS\system32\wininet.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360] "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 20:34 5724184] "Steam"="C:\Program Files\Steam\Steam.exe" [2008-06-29 19:49 1271032] "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 21:17 61440] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 10:50 413696] "PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-07 02:05 200704] "Tarantula"="C:\Program Files\Razer\Tarantula\razerhid.exe" [2006-09-30 15:48 176128] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784] "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-07 00:51 1177368] "SkyTel"="SkyTel.EXE" [2006-05-15 21:04 2879488 C:\WINDOWS\SkyTel.exe] "RTHDCPL"="RTHDCPL.EXE" [2006-09-11 19:58 16264192 C:\WINDOWS\RTHDCPL.EXE] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{003E07F6-D7A2-456A-AE04-EB9ABF822FE4}"= "C:\WINDOWS\TEMP\Down(0)ow.dll" [2008-07-06 23:32 164096] "{00627A41-E883-4899-BD2E-1B6F926757E7}"= "C:\DOCUME~1\Raymond\LOCALS~1\Temp\bulmfiles.dll" [2008-07-07 00:12 13312] "{E8606370-4F7A-4C2F-A39C-EDCDCC177924}"= "C:\WINDOWS\system32\vcrxfileju.dll" [2008-07-07 00:12 20192] "{C51C4AFB-2A3A-6C2E-BA41-C10F02760731}"= "C:\DOCUME~1\Raymond\LOCALS~1\Temp\xptfhsylgfile.dll" [2008-07-07 00:12 25178] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa] 2003-05-25 12:11 60416 C:\WINDOWS\system32\antiwpa.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=avgrsstx.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Opera\\opera.exe"= "C:\\Program Files\\BitLord\\BitLord.exe"= "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "C:\\Program Files\\Warcraft III\\Warcraft III.exe"= "C:\\Program Files\\World of Warcraft\\WoW-2.4.2-enGB-downloader.exe"= "C:\\Program Files\\Steam\\steamapps\\spacedog650\\counter-strike source\\hl2.exe"= "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "C:\\Program Files\\AVG\\AVG8\\avgemc.exe"= "C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3724:TCP"= 3724:TCP:Blizzard Downloader: 3724 R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-07-07 00:51] R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-07 00:51] R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-07 00:51] R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-07 00:51] R2 avgfws8;AVG8 Firewall;C:\PROGRA~1\AVG\AVG8\avgfws8.exe [2008-07-07 00:51] R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-07 00:51] R3 Avgfwdx;Avgfwdx;C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2008-07-07 00:50] R3 TarFltr;Razer Tarantula USB Keyboard;C:\WINDOWS\system32\Drivers\UsbFltr.sys [2006-09-27 14:48] S2 RPCH;Remote Procedure Call (HPM);C:\Program Files\NetMeeting\Intell.exe [2005-06-16 12:37] S2 RPCM;Remote Procedure Manager(TPM);C:\Program Files\Common Files\Microsoft Shared\Speech\csvde.exe [] S3 Avgfwfd;AVG network filter service;C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2008-07-07 00:50] *Newly Created Service* - AVG8EMC *Newly Created Service* - AVG8WD *Newly Created Service* - AVGFWS8 *Newly Created Service* - AVGLDX86 *Newly Created Service* - AVGMFX86 *Newly Created Service* - AVGRKX86 *Newly Created Service* - AVGTDIX *Newly Created Service* - CATCHME *Newly Created Service* - RPCH *Newly Created Service* - SASDIFSV *Newly Created Service* - SASENUM *Newly Created Service* - SASKUTIL . - - - - ORPHANS REMOVED - - - - ShellExecuteHooks-{0046D7F0-5DF9-42C3-916E-5EE7D13D09DC} - C:\D@ ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-07 01:48:47 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-07-07 1:49:13 ComboFix-quarantined-files.txt 2008-07-06 23:49:11 Pre-Run: 457,462,517,760 bytes free Post-Run: 459,592,347,648 bytes free 224 --- E O F --- 2008-07-01 12:15:16 Klikk for å se/fjerne innholdet nedenfor SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 07/07/2008 at 01:45 AM Application Version : 4.15.1000 Core Rules Database Version : 3469 Trace Rules Database Version: 1460 Scan type : Complete Scan Total Scan Time : 00:25:39 Memory items scanned : 505 Memory threats detected : 0 Registry items scanned : 3695 Registry threats detected : 0 File items scanned : 12871 File threats detected : 51 Adware.Tracking Cookie C:\Documents and Settings\Raymond\Cookies\raymond@apmebf[1].txt C:\Documents and Settings\Raymond\Cookies\raymond@tribalfusion[1].txt C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt C:\Documents and Settings\Raymond\Cookies\raymond@partypoker[2].txt C:\Documents and Settings\Raymond\Cookies\raymond@overture[1].txt C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt C:\Documents and Settings\Raymond\Cookies\raymond@zedo[1].txt C:\Documents and Settings\Raymond\Cookies\raymond@serving-sys[1].txt C:\Documents and Settings\Raymond\Cookies\raymond@adtech[1].txt C:\Documents and Settings\Raymond\Cookies\[email protected][2].txt C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt C:\Documents and Settings\Raymond\Cookies\[email protected][2].txt C:\Documents and Settings\Raymond\Cookies\[email protected][2].txt C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt C:\Documents and Settings\Raymond\Cookies\raymond@tradedoubler[2].txt C:\Documents and Settings\Raymond\Cookies\raymond@revsci[2].txt C:\Documents and Settings\Raymond\Cookies\raymond@atdmt[1].txt C:\Documents and Settings\Raymond\Cookies\[email protected][2].txt C:\Documents and Settings\Raymond\Cookies\[email protected][2].txt C:\Documents and Settings\Raymond\Cookies\raymond@doubleclick[1].txt C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt C:\Documents and Settings\Raymond\Cookies\[email protected][2].txt C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt C:\Documents and Settings\Raymond\Cookies\raymond@2o7[1].txt C:\Documents and Settings\Raymond\Cookies\raymond@jh[1].txt C:\Documents and Settings\Raymond\Cookies\raymond@cgi-bin[2].txt C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt C:\Documents and Settings\Raymond\Cookies\[email protected][2].txt C:\Documents and Settings\Raymond\Cookies\raymond@adrevolver[2].txt C:\Documents and Settings\Raymond\Cookies\raymond@adbrite[2].txt C:\Documents and Settings\Raymond\Cookies\raymond@adrevolver[3].txt C:\Documents and Settings\Raymond\Cookies\raymond@clicktorrent[2].txt C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt C:\Documents and Settings\Raymond\Cookies\raymond@mediaplex[1].txt C:\Documents and Settings\Raymond\Cookies\[email protected][2].txt C:\Documents and Settings\Raymond\Cookies\[email protected][2].txt C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt C:\Documents and Settings\Raymond\Cookies\raymond@questionmarket[2].txt C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt C:\Documents and Settings\Raymond\Cookies\raymond@hitbox[2].txt C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt C:\Documents and Settings\Raymond\Cookies\raymond@advertising[1].txt C:\Documents and Settings\Raymond\Cookies\[email protected][2].txt C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt C:\Documents and Settings\Raymond\Cookies\raymond@statcounter[1].txt Ja, hvor mye virus har jeg?=P Edit: AVG finner noe som heter Adware.RogueSuspect. (TrackingCookie også men det får jeg uansett hvilken PC jeg skanner =P) HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0EDC6C20-A31C-11DB-8AB9-0800200C9A66] og HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\3AAC4C68-AFC8-11DB-80EF-8AF955D89593} De var ikke dær før jeg kjørte de scanene.. Endret 7. juli 2008 av Raytee Lenke til kommentar
norbat Skrevet 7. juli 2008 Forfatter Del Skrevet 7. juli 2008 Noe smårusk igjen. Prøv dette først (før evt. en manuell fjerning): Last ned MBAM til skrivebordet. Kjør fila og installer programmet. Velg Norsk språkdrakt La programmet oppdatere seg og velg å kjør en hurtig systemskann. Du får en meldingsboks når programmet er ferdigkjørt Klikk deretter på Vis resultat-knappen. Hvis det er funnet malware, vil du nå se hva som er funnet. Klikk på Fjern valgt -knappen for å fjerne malwaren som evt. ble funnet. Når MBAM er ferdig med å fjerne det den har funnet, vil det bli åpnet en logg i notisblokk. Den kan du kopiere og poste hvis det ble funnet noe. Lenke til kommentar
Raytee Skrevet 7. juli 2008 Del Skrevet 7. juli 2008 (endret) Klikk for å se/fjerne innholdet nedenfor Malwarebytes' Anti-Malware 1.19Database versjon: 899 Windows 5.1.2600 Service Pack 2 02:32:23 07.07.2008 mbam-log-7-7-2008 (02-32-20).txt Skanntype: Rask Skann Objekter skannet: 38748 Tid tilbakelagt: 4 minute(s), 1 second(s) Minneprosesser infisert: 0 Minnemoduler infisert: 0 Registernøkler infisert: 1 Registerverdier infisert: 0 Registerfiler infisert: 0 Mapper infisert: 0 Filer infisert: 1 Minneprosesser infisert: (Ingen mistenkelige filer funnet) Minnemoduler infisert: (Ingen mistenkelige filer funnet) Registernøkler infisert: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\antiwpa (Malware.Tool) -> No action taken. Registerverdier infisert: (Ingen mistenkelige filer funnet) Registerfiler infisert: (Ingen mistenkelige filer funnet) Mapper infisert: (Ingen mistenkelige filer funnet) Filer infisert: C:\WINDOWS\system32\antiwpa.dll (Malware.Tool) -> No action taken. To (småe?) ting igjen så er jeg helt virus/spyware fri?=P Hvordan fjerner jeg disse to da? Edit: Dette var et veldig dumt spm. =P Jeg fjernet de og nå står finner ingen virusprogram noen ''threats'' =D(Kommer ikke på hva ordet heter på norsk! Men vet hva det er på engelsk xD) Endret 7. juli 2008 av Raytee Lenke til kommentar
dataturisten Skrevet 11. juli 2008 Del Skrevet 11. juli 2008 Hei, Jeg har slitt med å bli kvitt 2 trojanere (Trojan Vundo.B & Trojan Horse). Når norton ikke klarte å ta det prøvde jeg 'oppskriften' her. Har kjørt alle søkene men har ikke gjort dette før så aner ikke hva jeg skal se etter for å se om det har blitt fjernet fullstendig. Hadde satt kjempepris på om noen kunne tatt en kikk på loggene for meg... Her er loggene: SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 07/11/2008 at 03:25 PM Application Version : 4.15.1000 Core Rules Database Version : 3502 Trace Rules Database Version: 1493 Scan type : Complete Scan Total Scan Time : 00:47:25 Memory items scanned : 836 Memory threats detected : 0 Registry items scanned : 9397 Registry threats detected : 0 File items scanned : 27520 File threats detected : 2 Adware.Tracking Cookie C:\Users\Ravin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt C:\Users\Ravin\AppData\Roaming\Microsoft\Windows\Cookies\Low\ravin@adtech[1].txt Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:33:02, on 11/07/2008 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16681) Boot mode: Normal Running processes: c:\Program Files\Bioscrypt\VeriSoft\Bin\AsGHost.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe C:\Program Files\Hp\QuickPlay\QPService.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Windows\System32\rundll32.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Skype\Phone\Skype.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe C:\Program Files\Telenor Sikker Lagring\safestorage.exe C:\Windows\System32\rundll32.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe C:\Windows\Explorer.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe C:\Users\Ravin\Desktop\test.exe.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- End of file - 3963 bytes ComboFix 08-07-10.1 - Ravin 2008-07-11 15:57:24.1 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.236 [GMT 5.5:30] Running from: C:\Users\Ravin\Desktop\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2008-06-11 to 2008-07-11 ))))))))))))))))))))))))))))))) . No new files created in this timespan . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-11 10:06 --------- d-----w C:\Users\Ravin\AppData\Roaming\Skype 2008-07-11 09:05 --------- d-----w C:\Users\Ravin\AppData\Roaming\SUPERAntiSpyware.com 2008-07-11 09:05 --------- d-----w C:\ProgramData\SUPERAntiSpyware.com 2008-07-11 09:05 --------- d-----w C:\Program Files\SUPERAntiSpyware 2008-07-11 09:04 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2008-07-11 08:50 --------- d-----w C:\ProgramData\NVIDIA 2008-07-11 08:35 72,616 ----a-w C:\Users\Ravin\AppData\Roaming\nvModes.dat 2008-07-10 15:50 --------- d-----w C:\Users\Ravin\AppData\Roaming\uTorrent 2008-07-10 15:40 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-07-10 15:33 --------- d-----w C:\Program Files\Red Kawa 2008-07-10 13:05 --------- d-----w C:\ProgramData\Symantec 2008-07-10 11:17 --------- d-----w C:\Users\Ravin\AppData\Roaming\Template 2008-07-10 11:08 262,144 ----a-w C:\ntuser.dat 2008-07-10 07:52 174 --sha-w C:\Program Files\desktop.ini 2008-07-10 07:38 --------- d-----w C:\Program Files\Windows Mail 2008-07-10 07:30 --------- d-----w C:\Program Files\Norton 360 Online 2008-07-09 14:18 --------- d-----w C:\Users\Ravin\AppData\Roaming\LimeWire 2008-07-09 14:14 --------- d-----w C:\Program Files\LimeWire 2008-07-08 14:07 --------- d-----w C:\Users\Ravin\AppData\Roaming\Symantec 2008-07-08 11:47 805 ----a-w C:\Windows\system32\drivers\SYMEVENT.INF 2008-07-08 11:47 123,952 ----a-w C:\Windows\system32\drivers\SYMEVENT.SYS 2008-07-08 11:47 10,671 ----a-w C:\Windows\system32\drivers\SYMEVENT.CAT 2008-07-08 11:47 --------- d-----w C:\Program Files\Symantec 2008-07-08 11:46 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2008-07-08 09:42 --------- d-----w C:\Program Files\Telenor Sikker Lagring 2008-07-08 09:36 --------- d-----w C:\Users\Ravin\AppData\Roaming\Telenor 2008-07-08 09:06 0 ----a-w C:\nis2008.exe 2008-06-24 07:45 --------- d-----w C:\Users\Ravin\AppData\Roaming\Nokia 2008-06-21 19:08 0 ---ha-w C:\Windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf 2008-06-21 19:04 --------- d-----w C:\Program Files\Nokia 2008-06-14 09:32 --------- d-----w C:\Program Files\Sony 2008-06-14 09:07 --------- d-----w C:\Users\Ravin\AppData\Roaming\Sony Corporation 2008-06-14 09:04 --------- d-----w C:\Program Files\Picasa2 2008-06-14 07:50 --------- d-----w C:\Program Files\Google 2008-06-13 16:56 --------- d-----w C:\Users\Ravin\AppData\Roaming\PC Suite 2008-06-13 16:55 --------- d-----w C:\ProgramData\PC Suite 2008-06-13 16:51 --------- d-----w C:\Program Files\Common Files\PCSuite 2008-06-13 16:51 --------- d-----w C:\Program Files\Common Files\Nokia 2008-06-13 16:50 --------- d-----w C:\Program Files\DIFX 2008-06-13 16:46 --------- d-----w C:\Program Files\PC Connectivity Solution 2008-06-13 16:40 --------- d-----w C:\ProgramData\Installations 2008-06-05 06:33 --------- d-----w C:\Program Files\PalickSoft 2008-06-02 04:41 2,147,544 ----a-w C:\Windows\system32\drivers\RTKVHDA.sys 2008-05-29 16:03 --------- d-----w C:\Users\Ravin\AppData\Roaming\Logitech 2008-05-29 16:03 --------- d-----w C:\ProgramData\LogiShrd 2008-05-29 15:58 --------- d-----w C:\Program Files\Common Files\Logishrd 2008-05-29 15:57 --------- d-----w C:\ProgramData\Logitech 2008-05-29 15:57 --------- d-----w C:\Program Files\Logitech 2008-05-28 02:36 6,144,000 ----a-w C:\Windows\RtHDVCpl.exe 2008-04-25 04:23 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll 2007-08-03 05:39 0 ----a-w C:\Users\Ravin\AppData\Roaming\wklnhst.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-13 01:04 1232896] "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 18:05 125440] "Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-05-30 15:54 21718312] "Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe" [2008-03-26 18:41 1232896] "PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2008-04-16 12:53 1079808] "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 18:06 201728] "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-10-09 10:13 729088] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 02:05 1045800] "HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 16:24 54840] "QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2007-03-29 06:15 176128] "HP Health Check Scheduler"="C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-03-13 00:24 50696] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496] "CognizanceTS"="c:\PROGRA~1\BIOSCR~1\VeriSoft\Bin\ASTSVCC.dll" [2003-12-23 00:42 17920] "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 04:17 31016] "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 19:10 155648] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24 286720] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-14 10:00 267064] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048] "SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 02:29 102400] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 11:29 115816] "MSConfig"="C:\Windows\system32\msconfig.exe" [2006-11-02 15:15 222208] "NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-11-07 02:35 86016] "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-11-07 02:35 8534560] "NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-11-07 02:35 81920] "RtHDVCpl"="RtHDVCpl.exe" [2008-05-28 08:06 6144000 C:\Windows\RtHDVCpl.exe] C:\Users\Ravin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 23:54:54 98632] Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2008-06-14 12:45:29 385024] Telenor Sikker Lagring.lnk - C:\Program Files\Telenor Sikker Lagring\safestorage.exe [2008-07-08 14:58:09 43008] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-12-20 15:57:40 719664] HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-01-03 01:10:10 210520] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UacDisableNotify"=dword:00000001 "InternetSettingsDisableNotify"=dword:00000001 "AutoUpdateDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{915A2B2E-5408-464A-AA15-FF734E492C4D}"= C:\Program Files\HP\QuickPlay\QP.exe:Quick Play "{3012EBBA-0370-44A6-87B3-D50F4CDE022A}"= C:\Program Files\HP\QuickPlay\QPService.exe:Quick Play Resident Program "{EDD813E2-863D-4548-B8B1-C98D98F2D0E5}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook "{05D277DB-D577-4C7D-A4D8-E0BF86D70E8E}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{E9D8D2CE-B4B5-4A0F-AD5C-4E66FC7B2DD9}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{263E4796-CE69-48A6-9DC0-676AE793C0D6}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{B88F6876-4B60-4DE2-BDEB-A13493ABEE8A}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{91F050BE-7912-4CE1-A380-8109E54CCD58}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes "{C2343607-FDE3-4BD4-BCAF-A5366D42C746}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes "{5DEB48B4-8E59-4FD7-90DF-89C15242AD6F}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent "{CA825080-8965-43E2-A3D8-48F09D3FE706}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent "{5352130D-A163-4A07-AAAF-4503A7B87E3F}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "{25E84F1A-96B7-410F-AE38-C707E761825F}"= UDP:C:\Program Files\Online Services\SkypeSV\SkypeSetup.exe:Skype "{85362CD1-1422-41C8-BFB6-F9175780E920}"= TCP:C:\Program Files\Online Services\SkypeSV\SkypeSetup.exe:Skype "TCP Query User{6F887F06-5A47-4151-9B12-8DEA79928F88}C:\\program files\\skype\\phone\\skype.exe"= UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath "UDP Query User{1E831883-DD9D-4744-B329-3E838B846EF2}C:\\program files\\skype\\phone\\skype.exe"= TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath "{04FD6D47-7603-414F-ADD6-CD168234AFA0}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent "{7B32A4A4-F73B-4987-BC0A-C9CB3AA65632}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent "{4B57B943-3EE9-4B1B-B52D-773B389099DE}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire "{17581F74-36BD-4AB0-85B3-7B805583E027}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire "TCP Query User{B69AD71A-CA88-44A0-816D-6701BD768615}C:\\program files\\skype\\phone\\skype.exe"= UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath "UDP Query User{47B62720-0442-4781-B070-5E1590B55C23}C:\\program files\\skype\\phone\\skype.exe"= TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath "TCP Query User{BA1393A3-1025-4437-A3E9-786EFFD6D8AB}C:\\windows\\system32\\ftp.exe"= UDP:C:\windows\system32\ftp.exe:File Transfer Program "UDP Query User{4F2C6873-89D6-4091-B164-D3D098F054FB}C:\\windows\\system32\\ftp.exe"= TCP:C:\windows\system32\ftp.exe:File Transfer Program "TCP Query User{5ED97D1B-ABAD-40BB-97D5-0DDD5CE8FDC7}C:\\users\\ravin\\program files\\utorrent\\utorrent.exe"= UDP:C:\users\ravin\program files\utorrent\utorrent.exe:utorrent.exe "UDP Query User{1C05E718-B957-427B-88A1-B7933F8196C4}C:\\users\\ravin\\program files\\utorrent\\utorrent.exe"= TCP:C:\users\ravin\program files\utorrent\utorrent.exe:utorrent.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System] "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic| [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ Cognizance REG_MULTI_SZ ASBroker ASChannel GPSvcGroup REG_MULTI_SZ GPSvc HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4e6928e7-20ce-11dd-ac61-001a6b89376b}] \shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL remove.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8bdb7c15-16b9-11dd-b43d-001b244258e4}] \shell\AutoRun\command - F:\fun.exe \shell\explore\Command - F:\fun.exe \shell\open\Command - F:\fun.exe *Newly Created Service* - COMHOST . Contents of the 'Scheduled Tasks' folder "2008-06-30 15:05:27 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Ravin.job" - c:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK: . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-11 16:08:50 Windows 6.0.6000 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Windows\System32\audiodg.exe C:\Windows\System32\wisptis.exe C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Windows\System32\wlanext.exe C:\Program Files\Bioscrypt\VeriSoft\Bin\asghost.exe C:\Windows\System32\wisptis.exe C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Hp\QuickPlay\Kernel\TV\CLCapSvc.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files\Hp\QuickPlay\Kernel\TV\CLSched.exe C:\Windows\System32\conime.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\wbem\unsecapp.exe C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe C:\Windows\System32\wbem\WMIADAP.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\System32\rundll32.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe C:\Program Files\PC Connectivity Solution\ServiceLayer.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe . ************************************************************************** . Completion time: 2008-07-11 16:18:23 - machine was rebooted [Ravin] ComboFix-quarantined-files.txt 2008-07-11 10:47:31 The system cannot find message text for message number 0x2379 in the message file for Application. Post-Run: 90,507,902,976 bytes free 215 --- E O F --- 2008-07-11 09:43:26 Lenke til kommentar
r2d290 Skrevet 11. juli 2008 Del Skrevet 11. juli 2008 (endret) Er du sikker på at du har fått med hele HijackThis-loggen? Synes det er rart at du ikke har noe mellom "running processes" og "O23"-linjene. Her er et eksempel på en full HijackThis-logg: Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programfiler\Sygate\SPF\smc.exe C:\WINDOWS\system32\spoolsv.exe c:\programfiler\fellesfiler\logitech\lvmvfm\LVPrcSrv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\system32\LVCOMSX.EXE C:\Programfiler\Logitech\Video\CameraAssistant.exe C:\WINDOWS\system32\ElkCtrl.exe C:\WINDOWS\SOUNDMAN.EXE C:\Programfiler\Java\jre1.5.0_07\bin\jusched.exe C:\Programfiler\Ahead\InCD\InCD.exe C:\Programfiler\MSN Messenger\MsnMsgr.Exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Kenneth\Skrivebord\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://stealthy.foolishgames.net/news.php R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Programfiler\Logitech\Video\CameraAssistant.exe O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Programfiler\Logitech\Video\InstallHelper.exe /inspect O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Programfiler\RivaTuner v2.0 RC 16\RivaTuner.exe" /S O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background O8 - Extra context menu item: Write a Review... - http://client.alexa.com/holiday/script/actions/review.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\System32\shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programfiler\fellesfiler\logitech\lvmvfm\LVPrcSrv.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Programfiler\Sygate\SPF\smc.exe Prøv en gang til, og se om du fortsatt får samme HijackThis-logg... Vidre gjor du følgende: Gå til http://virusscan.jotti.org , trykk på Browse, og last opp følgende fil til analyse: F:\fun.exe Deretter trykker du på Submit. Godta at filen blir scannet. Til slutt kopierer du resultatet, og limer det inn i din neste post, så jeg kan se på den, og vurdere hva som må gjøres videre. Det kan hende du er nødt til å skru på skjulte filer og mapper for å kunne finne denne fila: http://windowshelp.microsoft.com/Windows/n...04a59f1044.mspx Endret 11. juli 2008 av r2d290 Lenke til kommentar
r2d290 Skrevet 11. juli 2008 Del Skrevet 11. juli 2008 En ting til: Det ser ut til at du har HijackThis kjørende direkte fra Skrivebordet. Hvis du gjør dette, vil ikke HijackThis kunne ta backup av det vi eventuelt fjerner. Siden backup er viktig, bør du flytte denne fila inn i en egen mappe (f.eks i C:\hjt). Du kommer ikke til å få mer respons før du har gjort dette... Si ifra når det er gjort, eller post en ny logg som viser at det er gjort Lenke til kommentar
C 22 Skrevet 12. juli 2008 Del Skrevet 12. juli 2008 Så nettopp at en fil som heter NirCmd.cfexe prøvde å avslutte firewallen (ca samtidig som jeg fjernet Combofix). Er dette normalt eller er det en eller annen form for malware? Lenke til kommentar
norbat Skrevet 12. juli 2008 Forfatter Del Skrevet 12. juli 2008 NirCmd.cfexe er en del av combofix Lenke til kommentar
matseeey Skrevet 14. juli 2008 Del Skrevet 14. juli 2008 (endret) får opp statig pop ups som "http://nolanding.ringtonetimesDOTnet/ og andre ringtetone sider reklamere for.. Hvordan får jeg pop upsen bort??? c Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:40:29, on 14.07.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programfiler\Fellesfiler\Symantec Shared\ccSetMgr.exe C:\Programfiler\Fellesfiler\Symantec Shared\ccEvtMgr.exe C:\Programfiler\Fellesfiler\Symantec Shared\SPBBC\SPBBCSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Programfiler\Java\jre1.6.0_05\bin\jusched.exe C:\WINDOWS\RTHDCPL.EXE C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe D:\Programmer\office\Office12\GrooveMonitor.exe C:\WINDOWS\system32\ctfmon.exe C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe C:\Programfiler\Messenger\msmsgs.exe C:\Programfiler\Bonjour\mDNSResponder.exe C:\Programfiler\Symantec AntiVirus\DefWatch.exe C:\Programfiler\Symantec AntiVirus\Rtvscan.exe C:\Programfiler\Windows Live\Messenger\usnsvc.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\Is6l38sq.exe C:\Programfiler\Mozilla Firefox\firefox.exe D:\Programfiler\Ny mappe\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Koblingshjelpeprogram for Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\office\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [ccApp] "C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [synTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [GrooveMonitor] "D:\Programmer\office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Programfiler\Adobe\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [WinampAgent] C:\Programfiler\Winamp\winampa.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\msmsgs.exe" /background O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\office\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\office\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\office\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\office\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = (skjult) O17 - HKLM\Software\..\Telephony: DomainName = (skjult) O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = (skjult) O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = (skjult) O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\office\Office12\GR99D3~1.DLL O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Programfiler\Bonjour\mDNSResponder.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Programfiler\Symantec AntiVirus\DefWatch.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programfiler\Fellesfiler\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: SAVRoam (SavRoam) - symantec - C:\Programfiler\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Programfiler\Symantec AntiVirus\Rtvscan.exe -- End of file - 8077 bytes Endret 14. juli 2008 av matseeey Lenke til kommentar
norbat Skrevet 14. juli 2008 Forfatter Del Skrevet 14. juli 2008 Kjør gjennom veiledningen du finner i 1.post i denne tråd. Opprett en egen tråd der du legger de loggene det spørres etter. Lenke til kommentar
Lock-Aze Skrevet 17. juli 2008 Del Skrevet 17. juli 2008 Hei, har en terminalserver som jeg mistenker har spyware. Jeg blir ikke skikkelig klok på den, kan noen være så snill og se på hijackthis loggen og se om det er noe å hente fra den. Det var desverre alt jeg hadde tid til å kjøre i dag. Har kjørt Ccleaner og superantispyware først. Trenger all den hjelp jeg kan få, da jeg er møkklei av å havne på div. spamfilter... Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:09:09, on 17.07.2008 Platform: Windows 2003 SP2 (WinNT 5.02.3790) MSIE: Internet Explorer v6.00 SP2 (6.00.3790.3959) Boot mode: Normal Running processes: M:\Documents and Settings\Administrator.NORVAG\WINDOWS\System32\smss.exe M:\WINDOWS\system32\winlogon.exe M:\WINDOWS\system32\services.exe M:\WINDOWS\system32\lsass.exe M:\WINDOWS\system32\svchost.exe M:\WINDOWS\System32\svchost.exe M:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe M:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe M:\WINDOWS\system32\brsvc01a.exe M:\WINDOWS\system32\spoolsv.exe M:\WINDOWS\system32\brss01a.exe M:\Program Files\Symantec AntiVirus\DefWatch.exe M:\WINDOWS\System32\svchost.exe M:\Program Files\LogMeIn\x86\RaMaint.exe M:\Program Files\LogMeIn\x86\LogMeIn.exe M:\Program Files\LogMeIn\x86\LMIGuardian.exe M:\Program Files\Symantec AntiVirus\SavRoam.exe M:\Program Files\Symantec AntiVirus\Rtvscan.exe M:\WINDOWS\system32\lserver.exe m:\program files\software innovation\vega5\vegasmb.tools.trace.service.exe M:\Program Files\Citrix\system32\cdmsvc.exe M:\Program Files\Citrix\System32\ctxxmlss.exe M:\Program Files\Citrix\system32\encsvc.exe M:\Program Files\Citrix\System32\Citrix\Ima\ImaSrv.exe M:\Program Files\Citrix\System32\mfcom.exe M:\WINDOWS\System32\svchost.exe M:\WINDOWS\system32\winlogon.exe M:\WINDOWS\System32\svchost.exe M:\Program Files\Citrix\ICA Client\ssonsvr.exe M:\WINDOWS\Explorer.EXE M:\Program Files\Citrix\system32\icabar.exe M:\Program Files\Common Files\Symantec Shared\ccApp.exe M:\PROGRA~1\SYMANT~1\VPTray.exe M:\Program Files\Java\jre1.6.0_07\bin\jusched.exe M:\Program Files\LogMeIn\x86\LogMeInSystray.exe M:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe M:\WINDOWS\system32\ctfmon.exe M:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe M:\Program Files\LogMeIn\x86\LMIGuardian.exe M:\Program Files\WinZip\WZQKPICK.EXE M:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe M:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe M:\WINDOWS\system32\winlogon.exe M:\WINDOWS\system32\winlogon.exe M:\WINDOWS\system32\winlogon.exe M:\WINDOWS\system32\winlogon.exe M:\WINDOWS\system32\winlogon.exe M:\WINDOWS\system32\winlogon.exe M:\WINDOWS\system32\winlogon.exe M:\WINDOWS\system32\winlogon.exe M:\WINDOWS\system32\winlogon.exe M:\WINDOWS\system32\winlogon.exe M:\Program Files\Internet Explorer\IEXPLORE.EXE M:\Program Files\LogMeIn\x86\LogMeIn.exe M:\Program Files\LogMeIn\x86\LMIGuardian.exe M:\Documents and Settings\Administrator.NORVAG\Desktop\kjeks\testprog.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.no R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.no R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = M:\WINDOWS\system32\blank.htm R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Norvag F2 - REG:system.ini: UserInit=M:\WINDOWS\system32\userinit.exe, O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - M:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - M:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - m:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - M:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - m:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [icaBar] "M:\Program Files\Citrix\system32\icabar.exe" /adminonly O4 - HKLM\..\Run: [ccApp] "M:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] M:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "M:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [LogMeIn GUI] "M:\Program Files\LogMeIn\x86\LogMeInSystray.exe" O4 - HKLM\..\Run: [Google Desktop Search] "M:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKCU\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] M:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-21-17155eg blir 67821-725345543-1417001333-1120\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'tot') O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1120\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'tot') O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1122\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'ao') O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1122\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'ao') O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1126\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'ek') O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1126\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'ek') O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1130\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'js') O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1130\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'js') O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1133\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'ka') O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1142\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'le') O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1142\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'le') O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1190\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'idarp') O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1190\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'idarp') O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1195\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'frodea') O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1612\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'perh') O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1614\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'bodobutikk') O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1614\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'bodobutikk') O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1615\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'jonnyo') O4 - HKUS\S-1-5-21-3295084221-2774560929-1612176347-1004\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\CTFMON.EXE (User 'Ctx_SmaUser') O4 - HKUS\S-1-5-21-3295084221-2774560929-1612176347-1004\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Ctx_SmaUser') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user') O4 - Global Startup: Hurtigstart for Adobe Reader.lnk = M:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: WinZip Quick Pick.lnk = M:\Program Files\WinZip\WZQKPICK.EXE O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://M:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - M:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - M:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - M:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL O10 - Broken Internet access because of LSP provider 'm:\documents and settings\administrator.norvag\windows\system32\mswsock.dll' missing O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1160999908231 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = norvag.no O17 - HKLM\Software\..\Telephony: DomainName = norvag.no O17 - HKLM\System\CCS\Services\Tcpip\..\{CD3C6594-6A07-4B19-89C4-C3FAE82CFCFE}: NameServer = 192.168.1.10 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = norvag.no O20 - AppInit_DLLs: mfaphook.dll M:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - M:\WINDOWS\system32\brsvc01a.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - M:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - M:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - M:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Diagnostic Facility COM Server (CdfSvc) - Citrix Systems, Inc. - M:\Program Files\Common Files\Citrix\System32\CdfSvc.exe O23 - Service: Client Network (CdmService) - Citrix Systems, Inc. - M:\Program Files\Citrix\system32\cdmsvc.exe O23 - Service: Citrix SMA Service - Citrix Systems Inc. - M:\Program Files\Citrix\Sma\SmaService.exe O23 - Service: Citrix Virtual Memory Optimization - Citrix Systems, Inc. - M:\Program Files\Citrix\Server Resource Management\Memory Optimization Management\Program\CtxSFOSvc.exe O23 - Service: Citrix XTE Server (CitrixXTEServer) - Citrix Systems, Inc. - M:\Program Files\Citrix\XTE\bin\XTE.exe O23 - Service: Citrix Print Manager Service (cpsvc) - Citrix Systems, Inc. - M:\Program Files\Citrix\system32\CpSvc.exe O23 - Service: Citrix CPU Utilization Mgmt/Resource Mgmt (ctxcpuSched) - Aurema Pty Limited - M:\Program Files\Citrix\Server Resource Management\CPU Utilization Management\bin\ctxcpusched.exe O23 - Service: Citrix CPU Utilization Mgmt/User-Session Sync (CTXCPUUsync) - Aurema Pty Limited - M:\Program Files\Citrix\Server Resource Management\CPU Utilization Management\bin\ctxcpuusync.exe O23 - Service: Citrix XML Service (CtxHttp) - Citrix Systems, Inc. - M:\Program Files\Citrix\System32\ctxxmlss.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - M:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: Encryption Service - Citrix Systems, Inc. - M:\Program Files\Citrix\system32\encsvc.exe O23 - Service: GoogleDesktopManager - Google - M:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updater Service (gusvc) - Google - M:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Independent Management Architecture (IMAService) - Citrix Systems, Inc. - M:\Program Files\Citrix\System32\Citrix\Ima\ImaSrv.exe O23 - Service: InfoCenter - Software Innovation asa - M:\Program Files\Software Innovation\InfoCenter\infocsvc.exe O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - M:\Program Files\LogMeIn\x86\RaMaint.exe O23 - Service: LogMeIn - LogMeIn, Inc. - M:\Program Files\LogMeIn\x86\LogMeIn.exe O23 - Service: MetaFrame COM Server (MFCom) - Citrix Systems, Inc. - M:\Program Files\Citrix\System32\mfcom.exe O23 - Service: Phobos - Software Innovation asa - M:\Program Files\Software Innovation\Polaris\phobos.exe O23 - Service: SAVRoam (SavRoam) - symantec - M:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - M:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - M:\Program Files\Symantec AntiVirus\Rtvscan.exe O23 - Service: VegaSMB.Indexing.Service - Unknown owner - m:\program files\software innovation\vega5\vegasmb.indexing.service.exe O23 - Service: VegaSMB.Tools.Trace.Service - Unknown owner - m:\program files\software innovation\vega5\vegasmb.tools.trace.service.exe -- End of file - 12851 bytes Lenke til kommentar
norbat Skrevet 17. juli 2008 Forfatter Del Skrevet 17. juli 2008 Fila M:\Documents and Settings\Administrator.NORVAG\WINDOWS\System32\smss.exe bruker kanskje å kjøre fra denne plasseringen på serveren? (Vanlig plassering er WINDOWS\System32\smss.exe). Hva gjør at du mistenker malware? Lenke til kommentar
Lock-Aze Skrevet 17. juli 2008 Del Skrevet 17. juli 2008 Det at det er den eneste maskina i nettverket som har lov til å sende på port 25 og jeg har problemer med at jeg blir utestengt fra div spamfilter pga spam. Her er feedbacken jeg får fra en av svartelistene: ATTENTION: This IP is infected with, or NATting for a computer infected with a high volume spam sending trojan - it is participating in a botnet. This is the Srizbi BOT You need to patch your system and then fix/remove the trojan. Do this before delisting, or you're most likely to be listed again almost immediately. If this IP is a NAT firewall/gateway, you MUST configure the NAT to prevent outbound port 25 connections to the Internet except from your real mail servers. Lenke til kommentar
Bartin Skrevet 22. juli 2008 Del Skrevet 22. juli 2008 SAS logg SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 07/22/2008 at 01:59 AM Application Version : 4.15.1000 Core Rules Database Version : 3469 Trace Rules Database Version: 1460 Scan type : Quick Scan Total Scan Time : 00:18:51 Memory items scanned : 476 Memory threats detected : 13 Registry items scanned : 487 Registry threats detected : 104 File items scanned : 9797 File threats detected : 134 Adware.Adservs C:\WINDOWS\SMFUIEHVBHZPAW\ASAPPSRV.DLL C:\WINDOWS\SMFUIEHVBHZPAW\ASAPPSRV.DLL C:\WINDOWS\system32\atmtd.dll C:\WINDOWS\system32\atmtd.dll._ C:\WINDOWS\SYSTEM32\MD4\VOMB33DLL.EXE Trojan.Vundo-Variant/Small C:\WINDOWS\SYSTEM32\SXGBWBSO.DLL C:\WINDOWS\SYSTEM32\SXGBWBSO.DLL C:\WINDOWS\SYSTEM32\PINPXUOK.DLL C:\WINDOWS\SYSTEM32\PINPXUOK.DLL HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d74a6b4f-8280-42ca-adfa-73163665b7d7} HKCR\CLSID\{D74A6B4F-8280-42CA-ADFA-73163665B7D7} HKCR\CLSID\{D74A6B4F-8280-42CA-ADFA-73163665B7D7}\InprocServer32 HKCR\CLSID\{D74A6B4F-8280-42CA-ADFA-73163665B7D7}\InprocServer32#ThreadingModel C:\WINDOWS\SYSTEM32\ABDIYILJ.DLL C:\WINDOWS\SYSTEM32\PFLQBCFD.DLL C:\WINDOWS\SYSTEM32\RUGWVUEW.DLL C:\WINDOWS\SYSTEM32\WHSKWPVV.DLL Trojan.Vundo-Variant/F C:\WINDOWS\SYSTEM32\IIFGFGG.DLL C:\WINDOWS\SYSTEM32\IIFGFGG.DLL Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\iifgfgg C:\WINDOWS\SYSTEM32\EFCDDDD.DLL C:\WINDOWS\SYSTEM32\IIFFEUUO.DLL Adware.Vundo Variant/Resident C:\WINDOWS\SYSTEM32\MLLMK.DLL C:\WINDOWS\SYSTEM32\MLLMK.DLL Unclassified.Unknown Origin C:\WINDOWS\SMFUIEHVBHZPAW\COMMAND.EXE C:\WINDOWS\SMFUIEHVBHZPAW\COMMAND.EXE Trojan.NetMon/DNSChange C:\PROGRAMFILER\NETWORK MONITOR\NETMON.EXE C:\PROGRAMFILER\NETWORK MONITOR\NETMON.EXE HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor#Type HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor#Start HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor#ErrorControl HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor#ImagePath HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor#DisplayName HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor#ObjectName HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor\Security HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor\Security#Security HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor\Enum HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor\Enum#0 HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor\Enum#Count HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor\Enum#NextInstance HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR#NextInstance HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR00 HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR00#Service HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR00#Legacy HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR00#ConfigFlags HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR00#Class HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR00#ClassGUID HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR00#DeviceDesc HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR00\Control HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR00\Control#ActiveService HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A394E835-C8D6-4B4B-884B-D2709059F3BE} HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A394E835-C8D6-4B4B-884B-D2709059F3BE}#Contact HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A394E835-C8D6-4B4B-884B-D2709059F3BE}#DisplayName HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A394E835-C8D6-4B4B-884B-D2709059F3BE}#DisplayVersion HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A394E835-C8D6-4B4B-884B-D2709059F3BE}#NoModify HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A394E835-C8D6-4B4B-884B-D2709059F3BE}#NoRemove HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A394E835-C8D6-4B4B-884B-D2709059F3BE}#NoRepair HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A394E835-C8D6-4B4B-884B-D2709059F3BE}#UninstallString C:\Programfiler\Network Monitor Trojan.Downloader-Gen/Svchost-Fake C:\WINDOWS\FONTS\SVCHOST.EXE C:\WINDOWS\FONTS\SVCHOST.EXE C:\WINDOWS\Prefetch\SVCHOST.EXE-178E8C2A.pf Adware.JavaCore C:\PROGRAMFILER\JAVACORE\JAVACORE.EXE C:\PROGRAMFILER\JAVACORE\JAVACORE.EXE [JavaCore] C:\PROGRAMFILER\\JAVACORE\\JAVACORE.EXE C:\PROGRAMFILER\\JAVACORE\\JAVACORE.EXE C:\WINDOWS\Prefetch\JAVACORE.EXE-33709A79.pf Adware.ClickSpring-Variant C:\WINDOWS\SSTEM3~1\SMSS.EXE C:\WINDOWS\SSTEM3~1\SMSS.EXE [sira] C:\WINDOWS\SSTEM3~1\SMSS.EXE C:\WINDOWS\S?STEM32\SMSS.EXE C:\WINDOWS\Prefetch\SMSS.EXE-2A18F5C8.pf Adware.ClickSpring/Resident C:\PROGRA~1\STEM32~1\DXPLOR~1.EXE C:\PROGRA~1\STEM32~1\DXPLOR~1.EXE C:\WINDOWS\SYSTEM32\GPOOE.DLL C:\WINDOWS\SYSTEM32\GPOOE.DLL Trojan.Downloader-NewJuan/VM C:\WINDOWS\SYSTEM32\LVLNNNXT.DLL C:\WINDOWS\SYSTEM32\LVLNNNXT.DLL Trojan.Downloader-SVCHost/Fake [Host Process] C:\WINDOWS\FONTS\SVCHOST.EXE Adware.Vundo Variant HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{57B56E77-ACE3-4A90-8171-64A39F880E9F} HKCR\CLSID\{57B56E77-ACE3-4A90-8171-64A39F880E9F} HKCR\CLSID\{57B56E77-ACE3-4A90-8171-64A39F880E9F}\InprocServer32 HKCR\CLSID\{57B56E77-ACE3-4A90-8171-64A39F880E9F}\InprocServer32#ThreadingModel HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{70AB0A8B-8A8A-496F-A339-4CD2F3352991} HKCR\CLSID\{70AB0A8B-8A8A-496F-A339-4CD2F3352991} HKCR\CLSID\{70AB0A8B-8A8A-496F-A339-4CD2F3352991}\InprocServer32 HKCR\CLSID\{70AB0A8B-8A8A-496F-A339-4CD2F3352991}\InprocServer32#ThreadingModel HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EFFB38AD-AC35-F1C4-1793-A18F02232EC3} HKCR\CLSID\{EFFB38AD-AC35-F1C4-1793-A18F02232EC3} HKCR\CLSID\{EFFB38AD-AC35-F1C4-1793-A18F02232EC3}\InprocServer32 HKCR\CLSID\{EFFB38AD-AC35-F1C4-1793-A18F02232EC3}\InprocServer32#ThreadingModel HKCR\CLSID\{EFFB38AD-AC35-F1C4-1793-A18F02232EC3}\Programmable HKCR\CLSID\{EFFB38AD-AC35-F1C4-1793-A18F02232EC3}\TypeLib HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{70AB0A8B-8A8A-496F-A339-4CD2F3352991} HKCR\CLSID\{70AB0A8B-8A8A-496F-A339-4CD2F3352991} Adware.Tracking Cookie Trojan.cmdService HKLM\SYSTEM\CurrentControlSet\Services\cmdService HKLM\SYSTEM\CurrentControlSet\Services\cmdService#Type HKLM\SYSTEM\CurrentControlSet\Services\cmdService#Start HKLM\SYSTEM\CurrentControlSet\Services\cmdService#ErrorControl HKLM\SYSTEM\CurrentControlSet\Services\cmdService#ImagePath HKLM\SYSTEM\CurrentControlSet\Services\cmdService#DisplayName HKLM\SYSTEM\CurrentControlSet\Services\cmdService#ObjectName HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Security HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Security#Security HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum#0 HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum#Count HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum#NextInstance HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920} HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}#Contact HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}#DisplayName HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}#DisplayVersion HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}#NoModify HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}#NoRemove HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}#NoRepair HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}#UninstallString HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE#NextInstance HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE00 HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE00#Service HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE00#Legacy HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE00#ConfigFlags HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE00#Class HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE00#ClassGUID HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE00#DeviceDesc HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE00\Control HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE00\Control#ActiveService Adware.ClickSpring/Outer Info Network HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#Publisher HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#DisplayName HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#UninstallString HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#HelpLink HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#InstallLocation HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#NoModify HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#NoRepair HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#DisplayVersion HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#DisplayIcon C:\Programfiler\Outerinfo\FF\chrome.manifest C:\Programfiler\Outerinfo\FF\components\FF.dll C:\Programfiler\Outerinfo\FF\components\OuterinfoAds.xpt C:\Programfiler\Outerinfo\FF\components C:\Programfiler\Outerinfo\FF\install.rdf C:\Programfiler\Outerinfo\FF C:\Programfiler\Outerinfo\Terms.rtf C:\Programfiler\Outerinfo C:\Documents and Settings\Eier\Start-meny\Programmer\Outerinfo\Terms.lnk C:\Documents and Settings\Eier\Start-meny\Programmer\Outerinfo\Uninstall.lnk C:\Documents and Settings\Eier\Start-meny\Programmer\Outerinfo Trojan.Downloader-Gen/RetAd HKLM\Software\Microsoft\Windows\CurrentVersion\Run#runner1 [ C:\WINDOWS\mrofinu1188.exe 61A847B5BBF72813339330466188719AB689201522886B092CBD44BD8689220221DD325762EA4EBF968951185E C412806867680AEDE604D64C2661373F819EBDCD66A47 ] Rogue.SysCleaner HKU\S-1-5-21-2820906742-3425357240-438028536-1007\Software\xInsiDERexe Adware.WinTouch/XInside C:\Programfiler\InetGet2 Adware.JavaCore/NoDNS C:\Programfiler\JavaCore\UnInstall.exe C:\Programfiler\JavaCore HKU\S-1-5-21-2820906742-3425357240-438028536-1007\Software\Microsoft\Windows\CurrentVersion\Run#JavaCore [ C:\Programfiler\\JavaCore\\JavaCore.exe ] Trojan.Unclassified/NVCOI C:\Programfiler\Temporary\InsiDERInst.exe C:\Programfiler\Temporary C:\WINDOWS\Prefetch\INSIDERINST.EXE-23669BF1.pf Adware.Vundo Variant/Rel HKLM\SOFTWARE\Microsoft\aoprndtws HKLM\SOFTWARE\Microsoft\RemoveRP HKU\S-1-5-21-2820906742-3425357240-438028536-1007\Software\Microsoft\rdfa C:\WINDOWS\SYSTEM32\KMLLM.INI C:\WINDOWS\SYSTEM32\KMLLM.INI2 Trojan.Unclassified/Zombie C:\DOCUMENTS AND SETTINGS\EIER\LSASS.EXE C:\WINDOWS\Prefetch\LSASS.EXE-39593BC0.pf Adware.ClickSpring/Yazzle C:\PROGRAMFILER\FELLESFILER\YAZZLE1560OINUNINSTALLER.EXE Trojan.Downloader-Gen/Bundle Installer C:\WINDOWS\B128.EXE C:\WINDOWS\B152.EXE C:\WINDOWS\B153.EXE C:\WINDOWS\B156.EXE C:\WINDOWS\Prefetch\B128.EXE-13D9CEE5.pf C:\WINDOWS\Prefetch\B152.EXE-2574C670.pf C:\WINDOWS\Prefetch\B153.EXE-298A1742.pf C:\WINDOWS\Prefetch\B156.EXE-36A8F193.pf Trojan.Downloader-Gen/MROFIN C:\WINDOWS\MROFINU1000106.EXE C:\WINDOWS\MROFINU1188.EXE C:\WINDOWS\Prefetch\MROFINU1000106.EXE-23500A9A.pf C:\WINDOWS\Prefetch\MROFINU1188.EXE-035A0B37.pf Adware.Vundo-Variant/E C:\WINDOWS\SYSTEM32\APYUDUGK.DLL C:\WINDOWS\SYSTEM32\GROGMLMJ.DLL C:\WINDOWS\SYSTEM32\ISCRWWWM.DLL C:\WINDOWS\SYSTEM32\KCAYKNTS.DLL Adware.Vundo-Variant/Small-A C:\WINDOWS\SYSTEM32\BUMEPRPD.DLL C:\WINDOWS\SYSTEM32\DXEYLTCJ.DLL C:\WINDOWS\SYSTEM32\ERVOMIAO.DLL C:\WINDOWS\SYSTEM32\LYQFPYTK.DLL C:\WINDOWS\SYSTEM32\WIQNIBTS.DLL Trojan.Vundo-Variant/Small-GEN C:\WINDOWS\SYSTEM32\GEBTLBRO.DLL Trojan.Unknown Origin C:\WINDOWS\SMFUIEHVBHZPAW\MAIRKH1SVJTDUT.VBS C:\WINDOWS\UNINSTALL_NMON.VBS COMBOFIX logg ComboFix 08-07-21.1 - Eier 2008-07-22 2:24:01.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1044.18.216 [GMT 2:00] Running from: C:\Documents and Settings\Eier\Skrivebord\combofix.exe * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316 C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\BrowserSearch\BrowserSearch.xml C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\BrowserSearch\BrowserSearch.xml.backup C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Configurator\Configurator.xml C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Configurator\Configurator.xml.backup C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\ErrorSearch\ErrorSearchOptions.xml C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\ErrorSearch\ErrorSearchOptions.xml.backup C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Games\GamesOptions.xml C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Games\GamesOptions.xml.backup C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Games\images\active\Games0.bmp C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Layouts\ToolbarLayout.xml C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Layouts\ToolbarLayout.xml.backup C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Manager\ManagerOptions.xml C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Manager\ManagerOptions.xml.backup C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Movies\images\active\Movies0.bmp C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Movies\MoviesOptions.xml C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Movies\MoviesOptions.xml.backup C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Reference\ReferenceOptions.xml C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Reference\ReferenceOptions.xml.backup C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\RelatedSearch\RelatedSearchOptions.xml C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\RelatedSearch\RelatedSearchOptions.xml.backup C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Screensavers\ScreensaversOptions.xml C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Screensavers\ScreensaversOptions.xml.backup C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\ScreensaversMarketingSitePager\images\active\ScreensaversMarketingSitePager0.bmp C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Toolbar\TBProductsOptions.xml C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Toolbar\TBProductsOptions.xml.backup C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\ToolbarLogo\ToolbarLogoOptions.xml C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\ToolbarLogo\ToolbarLogoOptions.xml.backup C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\ToolbarSearch\ToolbarSearchOptions.xml C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\ToolbarSearch\ToolbarSearchOptions.xml.backup C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\TravelSearch\TravelSearchOptions.xml C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\TravelSearch\TravelSearchOptions.xml.backup C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Weather\AlertArchive.xml C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Weather\WeatherOptions.xml C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Weather\WeatherOptions.xml.backup C:\Documents and Settings\LocalService\Programdata\NetMon C:\Documents and Settings\LocalService\Programdata\NetMon\domains.txt C:\Documents and Settings\LocalService\Programdata\NetMon\log.txt C:\Programfiler\network monitor C:\Programfiler\stem32~1 C:\Programfiler\Svconr C:\Programfiler\Svconr\Svconr.exe C:\Temp\1cb C:\Temp\1cb\syscheck.log C:\Temp\gbRve12 C:\Temp\gbRve12\csLioes.log C:\Temp\sanR24 C:\Temp\sanR24\lDii.log C:\Temp\vtmp2 C:\Temp\vtmp2\ktnv33.log C:\WINDOWS\Downloaded Program Files\setup.inf C:\WINDOWS\Fonts\' C:\WINDOWS\Fonts\a.zip C:\WINDOWS\Fonts\Crack.exe C:\WINDOWS\pskt.ini C:\WINDOWS\sstem3~1 C:\WINDOWS\sstem3~1\s?stem32\ C:\WINDOWS\system32\ahcsonvw.ini C:\WINDOWS\system32\aqVreo18 C:\WINDOWS\system32\aqVreo18\aqVreo182328.exe C:\WINDOWS\system32\AutoRun.inf C:\WINDOWS\system32\jnxxcvhv.exe C:\WINDOWS\system32\kernlaoo.exe C:\WINDOWS\system32\mcrh.tmp C:\WINDOWS\system32\mdm.exe C:\WINDOWS\system32\MSINET.oca C:\WINDOWS\system32\nytedlhd.ini C:\WINDOWS\system32\oaimovre.ini C:\WINDOWS\system32\osbwbgxs.ini C:\WINDOWS\system32\osbwbgxs.ini2 C:\WINDOWS\system32\osbwbgxs.tmp C:\WINDOWS\system32\pac.txt C:\WINDOWS\system32\superiorads-uninst.exe C:\WINDOWS\system32\uqvdkeet.ini C:\winlogon.exe C:\x.dat C:\z.dat . ((((((((((((((((((((((((( Files Created from 2008-06-22 to 2008-07-22 ))))))))))))))))))))))))))))))) . 2008-07-22 01:38 . 2008-07-22 01:38 <DIR> dr-h----- C:\Documents and Settings\Eier\Siste 2008-07-22 01:37 . 2008-07-22 01:37 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\SUPERAntiSpyware.com 2008-07-22 01:36 . 2008-07-22 01:36 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware 2008-07-22 01:36 . 2008-07-22 01:36 <DIR> d-------- C:\Documents and Settings\Eier\Programdata\SUPERAntiSpyware.com 2008-07-22 01:35 . 2008-07-22 01:35 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard 2008-07-22 01:31 . 2008-07-22 01:31 <DIR> d-------- C:\Programfiler\CCleaner 2008-07-22 00:56 . 2008-07-22 00:56 128 --a------ C:\Documents and Settings\Eier\services.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-22 00:32 --------- d-----w C:\Programfiler\Steam 2008-07-21 22:59 --------- d-----w C:\Documents and Settings\Eier\Programdata\LimeWire 2008-07-21 22:54 --------- d---a-w C:\Documents and Settings\All Users\Programdata\TEMP 2008-03-12 17:23 40,960 ----a-w C:\Documents and Settings\Eier\f.exe 2008-02-08 01:07 217,088 ----a-w C:\Programfiler\TTC.dll 2008-01-21 19:31 63,408 ----a-w C:\Documents and Settings\Eier\Programdata\GDIPFONTCACHEV1.DAT 2008-01-15 21:34 140,800 --sh--w C:\Programfiler\Fellesfiler\Yazzle1560OinAdmin.exe 2007-01-26 12:31 62,400 ----a-w C:\Documents and Settings\GJESTEKONTO\Programdata\GDIPFONTCACHEV1.DAT 2004-07-22 08:51 3,432,656 -c--a-w C:\Programfiler\ManagedDX.CAB 2004-07-19 20:58 1,156,363 -c--a-w C:\Programfiler\BDANT.cab 2004-07-19 20:53 976,020 -c--a-w C:\Programfiler\BDAXP.cab 2004-07-09 12:17 13,265,040 -c--a-w C:\Programfiler\dxnt.cab 2004-07-09 07:13 703,080 -c--a-w C:\Programfiler\BDA.cab 2004-07-09 07:13 15,493,481 -c--a-w C:\Programfiler\DirectX.cab 2004-07-09 02:08 472,576 ----a-w C:\Programfiler\dxsetup.exe 2004-07-09 02:08 2,242,560 ----a-w C:\Programfiler\dsetup32.dll 2004-07-09 01:03 62,976 ----a-w C:\Programfiler\DSETUP.dll 1999-08-18 14:36 135,168 -c--a-w C:\WINDOWS\inf\Agfa\message.exe 2006-12-06 07:17 104 --sh--r C:\WINDOWS\system32\94CEB4F867.sys 2007-03-02 19:58 6,580 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Dqdwve"="C:\Programfiler\??stem32\d?xplore.exe" [?] "MsnMsgr"="C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 12:34 5724184] "Steam"="c:\programfiler\steam\steam.exe" [2008-05-01 14:19 1271032] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360] "CTSyncU.exe"="C:\Programfiler\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-07-17 12:03 868352] "SUPERAntiSpyware"="C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [X] "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 22:49 94208] "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 22:46 77824] "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 22:50 114688] "SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00 132496] "DMXLauncher"="C:\Programfiler\Dell\Media Experience\DMXLauncher.exe" [2005-11-01 05:12 94208] "SynTPEnh"="C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 06:56 761947] "Dell QuickSet"="C:\Programfiler\Dell\QuickSet\quickset.exe" [2005-12-15 12:44 839680] "ISUSPM Startup"="C:\Programfiler\Fellesfiler\InstallShield\UpdateService\isuspm.exe" [2005-06-10 12:44 249856] "ISUSScheduler"="C:\Programfiler\Fellesfiler\InstallShield\UpdateService\issch.exe" [2005-06-10 12:44 81920] "DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 07:20 122940] "Microsoft Works Update Detection"="C:\Programfiler\Fellesfiler\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-25 07:20 28672] "CTCheck"="C:\Programfiler\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe" [2007-11-06 12:08 397312] "HP Software Update"="C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 22:34 49152] "Google Desktop Search"="C:\Programfiler\Google\Google Desktop Search\GoogleDesktop.exe" [2008-03-07 15:57 29744] "SigmatelSysTrayApp"="stsystra.exe" [2005-09-10 01:19 393216 C:\WINDOWS\stsystra.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360] C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\ Digital Line Detect.lnk - C:\Programfiler\Digital Line Detect\DLG.exe [2006-03-24 15:59:55 24576] HP Digital Imaging Monitor.lnk - C:\Programfiler\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 22:26:24 210520] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2007-04-19 13:41 294912 C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Programfiler\\Messenger\\msmsgs.exe"= "C:\\WINDOWS\\system32\\dpvsetup.exe"= "C:\\StubInstaller.exe"= "C:\\Programfiler\\LimeWire\\LimeWire.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Programfiler\\Steam\\SteamApps\\vholvik\\counter-strike source\\hl2.exe"= "C:\\Programfiler\\Steam\\SteamApps\\marti946\\counter-strike source\\hl2.exe"= "C:\\Programfiler\\Windows Live\\Messenger\\livecall.exe"= "C:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"= R2 NwSapAgent;SAP Agent;C:\WINDOWS\system32\svchost.exe [2004-08-04 14:00] S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;C:\Programfiler\Google\Google Desktop Search\GoogleDesktop.exe [2008-03-07 15:57] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder "2006-07-10 21:27:34 C:\WINDOWS\Tasks\Low Battery Alarm Program.job" . - - - - ORPHANS REMOVED - - - - HKCU-Run-ModemOnHold - C:\Programfiler\NetWaiting\netwaiting.exe HKCU-Run-WebCamRT.exe - (no file) HKLM-Run-Engage - c:\programfiler\engage\engage.exe HKLM-Run-BMfb8f3b4f - C:\WINDOWS\system32\pinpxuok.dll HKLM-Run-f8bc08d3 - C:\WINDOWS\system32\sxgbwbso.dll HKLM-Run-Logitech Hardware Abstraction Layer - KHALMNPR.EXE . ------- Supplementary Scan ------- . R0 -: HKCU-Main,Start Page = hxxp://www.nettby.no/ R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} R0 -: HKLM-Main,Window Title = Microsoft Internet Explorer R1 -: HKCU-Internet Settings,ProxyOverride = localhost O8 -: E&ksporter til Microsoft Excel - C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O16 -: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} - hxxp://www.tvlution.com/KooPlayer.ocx C:\WINDOWS\Downloaded Program Files\KooPlayer.ocx O16 -: {745395C8-D0E1-4227-8586-624CA9A10A8D} - hxxp://217.197.149.13/activex/AMC.cab C:\WINDOWS\Downloaded Program Files\setup.inf O16 -: {C111A91F-D4EC-4D22-8D27-C3BCB0389F43} - hxxp://195.136.36.165/activex/AMC.cab C:\WINDOWS\Downloaded Program Files\setup.inf O16 -: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://cam.butovonet.ru/activex/AMC.cab C:\WINDOWS\Downloaded Program Files\setup.inf ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-22 02:32:03 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\WLTRYSVC.EXE C:\WINDOWS\system32\BCMWLTRY.EXE C:\WINDOWS\system32\brss01a.exe C:\WINDOWS\system32\CTSVCCDA.EXE C:\Programfiler\Dell\NicConfigSvc\NicConfigSvc.exe C:\WINDOWS\system32\WLTRAY.EXE C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\system32\msiexec.exe C:\Programfiler\HP\Digital Imaging\bin\hpqste08.exe . ************************************************************************** . Completion time: 2008-07-22 2:38:08 - machine was rebooted ComboFix-quarantined-files.txt 2008-07-22 00:37:54 Pre-Run: 37,276,983,296 byte ledig Post-Run: 37,554,270,208 byte ledig 233 --- E O F --- 2008-05-24 14:07:02 HIJACKTHIS logg Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 02:43:26, on 22.07.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\brss01a.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programfiler\Dell\NICCONFIGSVC\NICCONFIGSVC.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe C:\WINDOWS\stsystra.exe C:\Programfiler\Dell\Media Experience\DMXLauncher.exe C:\WINDOWS\system32\WLTRAY.exe C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe C:\Programfiler\Dell\QuickSet\quickset.exe C:\WINDOWS\System32\DLA\DLACTRLW.EXE C:\Programfiler\Fellesfiler\Microsoft Shared\Works Shared\WkUFind.exe C:\Programfiler\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\system32\ctfmon.exe C:\Programfiler\Creative\Sync Manager Unicode\CTSyncU.exe C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\WINDOWS\system32\msiexec.exe C:\Programfiler\Digital Line Detect\DLG.exe C:\Programfiler\HP\Digital Imaging\bin\hpqtra08.exe C:\Programfiler\HP\Digital Imaging\bin\hpqSTE08.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\explorer.exe C:\Programfiler\internet explorer\iexplore.exe C:\Programfiler\HP\Smart Web Printing\hpswp_clipbook.exe C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Documents and Settings\Eier\Skrivebord\hijackkk\test.exe.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nettby.no/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file) R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Programfiler\HP\Smart Web Printing\hpswp_framework.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe O4 - HKLM\..\Run: [DMXLauncher] C:\Programfiler\Dell\Media Experience\DMXLauncher.exe O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY O4 - HKLM\..\Run: [synTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [Dell QuickSet] C:\Programfiler\Dell\QuickSet\quickset.exe O4 - HKLM\..\Run: [showLOMControl] O4 - HKLM\..\Run: [iSUSPM Startup] "C:\Programfiler\Fellesfiler\InstallShield\UpdateService\isuspm.exe" -startup O4 - HKLM\..\Run: [iSUSScheduler] "C:\Programfiler\Fellesfiler\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programfiler\Fellesfiler\Microsoft Shared\Works Shared\WkUFind.exe O4 - HKLM\..\Run: [CTCheck] C:\Programfiler\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe O4 - HKLM\..\Run: [HP Software Update] C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [Google Desktop Search] "C:\Programfiler\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [steam] "c:\programfiler\steam\steam.exe" -silent O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Programfiler\Creative\Sync Manager Unicode\CTSyncU.exe" O4 - HKCU\..\Run: [Dqdwve] C:\Programfiler\??stem32\d?xplore.exe O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: GameSpot Download Manager.lnk = C:\Documents and Settings\Eier\Skrivebord\GameSpot\GameSpotDownloadManager_Win32.exe O4 - Global Startup: Digital Line Detect.lnk = ? O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programfiler\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: Logitech Desktop Messenger Agent.lnk = C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: HP Utklippsbok - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Programfiler\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: HP Smart valgmetode - {700259D7-1666-479a-93B1-3250410481E8} - C:\Programfiler\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O14 - IERESET.INF: START_PAGE_URL=http://www.online.no/ O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/SU/SU1.5/ocx/15030/CTSUEng.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by136fd.bay136.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvlution.com/KooPlayer.ocx O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} - http://217.197.149.13/activex/AMC.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} - http://update.videoegg.com/Install/Windows...ggPublisher.exe O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab O16 - DPF: {C111A91F-D4EC-4D22-8D27-C3BCB0389F43} - http://195.136.36.165/activex/AMC.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - http://cam.butovonet.ru/activex/AMC.cab O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by136fd.bay136.hotmail.msn.com/activex/HMAtchmt.ocx O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/SU/SU1.5/ocx/15033/CTPID.cab O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Programfiler\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Programfiler\Dell\NICCONFIGSVC\NICCONFIGSVC.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe O24 - Desktop Component 1: (no name) - http://www.vg.no/ -- End of file - 10535 bytes Lenke til kommentar
norbat Skrevet 22. juli 2008 Forfatter Del Skrevet 22. juli 2008 Åpne notisblokk og kopier inn det som står i fet skrift under, lagre fila på skrivebordet som CFScript.txt. Dra deretter fila over Combofix-iconet. Combofix vil starte igjen. File:: C:\Documents and Settings\Eier\services.exe C:\Documents and Settings\Eier\f.exe C:\Programfiler\Fellesfiler\Yazzle1560OinAdmin.exe Registry:: [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Dqdwve"=- Last ned Malwarebytes Anti-Malware til skrivebordet. Kjør og installer programmet. Velg Norsk-språk La programmet oppdatere seg og velg å kjør en 'full systemskann', klikk Skann. Det kommer en meldingsboks om at scannen er ferdig, klikk Ok Klikk på Vis resultat-knappen.Hvis det er funnet malware, vil du nå se hva som er funnet. Klikk så på Fjern valgte -knappen for å fjerne malwaren som evt. ble funnet. Det vil deretter åpnes en logg i notisblokk. Den kan du kopiere og poste om den finner noe. Post ny hjt-logg. Lenke til kommentar
Anbefalte innlegg
Opprett en konto eller logg inn for å kommentere
Du må være et medlem for å kunne skrive en kommentar
Opprett konto
Det er enkelt å melde seg inn for å starte en ny konto!
Start en kontoLogg inn
Har du allerede en konto? Logg inn her.
Logg inn nå