Gå til innhold

Poster utskilt fra veiledertråden-2


Anbefalte innlegg

Kjør en systemgjenoppretting til før problemet oppsto (tilbehør->systemverktøy->systemgjenoppretting)

 

Deretter kjører du en ny scan med SAS, fjerner de toolbarene du ønsker fra legg til / fjern programmer og poster ny hjt-logg.

Lenke til kommentar
Videoannonse
Annonse

Fikset, pcen hang seg bare opp, en restart hjalp.

 

HJT log, etter jeg sletta filene du nevnte og kjørte Ccleaner. Mangler å fjerne noen toolbars, men må lukke IE, så poster loggen nå å fjerner de senere:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 20:30:11, on 03.07.2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Programfiler\Fellesfiler\GtFlashSwitch\GtFlashSwitch.exe

C:\Programfiler\Hotspot Shield\bin\openvpnas.exe

C:\WINDOWS\System32\svchost.exe

C:\Programfiler\Fellesfiler\LightScribe\LSSrvc.exe

C:\WINDOWS\system32\lxdicoms.exe

C:\Programfiler\Trend Micro\OfficeScan Client\ntrtscan.exe

C:\WINDOWS\system32\svchost.exe

C:\Programfiler\Trend Micro\OfficeScan Client\tmlisten.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Programfiler\Trend Micro\OfficeScan Client\OfcPfwSvc.exe

C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe

C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe

C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe

C:\Programfiler\hpq\HP Wireless Assistant\HP Wireless Assistant.exe

C:\Programfiler\iTunes\iTunesHelper.exe

C:\Programfiler\QuickTime\qttask.exe

C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe

C:\Programfiler\Trend Micro\OfficeScan Client\pccntmon.exe

C:\WINDOWS\system32\rundll32.exe

C:\Programfiler\Lexmark 3500-4500 Series\lxdimon.exe

C:\Programfiler\Fellesfiler\LogiShrd\LComMgr\Communications_Helper.exe

C:\Programfiler\Logitech\QuickCam10\QuickCam10.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\Windows Media Player\WMPNSCFG.exe

C:\WINDOWS\TEMP\GD19BC.EXE

C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Programfiler\Hp\Digital Imaging\bin\hpqtra08.exe

C:\Programfiler\Telenor\Mobilt Kontor\Mobilt Kontor.exe

C:\Programfiler\CASIO\Photo Loader\Plauto.exe

C:\Programfiler\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe

C:\Programfiler\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe

C:\Programfiler\Fellesfiler\LogiShrd\LComMgr\LVComSX.exe

C:\Programfiler\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe

C:\Programfiler\iPod\bin\iPodService.exe

C:\Programfiler\HPQ\SHARED\HPQWMI.exe

C:\Programfiler\HP\Digital Imaging\Product Assistant\bin\hprblog.exe

C:\Programfiler\Fellesfiler\Logishrd\LQCVFX\COCIManager.exe

C:\Programfiler\Trend Micro\OfficeScan Client\pccntupd.exe

C:\Programfiler\internet explorer\iexplore.exe

C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\system32\wuauclt.exe

C:\DOCUME~1\BIRTHE~1\LOKALE~1\Temp\~nsu.tmp\Au_.exe

C:\Documents and Settings\Birthe^_^\Mine dokumenter\test.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startsiden.no/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll

O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll

O4 - HKLM\..\Run: [ATIPTA] "C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe"

O4 - HKLM\..\Run: [HP Software Update] C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Programfiler\hpq\HP Wireless Assistant\HP Wireless Assistant.exe

O4 - HKLM\..\Run: [iTunesHelper] C:\Programfiler\iTunes\iTunesHelper.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe

O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programfiler\HPQ\Quick Launch Buttons\EabServr.exe /Start

O4 - HKLM\..\Run: [Cpqset] C:\Programfiler\HPQ\Default Settings\cpqset.exe

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe

O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Programfiler\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow

O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

O4 - HKLM\..\Run: [lxdimon.exe] "C:\Programfiler\Lexmark 3500-4500 Series\lxdimon.exe"

O4 - HKLM\..\Run: [lxdiamon] "C:\Programfiler\Lexmark 3500-4500 Series\lxdiamon.exe"

O4 - HKLM\..\Run: [FaxCenterServer] "C:\Programfiler\\Lexmark Fax Solutions\fm3032.exe" /s

O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Programfiler\Fellesfiler\LogiShrd\LComMgr\Communications_Helper.exe"

O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Programfiler\Logitech\QuickCam10\QuickCam10.exe" /hide

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [WMPNSCFG] C:\Programfiler\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\isabel\Start-meny\Programmer\IMVU\Run IMVU.lnk

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com

O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} (ObjWinNTCheck Class) - http://172.21.15.50:8080/officescan/consol...ll/WinNTChk.cab

O16 - DPF: {08D75BB0-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupINICtrl Class) - http://172.21.15.50:8080/officescan/consol...ll/setupini.cab

O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupCtrl Class) - http://172.21.15.50:8080/officescan/consol...stall/setup.cab

O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file://C:\Programfiler\Forgotten Riddles - The Mayan Princess\Images\stg_drm.ocx

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab

O16 - DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} (Encrypt Class) - http://172.21.15.50:8080/officescan/console/html/AtxEnc.cab

O16 - DPF: {5EFE8CB1-D095-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class) - http://172.21.15.50:8080/officescan/consol.../RemoveCtrl.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1140028536852

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Programfiler\Baby Luv\Images\armhelper.ocx

O16 - DPF: {E6C4420E-0669-4518-B825-F63CDDEF7D5D} (InitOcx Control) - http://rc.puppyred.com/init.cab

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: GtFlashSwitch - OptionNV - C:\Programfiler\Fellesfiler\GtFlashSwitch\GtFlashSwitch.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Programfiler\Hotspot Shield\bin\openvpnas.exe

O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Programfiler\HPQ\SHARED\HPQWMI.exe

O23 - Service: iPod-tjeneste (iPodService) - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programfiler\Fellesfiler\LightScribe\LSSrvc.exe

O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Programfiler\Fellesfiler\LogiShrd\SrvLnch\SrvLnch.exe

O23 - Service: lxdi_device - - C:\WINDOWS\system32\lxdicoms.exe

O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Programfiler\Trend Micro\OfficeScan Client\ntrtscan.exe

O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Programfiler\Trend Micro\OfficeScan Client\OfcPfwSvc.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Programfiler\Trend Micro\OfficeScan Client\tmlisten.exe

 

--

End of file - 10272 bytes

 

 

Hvordan ser det ut?

Lenke til kommentar

Ser flott ut :thumbup:

 

Kjør en ny runde med ccleaner

 

Fjern combofix ved å skrive combofix /u i kjør-feltet (start->kjør). Dette vil også nullstille systemgjenopprettingen slik at du ikke blir infisert ved en evt. gjenoppretting senere.

Lenke til kommentar

Klikk for å se/fjerne innholdet nedenfor
Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 02:04:36, on 07.07.2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\spoolsv.exe

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\PROGRA~1\AVG\AVG8\avgfws8.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\PROGRA~1\AVG\AVG8\avgam.exe

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

C:\PROGRA~1\AVG\AVG8\avgnsx.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Program Files\PowerISO\PWRISOVM.EXE

C:\Program Files\Razer\Tarantula\razerhid.exe

C:\PROGRA~1\AVG\AVG8\avgemc.exe

C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe

C:\PROGRA~1\AVG\AVG8\avgtray.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe

C:\WINDOWS\System32\alg.exe

C:\Program Files\Steam\Steam.exe

C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Program Files\Razer\Tarantula\razertra.exe

C:\Program Files\Windows Live\Messenger\usnsvc.exe

C:\Program Files\Opera\opera.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sol.no/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O4 - HKLM\..\Run: [startCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE

O4 - HKLM\..\Run: [Tarantula] C:\Program Files\Razer\Tarantula\razerhid.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [steam] "C:\Program Files\Steam\Steam.exe" -silent

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab3.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O20 - AppInit_DLLs: avgrsstx.dll

O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe

O23 - Service: Remote Procedure Manager(TPM) (RPCM) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\Speech\csvde.exe (file missing)

 

--

End of file - 5711 bytes

 

Klikk for å se/fjerne innholdet nedenfor

ComboFix 08-07-05.1 - Raymond 2008-07-07 1:47:59.2 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.379 [GMT 2:00]

Running from: C:\Documents and Settings\Raymond\Desktop\ComboFix.exe

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((((( Files Created from 2008-06-06 to 2008-07-06 )))))))))))))))))))))))))))))))

.

 

2008-07-07 01:17 . 2008-07-07 01:17 <DIR> d-------- C:\Program Files\SUPERAntiSpyware

2008-07-07 01:17 . 2008-07-07 01:17 <DIR> d-------- C:\Documents and Settings\Raymond\Application Data\SUPERAntiSpyware.com

2008-07-07 01:17 . 2008-07-07 01:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com

2008-07-07 01:15 . 2008-07-07 01:15 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard

2008-07-07 00:58 . 2008-07-07 01:28 <DIR> d--h----- C:\$AVG8.VAULT$

2008-07-07 00:51 . 2008-07-07 01:03 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg

2008-07-07 00:51 . 2008-07-07 00:57 <DIR> d-------- C:\Documents and Settings\Raymond\Application Data\AVGTOOLBAR

2008-07-07 00:51 . 2008-07-07 00:51 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys

2008-07-07 00:51 . 2008-07-07 00:51 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys

2008-07-07 00:51 . 2008-07-07 00:51 12,424 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys

2008-07-07 00:51 . 2008-07-07 00:51 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll

2008-07-07 00:50 . 2008-07-07 00:50 <DIR> d-------- C:\WINDOWS\LastGood

2008-07-07 00:50 . 2008-07-07 00:50 <DIR> d-------- C:\Program Files\AVG

2008-07-07 00:50 . 2008-07-07 00:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8

2008-07-07 00:50 . 2008-07-07 00:50 45,568 --a------ C:\WINDOWS\system32\avgfwdx.dll

2008-07-07 00:50 . 2008-07-07 00:50 22,528 --a------ C:\WINDOWS\system32\drivers\avgfwdx.sys

2008-07-07 00:22 . 2008-07-07 00:22 58 --a------ C:\QQ¸öÐÔ×Ö»ðÐÇÎÄ,·±Ìå×Öת»»Æ÷.url

2008-07-07 00:22 . 2008-07-07 00:22 51 --a------ C:\¹É³ÇÍø_¹ÉÊÐÐÐÇé_ÈçºÎ³´¹É.url

2008-07-07 00:12 . 2008-07-07 00:12 20,192 ---hs---- C:\WINDOWS\system32\vcrxfileju.dll

2008-07-06 22:33 . 2008-07-06 22:33 <DIR> d-------- C:\WINDOWS\Downloaded Installations

2008-07-06 22:33 . 2008-07-06 22:33 <DIR> d-------- C:\Program Files\GabbaSoft

2008-07-06 22:31 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl

2008-07-06 22:30 . 2008-07-06 22:31 <DIR> d-------- C:\Program Files\Java

2008-07-06 22:29 . 2008-07-06 22:29 <DIR> d-------- C:\Program Files\Common Files\Java

2008-07-06 22:27 . 2008-07-06 22:27 <DIR> d-------- C:\Program Files\Arcus

2008-07-06 14:41 . 2008-07-06 14:41 <DIR> d-------- C:\Logs

2008-07-06 00:46 . 2008-07-06 00:46 <DIR> d-------- C:\Program Files\SystemRequirementsLab

2008-07-05 23:20 . 2008-07-05 23:20 <DIR> d-------- C:\Program Files\Common Files\Blizzard Entertainment

2008-07-05 23:14 . 2008-07-06 15:22 <DIR> d-------- C:\Program Files\World of Warcraft

2008-07-05 20:40 . 2008-07-05 20:40 <DIR> d-------- C:\Program Files\Razer

2008-07-05 20:40 . 2006-07-12 18:31 77,824 --a------ C:\WINDOWS\system32\Tarantula.cpl

2008-07-05 20:40 . 2006-09-27 14:48 44,800 --a------ C:\WINDOWS\system32\drivers\UsbFltr.sys

2008-07-05 20:40 . 2005-12-21 11:23 14,592 --a------ C:\WINDOWS\system32\drivers\Usbicp.sys

2008-07-02 17:23 . 2008-07-02 17:28 139,264 --a------ C:\WINDOWS\War3Unin.exe

2008-07-02 17:23 . 2008-07-02 17:36 76,336 --a------ C:\WINDOWS\War3Unin.dat

2008-07-02 17:23 . 2008-07-02 17:28 2,829 --a------ C:\WINDOWS\War3Unin.pif

2008-07-02 17:22 . 2008-07-06 15:59 <DIR> d-------- C:\Program Files\Warcraft III

2008-07-02 14:38 . 2008-07-02 14:38 <DIR> d-------- C:\Program Files\PowerISO

2008-07-02 00:46 . 2008-07-02 00:46 <DIR> d-------- C:\Program Files\DivX

2008-06-30 14:22 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll

2008-06-30 14:22 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll

2008-06-30 14:22 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui

2008-06-30 13:32 . 2008-06-13 15:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys

2008-06-30 13:32 . 2008-06-13 15:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys

2008-06-30 13:22 . 2008-06-30 13:22 <DIR> d-------- C:\Documents and Settings\Raymond\Application Data\ATI

2008-06-30 13:22 . 2008-06-30 13:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ATI

2008-06-29 21:41 . 2008-07-01 14:15 <DIR> d--h----- C:\WINDOWS\$hf_mig$

2008-06-29 21:28 . 2008-06-29 21:28 <DIR> d-------- C:\Program Files\Google

2008-06-29 21:00 . 2004-08-04 02:56 21,504 --a------ C:\WINDOWS\system32\hidserv.dll

2008-06-29 21:00 . 2001-08-17 15:59 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys

2008-06-29 19:53 . 2008-06-29 19:53 <DIR> d---s---- C:\Documents and Settings\Raymond\UserData

2008-06-29 19:48 . 2008-07-06 17:53 <DIR> d-------- C:\Program Files\Steam

2008-06-29 19:47 . 2008-06-29 19:47 <DIR> d-------- C:\Documents and Settings\Raymond\Contacts

2008-06-29 19:46 . 2008-06-29 19:46 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE

2008-06-29 19:46 . 2003-05-25 12:11 60,416 --a------ C:\WINDOWS\system32\antiwpa.dll

2008-06-29 19:44 . 2008-06-29 19:45 <DIR> d-------- C:\Program Files\BitLord

2008-06-29 19:42 . 2008-06-29 19:46 <DIR> d-------- C:\Program Files\Windows Live

2008-06-29 19:42 . 2008-06-29 19:45 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller

2008-06-29 19:42 . 2008-06-29 19:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller

2008-06-29 19:35 . 2008-06-29 19:35 <DIR> d-------- C:\Program Files\Opera

2008-06-29 19:31 . 2008-06-29 19:31 <DIR> d-------- C:\WINDOWS\system32\Lang

2008-06-29 19:31 . 2008-06-29 19:31 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav

2008-06-29 19:31 . 2008-06-29 19:31 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav

2008-06-29 19:31 . 2008-06-29 19:31 0 --a------ C:\WINDOWS\ativpsrm.bin

2008-06-29 19:29 . 2008-06-29 19:29 <DIR> d-------- C:\Program Files\AMD

2008-06-29 19:28 . 2008-06-29 19:28 <DIR> d-------- C:\WINDOWS\system32\RTCOM

2008-06-29 19:27 . 2008-06-29 19:27 <DIR> d-------- C:\Program Files\Realtek

2008-06-29 19:23 . 2008-06-29 19:24 <DIR> d-------- C:\Program Files\ATI Technologies

2008-06-29 19:22 . 2008-06-29 19:22 <DIR> d-------- C:\ATI

2008-06-29 19:22 . 2008-06-03 06:05 593,920 --------- C:\WINDOWS\system32\ati2sgag.exe

2008-06-29 19:17 . 2008-07-05 20:40 <DIR> d--h----- C:\Program Files\InstallShield Installation Information

2008-06-29 19:16 . 2008-06-29 19:16 <DIR> d-------- C:\Program Files\VIA

2008-06-29 19:15 . 2008-06-29 19:23 <DIR> d-------- C:\Program Files\Common Files\InstallShield

2008-06-29 19:15 . 2008-06-29 19:27 16,174 --a------ C:\WINDOWS\Ascd_tmp.ini

2008-06-29 19:15 . 2004-04-26 18:00 5,824 --a------ C:\WINDOWS\system32\drivers\ASUSHWIO.SYS

2008-06-29 19:15 . 2004-08-13 04:56 5,810 -ra------ C:\WINDOWS\system32\drivers\ASACPI.sys

2008-06-29 19:11 . 2008-07-06 01:05 <DIR> d-------- C:\Documents and Settings\Raymond

2008-06-18 19:52 . 2008-06-18 19:52 161,096 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe

2008-06-11 02:07 . 2008-06-11 02:07 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll

2008-06-11 02:07 . 2008-06-11 02:07 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe

2008-06-11 02:07 . 2008-06-11 02:07 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb

2008-06-11 02:04 . 2008-06-11 02:04 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll

2008-06-11 02:04 . 2008-06-11 02:04 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-07-06 22:22 0 --sh--w C:\Program Files\desktoq.ini

2008-07-06 21:33 4,224 ----a-w C:\WINDOWS\system32\drivers\beep.sys

2008-06-30 02:07 --------- d-----w C:\Program Files\microsoft frontpage

2008-06-29 18:20 --------- d-----w C:\Program Files\QuickTime

2008-06-29 18:20 --------- d-----w C:\Program Files\Apple Software Update

2008-06-29 18:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer

2008-06-29 18:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple

2008-06-29 18:03 --------- d-----w C:\Program Files\Windows Media Connect 2

2008-06-11 00:07 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys

2008-06-11 00:07 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys

2008-06-11 00:07 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys

2008-06-11 00:07 129,784 ------w C:\WINDOWS\system32\pxafs.dll

2008-06-11 00:07 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe

2008-06-11 00:07 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe

2008-06-03 06:20 3,100,160 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys

2008-06-03 03:46 10,276,864 ----a-w C:\WINDOWS\system32\atioglx2.dll

2008-06-03 03:22 413,696 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll

2008-06-03 03:21 306,688 ----a-w C:\WINDOWS\system32\ati2dvag.dll

2008-06-03 03:11 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll

2008-06-03 03:11 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe

2008-06-03 03:11 180,224 ----a-w C:\WINDOWS\system32\atipdlxx.dll

2008-06-03 03:11 139,264 ----a-w C:\WINDOWS\system32\Oemdspif.dll

2008-06-03 03:11 139,264 ----a-w C:\WINDOWS\system32\ati2evxx.dll

2008-06-03 03:09 552,960 ----a-w C:\WINDOWS\system32\ati2evxx.exe

2008-06-03 03:08 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL

2008-06-03 03:04 245,760 ----a-w C:\WINDOWS\system32\atiok3x2.dll

2008-06-03 03:02 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll

2008-06-03 02:59 3,500,352 ----a-w C:\WINDOWS\system32\ati3duag.dll

2008-06-03 02:48 2,120,832 ----a-w C:\WINDOWS\system32\ativvaxx.dll

2008-06-03 02:33 48,128 ----a-w C:\WINDOWS\system32\amdpcom32.dll

2008-06-03 02:29 348,160 ----a-w C:\WINDOWS\system32\atikvmag.dll

2008-06-03 02:28 23,040 ----a-w C:\WINDOWS\system32\atiadlxx.dll

2008-06-03 02:28 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll

2008-06-03 02:27 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll

2008-06-03 02:22 5,439,488 ----a-w C:\WINDOWS\system32\atioglxx.dll

2008-06-03 02:21 557,056 ----a-w C:\WINDOWS\system32\ati2cqag.dll

2008-05-22 22:18 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll

2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys

2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll

2008-04-21 07:04 659,456 ----a-w C:\WINDOWS\system32\wininet.dll

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]

"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 20:34 5724184]

"Steam"="C:\Program Files\Steam\Steam.exe" [2008-06-29 19:49 1271032]

"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 21:17 61440]

"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 10:50 413696]

"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-07 02:05 200704]

"Tarantula"="C:\Program Files\Razer\Tarantula\razerhid.exe" [2006-09-30 15:48 176128]

"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]

"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-07 00:51 1177368]

"SkyTel"="SkyTel.EXE" [2006-05-15 21:04 2879488 C:\WINDOWS\SkyTel.exe]

"RTHDCPL"="RTHDCPL.EXE" [2006-09-11 19:58 16264192 C:\WINDOWS\RTHDCPL.EXE]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{003E07F6-D7A2-456A-AE04-EB9ABF822FE4}"= "C:\WINDOWS\TEMP\Down(0)ow.dll" [2008-07-06 23:32 164096]

"{00627A41-E883-4899-BD2E-1B6F926757E7}"= "C:\DOCUME~1\Raymond\LOCALS~1\Temp\bulmfiles.dll" [2008-07-07 00:12 13312]

"{E8606370-4F7A-4C2F-A39C-EDCDCC177924}"= "C:\WINDOWS\system32\vcrxfileju.dll" [2008-07-07 00:12 20192]

"{C51C4AFB-2A3A-6C2E-BA41-C10F02760731}"= "C:\DOCUME~1\Raymond\LOCALS~1\Temp\xptfhsylgfile.dll" [2008-07-07 00:12 25178]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa]

2003-05-25 12:11 60416 C:\WINDOWS\system32\antiwpa.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=avgrsstx.dll

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Program Files\\Opera\\opera.exe"=

"C:\\Program Files\\BitLord\\BitLord.exe"=

"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=

"C:\\Program Files\\World of Warcraft\\WoW-2.4.2-enGB-downloader.exe"=

"C:\\Program Files\\Steam\\steamapps\\spacedog650\\counter-strike source\\hl2.exe"=

"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=

"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

 

R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-07-07 00:51]

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-07 00:51]

R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-07 00:51]

R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-07 00:51]

R2 avgfws8;AVG8 Firewall;C:\PROGRA~1\AVG\AVG8\avgfws8.exe [2008-07-07 00:51]

R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-07 00:51]

R3 Avgfwdx;Avgfwdx;C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2008-07-07 00:50]

R3 TarFltr;Razer Tarantula USB Keyboard;C:\WINDOWS\system32\Drivers\UsbFltr.sys [2006-09-27 14:48]

S2 RPCH;Remote Procedure Call (HPM);C:\Program Files\NetMeeting\Intell.exe [2005-06-16 12:37]

S2 RPCM;Remote Procedure Manager(TPM);C:\Program Files\Common Files\Microsoft Shared\Speech\csvde.exe []

S3 Avgfwfd;AVG network filter service;C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2008-07-07 00:50]

 

*Newly Created Service* - AVG8EMC

*Newly Created Service* - AVG8WD

*Newly Created Service* - AVGFWS8

*Newly Created Service* - AVGLDX86

*Newly Created Service* - AVGMFX86

*Newly Created Service* - AVGRKX86

*Newly Created Service* - AVGTDIX

*Newly Created Service* - CATCHME

*Newly Created Service* - RPCH

*Newly Created Service* - SASDIFSV

*Newly Created Service* - SASENUM

*Newly Created Service* - SASKUTIL

.

- - - - ORPHANS REMOVED - - - -

 

ShellExecuteHooks-{0046D7F0-5DF9-42C3-916E-5EE7D13D09DC} - C:\D@

 

 

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-07 01:48:47

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2008-07-07 1:49:13

ComboFix-quarantined-files.txt 2008-07-06 23:49:11

 

Pre-Run: 457,462,517,760 bytes free

Post-Run: 459,592,347,648 bytes free

 

224 --- E O F --- 2008-07-01 12:15:16

 

 

Klikk for å se/fjerne innholdet nedenfor

 

SUPERAntiSpyware Scan Log

http://www.superantispyware.com

 

Generated 07/07/2008 at 01:45 AM

 

Application Version : 4.15.1000

 

Core Rules Database Version : 3469

Trace Rules Database Version: 1460

 

Scan type : Complete Scan

Total Scan Time : 00:25:39

 

Memory items scanned : 505

Memory threats detected : 0

Registry items scanned : 3695

Registry threats detected : 0

File items scanned : 12871

File threats detected : 51

 

Adware.Tracking Cookie

C:\Documents and Settings\Raymond\Cookies\raymond@apmebf[1].txt

C:\Documents and Settings\Raymond\Cookies\raymond@tribalfusion[1].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt

C:\Documents and Settings\Raymond\Cookies\raymond@partypoker[2].txt

C:\Documents and Settings\Raymond\Cookies\raymond@overture[1].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt

C:\Documents and Settings\Raymond\Cookies\raymond@zedo[1].txt

C:\Documents and Settings\Raymond\Cookies\raymond@serving-sys[1].txt

C:\Documents and Settings\Raymond\Cookies\raymond@adtech[1].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][2].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][2].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][2].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt

C:\Documents and Settings\Raymond\Cookies\raymond@tradedoubler[2].txt

C:\Documents and Settings\Raymond\Cookies\raymond@revsci[2].txt

C:\Documents and Settings\Raymond\Cookies\raymond@atdmt[1].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][2].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][2].txt

C:\Documents and Settings\Raymond\Cookies\raymond@doubleclick[1].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][2].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt

C:\Documents and Settings\Raymond\Cookies\raymond@2o7[1].txt

C:\Documents and Settings\Raymond\Cookies\raymond@jh[1].txt

C:\Documents and Settings\Raymond\Cookies\raymond@cgi-bin[2].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][2].txt

C:\Documents and Settings\Raymond\Cookies\raymond@adrevolver[2].txt

C:\Documents and Settings\Raymond\Cookies\raymond@adbrite[2].txt

C:\Documents and Settings\Raymond\Cookies\raymond@adrevolver[3].txt

C:\Documents and Settings\Raymond\Cookies\raymond@clicktorrent[2].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt

C:\Documents and Settings\Raymond\Cookies\raymond@mediaplex[1].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][2].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][2].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt

C:\Documents and Settings\Raymond\Cookies\raymond@questionmarket[2].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt

C:\Documents and Settings\Raymond\Cookies\raymond@hitbox[2].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt

C:\Documents and Settings\Raymond\Cookies\raymond@advertising[1].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][2].txt

C:\Documents and Settings\Raymond\Cookies\[email protected][1].txt

C:\Documents and Settings\Raymond\Cookies\raymond@statcounter[1].txt

 

 

 

Ja, hvor mye virus har jeg?=P

 

Edit: AVG finner noe som heter Adware.RogueSuspect. (TrackingCookie også men det får jeg uansett hvilken PC jeg skanner =P)

 

HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0EDC6C20-A31C-11DB-8AB9-0800200C9A66]

 

og

 

HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\3AAC4C68-AFC8-11DB-80EF-8AF955D89593}

 

De var ikke dær før jeg kjørte de scanene..

Endret av Raytee
Lenke til kommentar

Noe smårusk igjen. Prøv dette først (før evt. en manuell fjerning):

 

Last ned MBAM til skrivebordet.

Kjør fila og installer programmet. Velg Norsk språkdrakt

La programmet oppdatere seg og velg å kjør en hurtig systemskann.

 

Du får en meldingsboks når programmet er ferdigkjørt

Klikk deretter på Vis resultat-knappen. Hvis det er funnet malware, vil du nå se hva som er funnet.

 

Klikk på Fjern valgt -knappen for å fjerne malwaren som evt. ble funnet.

 

Når MBAM er ferdig med å fjerne det den har funnet, vil det bli åpnet en logg i notisblokk. Den kan du kopiere og poste hvis det ble funnet noe.

Lenke til kommentar

Klikk for å se/fjerne innholdet nedenfor
Malwarebytes' Anti-Malware 1.19

Database versjon: 899

Windows 5.1.2600 Service Pack 2

 

02:32:23 07.07.2008

mbam-log-7-7-2008 (02-32-20).txt

 

Skanntype: Rask Skann

Objekter skannet: 38748

Tid tilbakelagt: 4 minute(s), 1 second(s)

 

Minneprosesser infisert: 0

Minnemoduler infisert: 0

Registernøkler infisert: 1

Registerverdier infisert: 0

Registerfiler infisert: 0

Mapper infisert: 0

Filer infisert: 1

 

Minneprosesser infisert:

(Ingen mistenkelige filer funnet)

 

Minnemoduler infisert:

(Ingen mistenkelige filer funnet)

 

Registernøkler infisert:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\antiwpa (Malware.Tool) -> No action taken.

 

Registerverdier infisert:

(Ingen mistenkelige filer funnet)

 

Registerfiler infisert:

(Ingen mistenkelige filer funnet)

 

Mapper infisert:

(Ingen mistenkelige filer funnet)

 

Filer infisert:

C:\WINDOWS\system32\antiwpa.dll (Malware.Tool) -> No action taken.

 

To (småe?) ting igjen så er jeg helt virus/spyware fri?=P Hvordan fjerner jeg disse to da?

 

Edit: Dette var et veldig dumt spm. =P

Jeg fjernet de og nå står finner ingen virusprogram noen ''threats'' =D(Kommer ikke på hva ordet heter på norsk! Men vet hva det er på engelsk xD)

Endret av Raytee
Lenke til kommentar

Hei,

 

Jeg har slitt med å bli kvitt 2 trojanere (Trojan Vundo.B & Trojan Horse). Når norton ikke klarte å ta det prøvde jeg 'oppskriften' her. Har kjørt alle søkene men har ikke gjort dette før så aner ikke hva jeg skal se etter for å se om det har blitt fjernet fullstendig. Hadde satt kjempepris på om noen kunne tatt en kikk på loggene for meg...

 

Her er loggene:

 

 

SUPERAntiSpyware Scan Log

http://www.superantispyware.com

 

Generated 07/11/2008 at 03:25 PM

 

Application Version : 4.15.1000

 

Core Rules Database Version : 3502

Trace Rules Database Version: 1493

 

Scan type : Complete Scan

Total Scan Time : 00:47:25

 

Memory items scanned : 836

Memory threats detected : 0

Registry items scanned : 9397

Registry threats detected : 0

File items scanned : 27520

File threats detected : 2

 

Adware.Tracking Cookie

C:\Users\Ravin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt

C:\Users\Ravin\AppData\Roaming\Microsoft\Windows\Cookies\Low\ravin@adtech[1].txt

 

 

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 16:33:02, on 11/07/2008

Platform: Windows Vista (WinNT 6.00.1904)

MSIE: Internet Explorer v7.00 (7.00.6000.16681)

Boot mode: Normal

 

Running processes:

c:\Program Files\Bioscrypt\VeriSoft\Bin\AsGHost.exe

C:\Windows\system32\Dwm.exe

C:\Windows\system32\taskeng.exe

C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Windows\RtHDVCpl.exe

C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe

C:\Program Files\Hp\QuickPlay\QPService.exe

C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe

C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe

C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Windows\ehome\ehtray.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe

C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe

C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe

C:\Program Files\Telenor Sikker Lagring\safestorage.exe

C:\Windows\System32\rundll32.exe

C:\Windows\ehome\ehmsas.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe

C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe

C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe

C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe

C:\Windows\Explorer.exe

C:\Program Files\Internet Explorer\ieuser.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe

C:\Users\Ravin\Desktop\test.exe.exe

 

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe

O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe

O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

 

--

End of file - 3963 bytes

 

 

 

 

 

ComboFix 08-07-10.1 - Ravin 2008-07-11 15:57:24.1 - NTFSx86

Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.236 [GMT 5.5:30]

Running from: C:\Users\Ravin\Desktop\ComboFix.exe

.

 

((((((((((((((((((((((((( Files Created from 2008-06-11 to 2008-07-11 )))))))))))))))))))))))))))))))

.

 

No new files created in this timespan

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-07-11 10:06 --------- d-----w C:\Users\Ravin\AppData\Roaming\Skype

2008-07-11 09:05 --------- d-----w C:\Users\Ravin\AppData\Roaming\SUPERAntiSpyware.com

2008-07-11 09:05 --------- d-----w C:\ProgramData\SUPERAntiSpyware.com

2008-07-11 09:05 --------- d-----w C:\Program Files\SUPERAntiSpyware

2008-07-11 09:04 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard

2008-07-11 08:50 --------- d-----w C:\ProgramData\NVIDIA

2008-07-11 08:35 72,616 ----a-w C:\Users\Ravin\AppData\Roaming\nvModes.dat

2008-07-10 15:50 --------- d-----w C:\Users\Ravin\AppData\Roaming\uTorrent

2008-07-10 15:40 --------- d--h--w C:\Program Files\InstallShield Installation Information

2008-07-10 15:33 --------- d-----w C:\Program Files\Red Kawa

2008-07-10 13:05 --------- d-----w C:\ProgramData\Symantec

2008-07-10 11:17 --------- d-----w C:\Users\Ravin\AppData\Roaming\Template

2008-07-10 11:08 262,144 ----a-w C:\ntuser.dat

2008-07-10 07:52 174 --sha-w C:\Program Files\desktop.ini

2008-07-10 07:38 --------- d-----w C:\Program Files\Windows Mail

2008-07-10 07:30 --------- d-----w C:\Program Files\Norton 360 Online

2008-07-09 14:18 --------- d-----w C:\Users\Ravin\AppData\Roaming\LimeWire

2008-07-09 14:14 --------- d-----w C:\Program Files\LimeWire

2008-07-08 14:07 --------- d-----w C:\Users\Ravin\AppData\Roaming\Symantec

2008-07-08 11:47 805 ----a-w C:\Windows\system32\drivers\SYMEVENT.INF

2008-07-08 11:47 123,952 ----a-w C:\Windows\system32\drivers\SYMEVENT.SYS

2008-07-08 11:47 10,671 ----a-w C:\Windows\system32\drivers\SYMEVENT.CAT

2008-07-08 11:47 --------- d-----w C:\Program Files\Symantec

2008-07-08 11:46 --------- d-----w C:\Program Files\Common Files\Symantec Shared

2008-07-08 09:42 --------- d-----w C:\Program Files\Telenor Sikker Lagring

2008-07-08 09:36 --------- d-----w C:\Users\Ravin\AppData\Roaming\Telenor

2008-07-08 09:06 0 ----a-w C:\nis2008.exe

2008-06-24 07:45 --------- d-----w C:\Users\Ravin\AppData\Roaming\Nokia

2008-06-21 19:08 0 ---ha-w C:\Windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf

2008-06-21 19:04 --------- d-----w C:\Program Files\Nokia

2008-06-14 09:32 --------- d-----w C:\Program Files\Sony

2008-06-14 09:07 --------- d-----w C:\Users\Ravin\AppData\Roaming\Sony Corporation

2008-06-14 09:04 --------- d-----w C:\Program Files\Picasa2

2008-06-14 07:50 --------- d-----w C:\Program Files\Google

2008-06-13 16:56 --------- d-----w C:\Users\Ravin\AppData\Roaming\PC Suite

2008-06-13 16:55 --------- d-----w C:\ProgramData\PC Suite

2008-06-13 16:51 --------- d-----w C:\Program Files\Common Files\PCSuite

2008-06-13 16:51 --------- d-----w C:\Program Files\Common Files\Nokia

2008-06-13 16:50 --------- d-----w C:\Program Files\DIFX

2008-06-13 16:46 --------- d-----w C:\Program Files\PC Connectivity Solution

2008-06-13 16:40 --------- d-----w C:\ProgramData\Installations

2008-06-05 06:33 --------- d-----w C:\Program Files\PalickSoft

2008-06-02 04:41 2,147,544 ----a-w C:\Windows\system32\drivers\RTKVHDA.sys

2008-05-29 16:03 --------- d-----w C:\Users\Ravin\AppData\Roaming\Logitech

2008-05-29 16:03 --------- d-----w C:\ProgramData\LogiShrd

2008-05-29 15:58 --------- d-----w C:\Program Files\Common Files\Logishrd

2008-05-29 15:57 --------- d-----w C:\ProgramData\Logitech

2008-05-29 15:57 --------- d-----w C:\Program Files\Logitech

2008-05-28 02:36 6,144,000 ----a-w C:\Windows\RtHDVCpl.exe

2008-04-25 04:23 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll

2007-08-03 05:39 0 ----a-w C:\Users\Ravin\AppData\Roaming\wklnhst.dat

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-13 01:04 1232896]

"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 18:05 125440]

"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-05-30 15:54 21718312]

"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe" [2008-03-26 18:41 1232896]

"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2008-04-16 12:53 1079808]

"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 18:06 201728]

"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-10-09 10:13 729088]

"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 02:05 1045800]

"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 16:24 54840]

"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2007-03-29 06:15 176128]

"HP Health Check Scheduler"="C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-03-13 00:24 50696]

"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]

"CognizanceTS"="c:\PROGRA~1\BIOSCR~1\VeriSoft\Bin\ASTSVCC.dll" [2003-12-23 00:42 17920]

"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 04:17 31016]

"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 19:10 155648]

"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24 286720]

"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-14 10:00 267064]

"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]

"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 02:29 102400]

"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 11:29 115816]

"MSConfig"="C:\Windows\system32\msconfig.exe" [2006-11-02 15:15 222208]

"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-11-07 02:35 86016]

"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-11-07 02:35 8534560]

"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-11-07 02:35 81920]

"RtHDVCpl"="RtHDVCpl.exe" [2008-05-28 08:06 6144000 C:\Windows\RtHDVCpl.exe]

 

C:\Users\Ravin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 23:54:54 98632]

Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2008-06-14 12:45:29 385024]

Telenor Sikker Lagring.lnk - C:\Program Files\Telenor Sikker Lagring\safestorage.exe [2008-07-08 14:58:09 43008]

 

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\

Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-12-20 15:57:40 719664]

HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-01-03 01:10:10 210520]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"UacDisableNotify"=dword:00000001

"InternetSettingsDisableNotify"=dword:00000001

"AutoUpdateDisableNotify"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{915A2B2E-5408-464A-AA15-FF734E492C4D}"= C:\Program Files\HP\QuickPlay\QP.exe:Quick Play

"{3012EBBA-0370-44A6-87B3-D50F4CDE022A}"= C:\Program Files\HP\QuickPlay\QPService.exe:Quick Play Resident Program

"{EDD813E2-863D-4548-B8B1-C98D98F2D0E5}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook

"{05D277DB-D577-4C7D-A4D8-E0BF86D70E8E}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove

"{E9D8D2CE-B4B5-4A0F-AD5C-4E66FC7B2DD9}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove

"{263E4796-CE69-48A6-9DC0-676AE793C0D6}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote

"{B88F6876-4B60-4DE2-BDEB-A13493ABEE8A}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote

"{91F050BE-7912-4CE1-A380-8109E54CCD58}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes

"{C2343607-FDE3-4BD4-BCAF-A5366D42C746}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes

"{5DEB48B4-8E59-4FD7-90DF-89C15242AD6F}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent

"{CA825080-8965-43E2-A3D8-48F09D3FE706}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent

"{5352130D-A163-4A07-AAAF-4503A7B87E3F}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

"{25E84F1A-96B7-410F-AE38-C707E761825F}"= UDP:C:\Program Files\Online Services\SkypeSV\SkypeSetup.exe:Skype

"{85362CD1-1422-41C8-BFB6-F9175780E920}"= TCP:C:\Program Files\Online Services\SkypeSV\SkypeSetup.exe:Skype

"TCP Query User{6F887F06-5A47-4151-9B12-8DEA79928F88}C:\\program files\\skype\\phone\\skype.exe"= UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath

"UDP Query User{1E831883-DD9D-4744-B329-3E838B846EF2}C:\\program files\\skype\\phone\\skype.exe"= TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath

"{04FD6D47-7603-414F-ADD6-CD168234AFA0}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent

"{7B32A4A4-F73B-4987-BC0A-C9CB3AA65632}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent

"{4B57B943-3EE9-4B1B-B52D-773B389099DE}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire

"{17581F74-36BD-4AB0-85B3-7B805583E027}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire

"TCP Query User{B69AD71A-CA88-44A0-816D-6701BD768615}C:\\program files\\skype\\phone\\skype.exe"= UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath

"UDP Query User{47B62720-0442-4781-B070-5E1590B55C23}C:\\program files\\skype\\phone\\skype.exe"= TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath

"TCP Query User{BA1393A3-1025-4437-A3E9-786EFFD6D8AB}C:\\windows\\system32\\ftp.exe"= UDP:C:\windows\system32\ftp.exe:File Transfer Program

"UDP Query User{4F2C6873-89D6-4091-B164-D3D098F054FB}C:\\windows\\system32\\ftp.exe"= TCP:C:\windows\system32\ftp.exe:File Transfer Program

"TCP Query User{5ED97D1B-ABAD-40BB-97D5-0DDD5CE8FDC7}C:\\users\\ravin\\program files\\utorrent\\utorrent.exe"= UDP:C:\users\ravin\program files\utorrent\utorrent.exe:utorrent.exe

"UDP Query User{1C05E718-B957-427B-88A1-B7933F8196C4}C:\\users\\ravin\\program files\\utorrent\\utorrent.exe"= TCP:C:\users\ravin\program files\utorrent\utorrent.exe:utorrent.exe

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]

"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

 

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

bthsvcs REG_MULTI_SZ BthServ

Cognizance REG_MULTI_SZ ASBroker ASChannel

GPSvcGroup REG_MULTI_SZ GPSvc

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4e6928e7-20ce-11dd-ac61-001a6b89376b}]

\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL remove.exe

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8bdb7c15-16b9-11dd-b43d-001b244258e4}]

\shell\AutoRun\command - F:\fun.exe

\shell\explore\Command - F:\fun.exe

\shell\open\Command - F:\fun.exe

 

*Newly Created Service* - COMHOST

.

Contents of the 'Scheduled Tasks' folder

"2008-06-30 15:05:27 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Ravin.job"

- c:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:

.

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-11 16:08:50

Windows 6.0.6000 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

------------------------ Other Running Processes ------------------------

.

C:\Windows\System32\audiodg.exe

C:\Windows\System32\wisptis.exe

C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe

C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

C:\Windows\System32\wlanext.exe

C:\Program Files\Bioscrypt\VeriSoft\Bin\asghost.exe

C:\Windows\System32\wisptis.exe

C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Hp\QuickPlay\Kernel\TV\CLCapSvc.exe

C:\Program Files\Common Files\LightScribe\LSSrvc.exe

C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe

C:\Program Files\Hp\QuickPlay\Kernel\TV\CLSched.exe

C:\Windows\System32\conime.exe

C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe

C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe

C:\Windows\System32\rundll32.exe

C:\Windows\System32\wbem\unsecapp.exe

C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe

C:\Windows\System32\wbem\WMIADAP.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Windows\System32\rundll32.exe

C:\Windows\ehome\ehmsas.exe

C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe

C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe

C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe

C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe

C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe

C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe

.

**************************************************************************

.

Completion time: 2008-07-11 16:18:23 - machine was rebooted [Ravin]

ComboFix-quarantined-files.txt 2008-07-11 10:47:31

 

The system cannot find message text for message number 0x2379 in the message file for Application.

Post-Run: 90,507,902,976 bytes free

 

215 --- E O F --- 2008-07-11 09:43:26

Lenke til kommentar

Er du sikker på at du har fått med hele HijackThis-loggen? Synes det er rart at du ikke har noe mellom "running processes" og "O23"-linjene.

 

Her er et eksempel på en full HijackThis-logg:

 

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programfiler\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
c:\programfiler\fellesfiler\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programfiler\Logitech\Video\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programfiler\Java\jre1.5.0_07\bin\jusched.exe
C:\Programfiler\Ahead\InCD\InCD.exe
C:\Programfiler\MSN Messenger\MsnMsgr.Exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Kenneth\Skrivebord\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://stealthy.foolishgames.net/news.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Programfiler\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Programfiler\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Programfiler\RivaTuner v2.0 RC 16\RivaTuner.exe" /S
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: Write a Review... - http://client.alexa.com/holiday/script/actions/review.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programfiler\fellesfiler\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Programfiler\Sygate\SPF\smc.exe

 

Prøv en gang til, og se om du fortsatt får samme HijackThis-logg...

 

 

Vidre gjor du følgende:

 

Gå til http://virusscan.jotti.org , trykk på Browse, og last opp følgende fil til analyse:

F:\fun.exe

Deretter trykker du på Submit. Godta at filen blir scannet. Til slutt kopierer du resultatet, og limer det inn i din neste post, så jeg kan se på den, og vurdere hva som må gjøres videre.

 

 

Det kan hende du er nødt til å skru på skjulte filer og mapper for å kunne finne denne fila:

http://windowshelp.microsoft.com/Windows/n...04a59f1044.mspx

Endret av r2d290
Lenke til kommentar

En ting til: Det ser ut til at du har HijackThis kjørende direkte fra Skrivebordet. Hvis du gjør dette, vil ikke HijackThis kunne ta backup av det vi eventuelt fjerner. Siden backup er viktig, bør du flytte denne fila inn i en egen mappe (f.eks i C:\hjt).

 

Du kommer ikke til å få mer respons før du har gjort dette... Si ifra når det er gjort, eller post en ny logg som viser at det er gjort :)

Lenke til kommentar

får opp statig pop ups som "http://nolanding.ringtonetimesDOTnet/ og andre ringtetone sider reklamere for..

 

Hvordan får jeg pop upsen bort???

 

c

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 19:40:29, on 14.07.2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Programfiler\Fellesfiler\Symantec Shared\ccSetMgr.exe

C:\Programfiler\Fellesfiler\Symantec Shared\ccEvtMgr.exe

C:\Programfiler\Fellesfiler\Symantec Shared\SPBBC\SPBBCSvc.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Programfiler\Java\jre1.6.0_05\bin\jusched.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe

C:\PROGRA~1\SYMANT~1\VPTray.exe

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe

D:\Programmer\office\Office12\GrooveMonitor.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe

C:\Programfiler\Messenger\msmsgs.exe

C:\Programfiler\Bonjour\mDNSResponder.exe

C:\Programfiler\Symantec AntiVirus\DefWatch.exe

C:\Programfiler\Symantec AntiVirus\Rtvscan.exe

C:\Programfiler\Windows Live\Messenger\usnsvc.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\Is6l38sq.exe

C:\Programfiler\Mozilla Firefox\firefox.exe

D:\Programfiler\Ny mappe\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: Koblingshjelpeprogram for Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\office\Office12\GRA8E1~1.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [ccApp] "C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [GrooveMonitor] "D:\Programmer\office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Programfiler\Adobe\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [WinampAgent] C:\Programfiler\Winamp\winampa.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\msmsgs.exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\office\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\office\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\office\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\office\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = (skjult)

O17 - HKLM\Software\..\Telephony: DomainName = (skjult)

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = (skjult)

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = (skjult)

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\office\Office12\GR99D3~1.DLL

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Programfiler\Bonjour\mDNSResponder.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccSetMgr.exe

O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Programfiler\Symantec AntiVirus\DefWatch.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programfiler\Fellesfiler\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: SAVRoam (SavRoam) - symantec - C:\Programfiler\Symantec AntiVirus\SavRoam.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\SNDSrvc.exe

O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\SPBBC\SPBBCSvc.exe

O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Programfiler\Symantec AntiVirus\Rtvscan.exe

 

--

End of file - 8077 bytes

 

Endret av matseeey
Lenke til kommentar

Hei, har en terminalserver som jeg mistenker har spyware.

Jeg blir ikke skikkelig klok på den, kan noen være så snill og se på hijackthis loggen og se om det er noe å hente fra den. Det var desverre alt jeg hadde tid til å kjøre i dag. Har kjørt Ccleaner og superantispyware først.

Trenger all den hjelp jeg kan få, da jeg er møkklei av å havne på div. spamfilter... :cry:

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 15:09:09, on 17.07.2008

Platform: Windows 2003 SP2 (WinNT 5.02.3790)

MSIE: Internet Explorer v6.00 SP2 (6.00.3790.3959)

Boot mode: Normal

 

Running processes:

M:\Documents and Settings\Administrator.NORVAG\WINDOWS\System32\smss.exe

M:\WINDOWS\system32\winlogon.exe

M:\WINDOWS\system32\services.exe

M:\WINDOWS\system32\lsass.exe

M:\WINDOWS\system32\svchost.exe

M:\WINDOWS\System32\svchost.exe

M:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

M:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

M:\WINDOWS\system32\brsvc01a.exe

M:\WINDOWS\system32\spoolsv.exe

M:\WINDOWS\system32\brss01a.exe

M:\Program Files\Symantec AntiVirus\DefWatch.exe

M:\WINDOWS\System32\svchost.exe

M:\Program Files\LogMeIn\x86\RaMaint.exe

M:\Program Files\LogMeIn\x86\LogMeIn.exe

M:\Program Files\LogMeIn\x86\LMIGuardian.exe

M:\Program Files\Symantec AntiVirus\SavRoam.exe

M:\Program Files\Symantec AntiVirus\Rtvscan.exe

M:\WINDOWS\system32\lserver.exe

m:\program files\software innovation\vega5\vegasmb.tools.trace.service.exe

M:\Program Files\Citrix\system32\cdmsvc.exe

M:\Program Files\Citrix\System32\ctxxmlss.exe

M:\Program Files\Citrix\system32\encsvc.exe

M:\Program Files\Citrix\System32\Citrix\Ima\ImaSrv.exe

M:\Program Files\Citrix\System32\mfcom.exe

M:\WINDOWS\System32\svchost.exe

M:\WINDOWS\system32\winlogon.exe

M:\WINDOWS\System32\svchost.exe

M:\Program Files\Citrix\ICA Client\ssonsvr.exe

M:\WINDOWS\Explorer.EXE

M:\Program Files\Citrix\system32\icabar.exe

M:\Program Files\Common Files\Symantec Shared\ccApp.exe

M:\PROGRA~1\SYMANT~1\VPTray.exe

M:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

M:\Program Files\LogMeIn\x86\LogMeInSystray.exe

M:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

M:\WINDOWS\system32\ctfmon.exe

M:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

M:\Program Files\LogMeIn\x86\LMIGuardian.exe

M:\Program Files\WinZip\WZQKPICK.EXE

M:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

M:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

M:\WINDOWS\system32\winlogon.exe

M:\WINDOWS\system32\winlogon.exe

M:\WINDOWS\system32\winlogon.exe

M:\WINDOWS\system32\winlogon.exe

M:\WINDOWS\system32\winlogon.exe

M:\WINDOWS\system32\winlogon.exe

M:\WINDOWS\system32\winlogon.exe

M:\WINDOWS\system32\winlogon.exe

M:\WINDOWS\system32\winlogon.exe

M:\WINDOWS\system32\winlogon.exe

M:\Program Files\Internet Explorer\IEXPLORE.EXE

M:\Program Files\LogMeIn\x86\LogMeIn.exe

M:\Program Files\LogMeIn\x86\LMIGuardian.exe

M:\Documents and Settings\Administrator.NORVAG\Desktop\kjeks\testprog.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.no

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.no

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = M:\WINDOWS\system32\blank.htm

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Norvag

F2 - REG:system.ini: UserInit=M:\WINDOWS\system32\userinit.exe,

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - M:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - M:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - m:\program files\google\googletoolbar1.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - M:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - m:\program files\google\googletoolbar1.dll

O4 - HKLM\..\Run: [icaBar] "M:\Program Files\Citrix\system32\icabar.exe" /adminonly

O4 - HKLM\..\Run: [ccApp] "M:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [vptray] M:\PROGRA~1\SYMANT~1\VPTray.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "M:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKLM\..\Run: [LogMeIn GUI] "M:\Program Files\LogMeIn\x86\LogMeInSystray.exe"

O4 - HKLM\..\Run: [Google Desktop Search] "M:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

O4 - HKCU\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] M:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-21-17155eg blir 67821-725345543-1417001333-1120\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'tot')

O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1120\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'tot')

O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1122\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'ao')

O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1122\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'ao')

O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1126\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'ek')

O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1126\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'ek')

O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1130\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'js')

O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1130\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'js')

O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1133\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'ka')

O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1142\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'le')

O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1142\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'le')

O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1190\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'idarp')

O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1190\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'idarp')

O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1195\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'frodea')

O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1612\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'perh')

O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1614\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'bodobutikk')

O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1614\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'bodobutikk')

O4 - HKUS\S-1-5-21-1715567821-725345543-1417001333-1615\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'jonnyo')

O4 - HKUS\S-1-5-21-3295084221-2774560929-1612176347-1004\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\CTFMON.EXE (User 'Ctx_SmaUser')

O4 - HKUS\S-1-5-21-3295084221-2774560929-1612176347-1004\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Ctx_SmaUser')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] M:\WINDOWS\system32\ctfmon.exe (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')

O4 - Global Startup: Hurtigstart for Adobe Reader.lnk = M:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: WinZip Quick Pick.lnk = M:\Program Files\WinZip\WZQKPICK.EXE

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://M:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - M:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - M:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - M:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL

O10 - Broken Internet access because of LSP provider 'm:\documents and settings\administrator.norvag\windows\system32\mswsock.dll' missing

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1160999908231

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = norvag.no

O17 - HKLM\Software\..\Telephony: DomainName = norvag.no

O17 - HKLM\System\CCS\Services\Tcpip\..\{CD3C6594-6A07-4B19-89C4-C3FAE82CFCFE}: NameServer = 192.168.1.10

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = norvag.no

O20 - AppInit_DLLs: mfaphook.dll M:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - M:\WINDOWS\system32\brsvc01a.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - M:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - M:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - M:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

O23 - Service: Diagnostic Facility COM Server (CdfSvc) - Citrix Systems, Inc. - M:\Program Files\Common Files\Citrix\System32\CdfSvc.exe

O23 - Service: Client Network (CdmService) - Citrix Systems, Inc. - M:\Program Files\Citrix\system32\cdmsvc.exe

O23 - Service: Citrix SMA Service - Citrix Systems Inc. - M:\Program Files\Citrix\Sma\SmaService.exe

O23 - Service: Citrix Virtual Memory Optimization - Citrix Systems, Inc. - M:\Program Files\Citrix\Server Resource Management\Memory Optimization Management\Program\CtxSFOSvc.exe

O23 - Service: Citrix XTE Server (CitrixXTEServer) - Citrix Systems, Inc. - M:\Program Files\Citrix\XTE\bin\XTE.exe

O23 - Service: Citrix Print Manager Service (cpsvc) - Citrix Systems, Inc. - M:\Program Files\Citrix\system32\CpSvc.exe

O23 - Service: Citrix CPU Utilization Mgmt/Resource Mgmt (ctxcpuSched) - Aurema Pty Limited - M:\Program Files\Citrix\Server Resource Management\CPU Utilization Management\bin\ctxcpusched.exe

O23 - Service: Citrix CPU Utilization Mgmt/User-Session Sync (CTXCPUUsync) - Aurema Pty Limited - M:\Program Files\Citrix\Server Resource Management\CPU Utilization Management\bin\ctxcpuusync.exe

O23 - Service: Citrix XML Service (CtxHttp) - Citrix Systems, Inc. - M:\Program Files\Citrix\System32\ctxxmlss.exe

O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - M:\Program Files\Symantec AntiVirus\DefWatch.exe

O23 - Service: Encryption Service - Citrix Systems, Inc. - M:\Program Files\Citrix\system32\encsvc.exe

O23 - Service: GoogleDesktopManager - Google - M:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

O23 - Service: Google Updater Service (gusvc) - Google - M:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Independent Management Architecture (IMAService) - Citrix Systems, Inc. - M:\Program Files\Citrix\System32\Citrix\Ima\ImaSrv.exe

O23 - Service: InfoCenter - Software Innovation asa - M:\Program Files\Software Innovation\InfoCenter\infocsvc.exe

O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - M:\Program Files\LogMeIn\x86\RaMaint.exe

O23 - Service: LogMeIn - LogMeIn, Inc. - M:\Program Files\LogMeIn\x86\LogMeIn.exe

O23 - Service: MetaFrame COM Server (MFCom) - Citrix Systems, Inc. - M:\Program Files\Citrix\System32\mfcom.exe

O23 - Service: Phobos - Software Innovation asa - M:\Program Files\Software Innovation\Polaris\phobos.exe

O23 - Service: SAVRoam (SavRoam) - symantec - M:\Program Files\Symantec AntiVirus\SavRoam.exe

O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - M:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

O23 - Service: Symantec AntiVirus - Symantec Corporation - M:\Program Files\Symantec AntiVirus\Rtvscan.exe

O23 - Service: VegaSMB.Indexing.Service - Unknown owner - m:\program files\software innovation\vega5\vegasmb.indexing.service.exe

O23 - Service: VegaSMB.Tools.Trace.Service - Unknown owner - m:\program files\software innovation\vega5\vegasmb.tools.trace.service.exe

 

--

End of file - 12851 bytes

 

 

Lenke til kommentar

Fila M:\Documents and Settings\Administrator.NORVAG\WINDOWS\System32\smss.exe bruker kanskje å kjøre fra denne plasseringen på serveren? (Vanlig plassering er WINDOWS\System32\smss.exe).

 

Hva gjør at du mistenker malware?

Lenke til kommentar

Det at det er den eneste maskina i nettverket som har lov til å sende på port 25 og jeg har problemer med at jeg blir utestengt fra div spamfilter pga spam. Her er feedbacken jeg får fra en av svartelistene:

 

ATTENTION: This IP is infected with, or NATting for a computer infected with a high volume spam sending trojan - it is participating in a botnet.

 

This is the Srizbi BOT

 

You need to patch your system and then fix/remove the trojan. Do this before delisting, or you're most likely to be listed again almost immediately.

 

If this IP is a NAT firewall/gateway, you MUST configure the NAT to prevent outbound port 25 connections to the Internet except from your real mail servers.

Lenke til kommentar

SAS logg

 

SUPERAntiSpyware Scan Log

http://www.superantispyware.com

 

Generated 07/22/2008 at 01:59 AM

 

Application Version : 4.15.1000

 

Core Rules Database Version : 3469

Trace Rules Database Version: 1460

 

Scan type : Quick Scan

Total Scan Time : 00:18:51

 

Memory items scanned : 476

Memory threats detected : 13

Registry items scanned : 487

Registry threats detected : 104

File items scanned : 9797

File threats detected : 134

 

Adware.Adservs

C:\WINDOWS\SMFUIEHVBHZPAW\ASAPPSRV.DLL

C:\WINDOWS\SMFUIEHVBHZPAW\ASAPPSRV.DLL

C:\WINDOWS\system32\atmtd.dll

C:\WINDOWS\system32\atmtd.dll._

C:\WINDOWS\SYSTEM32\MD4\VOMB33DLL.EXE

 

Trojan.Vundo-Variant/Small

C:\WINDOWS\SYSTEM32\SXGBWBSO.DLL

C:\WINDOWS\SYSTEM32\SXGBWBSO.DLL

C:\WINDOWS\SYSTEM32\PINPXUOK.DLL

C:\WINDOWS\SYSTEM32\PINPXUOK.DLL

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d74a6b4f-8280-42ca-adfa-73163665b7d7}

HKCR\CLSID\{D74A6B4F-8280-42CA-ADFA-73163665B7D7}

HKCR\CLSID\{D74A6B4F-8280-42CA-ADFA-73163665B7D7}\InprocServer32

HKCR\CLSID\{D74A6B4F-8280-42CA-ADFA-73163665B7D7}\InprocServer32#ThreadingModel

C:\WINDOWS\SYSTEM32\ABDIYILJ.DLL

C:\WINDOWS\SYSTEM32\PFLQBCFD.DLL

C:\WINDOWS\SYSTEM32\RUGWVUEW.DLL

C:\WINDOWS\SYSTEM32\WHSKWPVV.DLL

 

Trojan.Vundo-Variant/F

C:\WINDOWS\SYSTEM32\IIFGFGG.DLL

C:\WINDOWS\SYSTEM32\IIFGFGG.DLL

Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\iifgfgg

C:\WINDOWS\SYSTEM32\EFCDDDD.DLL

C:\WINDOWS\SYSTEM32\IIFFEUUO.DLL

 

Adware.Vundo Variant/Resident

C:\WINDOWS\SYSTEM32\MLLMK.DLL

C:\WINDOWS\SYSTEM32\MLLMK.DLL

 

Unclassified.Unknown Origin

C:\WINDOWS\SMFUIEHVBHZPAW\COMMAND.EXE

C:\WINDOWS\SMFUIEHVBHZPAW\COMMAND.EXE

 

Trojan.NetMon/DNSChange

C:\PROGRAMFILER\NETWORK MONITOR\NETMON.EXE

C:\PROGRAMFILER\NETWORK MONITOR\NETMON.EXE

HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor

HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor#Type

HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor#Start

HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor#ErrorControl

HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor#ImagePath

HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor#DisplayName

HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor#ObjectName

HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor\Security

HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor\Security#Security

HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor\Enum

HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor\Enum#0

HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor\Enum#Count

HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor\Enum#NextInstance

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR#NextInstance

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR00

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR00#Service

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR00#Legacy

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR00#ConfigFlags

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR00#Class

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR00#ClassGUID

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR00#DeviceDesc

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR00\Control

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR00\Control#ActiveService

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A394E835-C8D6-4B4B-884B-D2709059F3BE}

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A394E835-C8D6-4B4B-884B-D2709059F3BE}#Contact

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A394E835-C8D6-4B4B-884B-D2709059F3BE}#DisplayName

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A394E835-C8D6-4B4B-884B-D2709059F3BE}#DisplayVersion

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A394E835-C8D6-4B4B-884B-D2709059F3BE}#NoModify

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A394E835-C8D6-4B4B-884B-D2709059F3BE}#NoRemove

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A394E835-C8D6-4B4B-884B-D2709059F3BE}#NoRepair

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A394E835-C8D6-4B4B-884B-D2709059F3BE}#UninstallString

C:\Programfiler\Network Monitor

 

Trojan.Downloader-Gen/Svchost-Fake

C:\WINDOWS\FONTS\SVCHOST.EXE

C:\WINDOWS\FONTS\SVCHOST.EXE

C:\WINDOWS\Prefetch\SVCHOST.EXE-178E8C2A.pf

 

Adware.JavaCore

C:\PROGRAMFILER\JAVACORE\JAVACORE.EXE

C:\PROGRAMFILER\JAVACORE\JAVACORE.EXE

[JavaCore] C:\PROGRAMFILER\\JAVACORE\\JAVACORE.EXE

C:\PROGRAMFILER\\JAVACORE\\JAVACORE.EXE

C:\WINDOWS\Prefetch\JAVACORE.EXE-33709A79.pf

 

Adware.ClickSpring-Variant

C:\WINDOWS\SSTEM3~1\SMSS.EXE

C:\WINDOWS\SSTEM3~1\SMSS.EXE

[sira] C:\WINDOWS\SSTEM3~1\SMSS.EXE

C:\WINDOWS\S?STEM32\SMSS.EXE

C:\WINDOWS\Prefetch\SMSS.EXE-2A18F5C8.pf

 

Adware.ClickSpring/Resident

C:\PROGRA~1\STEM32~1\DXPLOR~1.EXE

C:\PROGRA~1\STEM32~1\DXPLOR~1.EXE

C:\WINDOWS\SYSTEM32\GPOOE.DLL

C:\WINDOWS\SYSTEM32\GPOOE.DLL

 

Trojan.Downloader-NewJuan/VM

C:\WINDOWS\SYSTEM32\LVLNNNXT.DLL

C:\WINDOWS\SYSTEM32\LVLNNNXT.DLL

 

Trojan.Downloader-SVCHost/Fake

[Host Process] C:\WINDOWS\FONTS\SVCHOST.EXE

 

Adware.Vundo Variant

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{57B56E77-ACE3-4A90-8171-64A39F880E9F}

HKCR\CLSID\{57B56E77-ACE3-4A90-8171-64A39F880E9F}

HKCR\CLSID\{57B56E77-ACE3-4A90-8171-64A39F880E9F}\InprocServer32

HKCR\CLSID\{57B56E77-ACE3-4A90-8171-64A39F880E9F}\InprocServer32#ThreadingModel

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{70AB0A8B-8A8A-496F-A339-4CD2F3352991}

HKCR\CLSID\{70AB0A8B-8A8A-496F-A339-4CD2F3352991}

HKCR\CLSID\{70AB0A8B-8A8A-496F-A339-4CD2F3352991}\InprocServer32

HKCR\CLSID\{70AB0A8B-8A8A-496F-A339-4CD2F3352991}\InprocServer32#ThreadingModel

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EFFB38AD-AC35-F1C4-1793-A18F02232EC3}

HKCR\CLSID\{EFFB38AD-AC35-F1C4-1793-A18F02232EC3}

HKCR\CLSID\{EFFB38AD-AC35-F1C4-1793-A18F02232EC3}\InprocServer32

HKCR\CLSID\{EFFB38AD-AC35-F1C4-1793-A18F02232EC3}\InprocServer32#ThreadingModel

HKCR\CLSID\{EFFB38AD-AC35-F1C4-1793-A18F02232EC3}\Programmable

HKCR\CLSID\{EFFB38AD-AC35-F1C4-1793-A18F02232EC3}\TypeLib

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{70AB0A8B-8A8A-496F-A339-4CD2F3352991}

HKCR\CLSID\{70AB0A8B-8A8A-496F-A339-4CD2F3352991}

 

Adware.Tracking Cookie

 

 

Trojan.cmdService

HKLM\SYSTEM\CurrentControlSet\Services\cmdService

HKLM\SYSTEM\CurrentControlSet\Services\cmdService#Type

HKLM\SYSTEM\CurrentControlSet\Services\cmdService#Start

HKLM\SYSTEM\CurrentControlSet\Services\cmdService#ErrorControl

HKLM\SYSTEM\CurrentControlSet\Services\cmdService#ImagePath

HKLM\SYSTEM\CurrentControlSet\Services\cmdService#DisplayName

HKLM\SYSTEM\CurrentControlSet\Services\cmdService#ObjectName

HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Security

HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Security#Security

HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum

HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum#0

HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum#Count

HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum#NextInstance

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}#Contact

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}#DisplayName

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}#DisplayVersion

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}#NoModify

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}#NoRemove

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}#NoRepair

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}#UninstallString

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE#NextInstance

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE00

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE00#Service

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE00#Legacy

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE00#ConfigFlags

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE00#Class

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE00#ClassGUID

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE00#DeviceDesc

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE00\Control

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE00\Control#ActiveService

 

Adware.ClickSpring/Outer Info Network

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#Publisher

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#DisplayName

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#UninstallString

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#HelpLink

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#InstallLocation

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#NoModify

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#NoRepair

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#DisplayVersion

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#DisplayIcon

C:\Programfiler\Outerinfo\FF\chrome.manifest

C:\Programfiler\Outerinfo\FF\components\FF.dll

C:\Programfiler\Outerinfo\FF\components\OuterinfoAds.xpt

C:\Programfiler\Outerinfo\FF\components

C:\Programfiler\Outerinfo\FF\install.rdf

C:\Programfiler\Outerinfo\FF

C:\Programfiler\Outerinfo\Terms.rtf

C:\Programfiler\Outerinfo

C:\Documents and Settings\Eier\Start-meny\Programmer\Outerinfo\Terms.lnk

C:\Documents and Settings\Eier\Start-meny\Programmer\Outerinfo\Uninstall.lnk

C:\Documents and Settings\Eier\Start-meny\Programmer\Outerinfo

 

Trojan.Downloader-Gen/RetAd

HKLM\Software\Microsoft\Windows\CurrentVersion\Run#runner1 [ C:\WINDOWS\mrofinu1188.exe 61A847B5BBF72813339330466188719AB689201522886B092CBD44BD8689220221DD325762EA4EBF968951185E

C412806867680AEDE604D64C2661373F819EBDCD66A47 ]

 

Rogue.SysCleaner

HKU\S-1-5-21-2820906742-3425357240-438028536-1007\Software\xInsiDERexe

 

Adware.WinTouch/XInside

C:\Programfiler\InetGet2

 

Adware.JavaCore/NoDNS

C:\Programfiler\JavaCore\UnInstall.exe

C:\Programfiler\JavaCore

HKU\S-1-5-21-2820906742-3425357240-438028536-1007\Software\Microsoft\Windows\CurrentVersion\Run#JavaCore [ C:\Programfiler\\JavaCore\\JavaCore.exe ]

 

Trojan.Unclassified/NVCOI

C:\Programfiler\Temporary\InsiDERInst.exe

C:\Programfiler\Temporary

C:\WINDOWS\Prefetch\INSIDERINST.EXE-23669BF1.pf

 

Adware.Vundo Variant/Rel

HKLM\SOFTWARE\Microsoft\aoprndtws

HKLM\SOFTWARE\Microsoft\RemoveRP

HKU\S-1-5-21-2820906742-3425357240-438028536-1007\Software\Microsoft\rdfa

C:\WINDOWS\SYSTEM32\KMLLM.INI

C:\WINDOWS\SYSTEM32\KMLLM.INI2

 

Trojan.Unclassified/Zombie

C:\DOCUMENTS AND SETTINGS\EIER\LSASS.EXE

C:\WINDOWS\Prefetch\LSASS.EXE-39593BC0.pf

 

Adware.ClickSpring/Yazzle

C:\PROGRAMFILER\FELLESFILER\YAZZLE1560OINUNINSTALLER.EXE

 

Trojan.Downloader-Gen/Bundle Installer

C:\WINDOWS\B128.EXE

C:\WINDOWS\B152.EXE

C:\WINDOWS\B153.EXE

C:\WINDOWS\B156.EXE

C:\WINDOWS\Prefetch\B128.EXE-13D9CEE5.pf

C:\WINDOWS\Prefetch\B152.EXE-2574C670.pf

C:\WINDOWS\Prefetch\B153.EXE-298A1742.pf

C:\WINDOWS\Prefetch\B156.EXE-36A8F193.pf

 

Trojan.Downloader-Gen/MROFIN

C:\WINDOWS\MROFINU1000106.EXE

C:\WINDOWS\MROFINU1188.EXE

C:\WINDOWS\Prefetch\MROFINU1000106.EXE-23500A9A.pf

C:\WINDOWS\Prefetch\MROFINU1188.EXE-035A0B37.pf

 

Adware.Vundo-Variant/E

C:\WINDOWS\SYSTEM32\APYUDUGK.DLL

C:\WINDOWS\SYSTEM32\GROGMLMJ.DLL

C:\WINDOWS\SYSTEM32\ISCRWWWM.DLL

C:\WINDOWS\SYSTEM32\KCAYKNTS.DLL

 

Adware.Vundo-Variant/Small-A

C:\WINDOWS\SYSTEM32\BUMEPRPD.DLL

C:\WINDOWS\SYSTEM32\DXEYLTCJ.DLL

C:\WINDOWS\SYSTEM32\ERVOMIAO.DLL

C:\WINDOWS\SYSTEM32\LYQFPYTK.DLL

C:\WINDOWS\SYSTEM32\WIQNIBTS.DLL

 

Trojan.Vundo-Variant/Small-GEN

C:\WINDOWS\SYSTEM32\GEBTLBRO.DLL

 

Trojan.Unknown Origin

C:\WINDOWS\SMFUIEHVBHZPAW\MAIRKH1SVJTDUT.VBS

C:\WINDOWS\UNINSTALL_NMON.VBS

 

 

 

COMBOFIX logg

 

 

ComboFix 08-07-21.1 - Eier 2008-07-22 2:24:01.1 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1044.18.216 [GMT 2:00]

Running from: C:\Documents and Settings\Eier\Skrivebord\combofix.exe

* Created a new restore point

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\BrowserSearch\BrowserSearch.xml

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\BrowserSearch\BrowserSearch.xml.backup

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Configurator\Configurator.xml

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Configurator\Configurator.xml.backup

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\ErrorSearch\ErrorSearchOptions.xml

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\ErrorSearch\ErrorSearchOptions.xml.backup

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Games\GamesOptions.xml

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Games\GamesOptions.xml.backup

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Games\images\active\Games0.bmp

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Layouts\ToolbarLayout.xml

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Layouts\ToolbarLayout.xml.backup

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Manager\ManagerOptions.xml

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Manager\ManagerOptions.xml.backup

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Movies\images\active\Movies0.bmp

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Movies\MoviesOptions.xml

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Movies\MoviesOptions.xml.backup

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Reference\ReferenceOptions.xml

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Reference\ReferenceOptions.xml.backup

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\RelatedSearch\RelatedSearchOptions.xml

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\RelatedSearch\RelatedSearchOptions.xml.backup

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Screensavers\ScreensaversOptions.xml

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Screensavers\ScreensaversOptions.xml.backup

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\ScreensaversMarketingSitePager\images\active\ScreensaversMarketingSitePager0.bmp

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Toolbar\TBProductsOptions.xml

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Toolbar\TBProductsOptions.xml.backup

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\ToolbarLogo\ToolbarLogoOptions.xml

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\ToolbarLogo\ToolbarLogoOptions.xml.backup

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\ToolbarSearch\ToolbarSearchOptions.xml

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\ToolbarSearch\ToolbarSearchOptions.xml.backup

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\TravelSearch\TravelSearchOptions.xml

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\TravelSearch\TravelSearchOptions.xml.backup

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Weather\AlertArchive.xml

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Weather\WeatherOptions.xml

C:\Documents and Settings\GJESTEKONTO\Programdata\Starware316\Weather\WeatherOptions.xml.backup

C:\Documents and Settings\LocalService\Programdata\NetMon

C:\Documents and Settings\LocalService\Programdata\NetMon\domains.txt

C:\Documents and Settings\LocalService\Programdata\NetMon\log.txt

C:\Programfiler\network monitor

C:\Programfiler\stem32~1

C:\Programfiler\Svconr

C:\Programfiler\Svconr\Svconr.exe

C:\Temp\1cb

C:\Temp\1cb\syscheck.log

C:\Temp\gbRve12

C:\Temp\gbRve12\csLioes.log

C:\Temp\sanR24

C:\Temp\sanR24\lDii.log

C:\Temp\vtmp2

C:\Temp\vtmp2\ktnv33.log

C:\WINDOWS\Downloaded Program Files\setup.inf

C:\WINDOWS\Fonts\'

C:\WINDOWS\Fonts\a.zip

C:\WINDOWS\Fonts\Crack.exe

C:\WINDOWS\pskt.ini

C:\WINDOWS\sstem3~1

C:\WINDOWS\sstem3~1\s?stem32\

C:\WINDOWS\system32\ahcsonvw.ini

C:\WINDOWS\system32\aqVreo18

C:\WINDOWS\system32\aqVreo18\aqVreo182328.exe

C:\WINDOWS\system32\AutoRun.inf

C:\WINDOWS\system32\jnxxcvhv.exe

C:\WINDOWS\system32\kernlaoo.exe

C:\WINDOWS\system32\mcrh.tmp

C:\WINDOWS\system32\mdm.exe

C:\WINDOWS\system32\MSINET.oca

C:\WINDOWS\system32\nytedlhd.ini

C:\WINDOWS\system32\oaimovre.ini

C:\WINDOWS\system32\osbwbgxs.ini

C:\WINDOWS\system32\osbwbgxs.ini2

C:\WINDOWS\system32\osbwbgxs.tmp

C:\WINDOWS\system32\pac.txt

C:\WINDOWS\system32\superiorads-uninst.exe

C:\WINDOWS\system32\uqvdkeet.ini

C:\winlogon.exe

C:\x.dat

C:\z.dat

 

.

((((((((((((((((((((((((( Files Created from 2008-06-22 to 2008-07-22 )))))))))))))))))))))))))))))))

.

 

2008-07-22 01:38 . 2008-07-22 01:38 <DIR> dr-h----- C:\Documents and Settings\Eier\Siste

2008-07-22 01:37 . 2008-07-22 01:37 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\SUPERAntiSpyware.com

2008-07-22 01:36 . 2008-07-22 01:36 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware

2008-07-22 01:36 . 2008-07-22 01:36 <DIR> d-------- C:\Documents and Settings\Eier\Programdata\SUPERAntiSpyware.com

2008-07-22 01:35 . 2008-07-22 01:35 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard

2008-07-22 01:31 . 2008-07-22 01:31 <DIR> d-------- C:\Programfiler\CCleaner

2008-07-22 00:56 . 2008-07-22 00:56 128 --a------ C:\Documents and Settings\Eier\services.exe

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-07-22 00:32 --------- d-----w C:\Programfiler\Steam

2008-07-21 22:59 --------- d-----w C:\Documents and Settings\Eier\Programdata\LimeWire

2008-07-21 22:54 --------- d---a-w C:\Documents and Settings\All Users\Programdata\TEMP

2008-03-12 17:23 40,960 ----a-w C:\Documents and Settings\Eier\f.exe

2008-02-08 01:07 217,088 ----a-w C:\Programfiler\TTC.dll

2008-01-21 19:31 63,408 ----a-w C:\Documents and Settings\Eier\Programdata\GDIPFONTCACHEV1.DAT

2008-01-15 21:34 140,800 --sh--w C:\Programfiler\Fellesfiler\Yazzle1560OinAdmin.exe

2007-01-26 12:31 62,400 ----a-w C:\Documents and Settings\GJESTEKONTO\Programdata\GDIPFONTCACHEV1.DAT

2004-07-22 08:51 3,432,656 -c--a-w C:\Programfiler\ManagedDX.CAB

2004-07-19 20:58 1,156,363 -c--a-w C:\Programfiler\BDANT.cab

2004-07-19 20:53 976,020 -c--a-w C:\Programfiler\BDAXP.cab

2004-07-09 12:17 13,265,040 -c--a-w C:\Programfiler\dxnt.cab

2004-07-09 07:13 703,080 -c--a-w C:\Programfiler\BDA.cab

2004-07-09 07:13 15,493,481 -c--a-w C:\Programfiler\DirectX.cab

2004-07-09 02:08 472,576 ----a-w C:\Programfiler\dxsetup.exe

2004-07-09 02:08 2,242,560 ----a-w C:\Programfiler\dsetup32.dll

2004-07-09 01:03 62,976 ----a-w C:\Programfiler\DSETUP.dll

1999-08-18 14:36 135,168 -c--a-w C:\WINDOWS\inf\Agfa\message.exe

2006-12-06 07:17 104 --sh--r C:\WINDOWS\system32\94CEB4F867.sys

2007-03-02 19:58 6,580 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Dqdwve"="C:\Programfiler\??stem32\d?xplore.exe" [?]

"MsnMsgr"="C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 12:34 5724184]

"Steam"="c:\programfiler\steam\steam.exe" [2008-05-01 14:19 1271032]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]

"CTSyncU.exe"="C:\Programfiler\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-07-17 12:03 868352]

"SUPERAntiSpyware"="C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [X]

"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 22:49 94208]

"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 22:46 77824]

"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 22:50 114688]

"SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00 132496]

"DMXLauncher"="C:\Programfiler\Dell\Media Experience\DMXLauncher.exe" [2005-11-01 05:12 94208]

"SynTPEnh"="C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 06:56 761947]

"Dell QuickSet"="C:\Programfiler\Dell\QuickSet\quickset.exe" [2005-12-15 12:44 839680]

"ISUSPM Startup"="C:\Programfiler\Fellesfiler\InstallShield\UpdateService\isuspm.exe" [2005-06-10 12:44 249856]

"ISUSScheduler"="C:\Programfiler\Fellesfiler\InstallShield\UpdateService\issch.exe" [2005-06-10 12:44 81920]

"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 07:20 122940]

"Microsoft Works Update Detection"="C:\Programfiler\Fellesfiler\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-25 07:20 28672]

"CTCheck"="C:\Programfiler\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe" [2007-11-06 12:08 397312]

"HP Software Update"="C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 22:34 49152]

"Google Desktop Search"="C:\Programfiler\Google\Google Desktop Search\GoogleDesktop.exe" [2008-03-07 15:57 29744]

"SigmatelSysTrayApp"="stsystra.exe" [2005-09-10 01:19 393216 C:\WINDOWS\stsystra.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]

 

C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\

Digital Line Detect.lnk - C:\Programfiler\Digital Line Detect\DLG.exe [2006-03-24 15:59:55 24576]

HP Digital Imaging Monitor.lnk - C:\Programfiler\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 22:26:24 210520]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2007-04-19 13:41 294912 C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Programfiler\\Messenger\\msmsgs.exe"=

"C:\\WINDOWS\\system32\\dpvsetup.exe"=

"C:\\StubInstaller.exe"=

"C:\\Programfiler\\LimeWire\\LimeWire.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"C:\\Programfiler\\Steam\\SteamApps\\vholvik\\counter-strike source\\hl2.exe"=

"C:\\Programfiler\\Steam\\SteamApps\\marti946\\counter-strike source\\hl2.exe"=

"C:\\Programfiler\\Windows Live\\Messenger\\livecall.exe"=

"C:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"=

 

R2 NwSapAgent;SAP Agent;C:\WINDOWS\system32\svchost.exe [2004-08-04 14:00]

S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;C:\Programfiler\Google\Google Desktop Search\GoogleDesktop.exe [2008-03-07 15:57]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

Contents of the 'Scheduled Tasks' folder

"2006-07-10 21:27:34 C:\WINDOWS\Tasks\Low Battery Alarm Program.job"

.

- - - - ORPHANS REMOVED - - - -

 

HKCU-Run-ModemOnHold - C:\Programfiler\NetWaiting\netwaiting.exe

HKCU-Run-WebCamRT.exe - (no file)

HKLM-Run-Engage - c:\programfiler\engage\engage.exe

HKLM-Run-BMfb8f3b4f - C:\WINDOWS\system32\pinpxuok.dll

HKLM-Run-f8bc08d3 - C:\WINDOWS\system32\sxgbwbso.dll

HKLM-Run-Logitech Hardware Abstraction Layer - KHALMNPR.EXE

 

 

.

------- Supplementary Scan -------

.

R0 -: HKCU-Main,Start Page = hxxp://www.nettby.no/

R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}

R0 -: HKLM-Main,Window Title = Microsoft Internet Explorer

R1 -: HKCU-Internet Settings,ProxyOverride = localhost

O8 -: E&ksporter til Microsoft Excel - C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000

 

O16 -: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} - hxxp://www.tvlution.com/KooPlayer.ocx

C:\WINDOWS\Downloaded Program Files\KooPlayer.ocx

 

O16 -: {745395C8-D0E1-4227-8586-624CA9A10A8D} - hxxp://217.197.149.13/activex/AMC.cab

C:\WINDOWS\Downloaded Program Files\setup.inf

 

O16 -: {C111A91F-D4EC-4D22-8D27-C3BCB0389F43} - hxxp://195.136.36.165/activex/AMC.cab

C:\WINDOWS\Downloaded Program Files\setup.inf

 

O16 -: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://cam.butovonet.ru/activex/AMC.cab

C:\WINDOWS\Downloaded Program Files\setup.inf

 

 

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-22 02:32:03

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

------------------------ Other Running Processes ------------------------

.

C:\WINDOWS\system32\WLTRYSVC.EXE

C:\WINDOWS\system32\BCMWLTRY.EXE

C:\WINDOWS\system32\brss01a.exe

C:\WINDOWS\system32\CTSVCCDA.EXE

C:\Programfiler\Dell\NicConfigSvc\NicConfigSvc.exe

C:\WINDOWS\system32\WLTRAY.EXE

C:\WINDOWS\system32\igfxsrvc.exe

C:\WINDOWS\system32\msiexec.exe

C:\Programfiler\HP\Digital Imaging\bin\hpqste08.exe

.

**************************************************************************

.

Completion time: 2008-07-22 2:38:08 - machine was rebooted

ComboFix-quarantined-files.txt 2008-07-22 00:37:54

 

Pre-Run: 37,276,983,296 byte ledig

Post-Run: 37,554,270,208 byte ledig

 

233 --- E O F --- 2008-05-24 14:07:02

 

 

 

HIJACKTHIS logg

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 02:43:26, on 22.07.2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\wltrysvc.exe

C:\WINDOWS\System32\bcmwltry.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\brss01a.exe

C:\WINDOWS\system32\CTsvcCDA.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Programfiler\Dell\NICCONFIGSVC\NICCONFIGSVC.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe

C:\WINDOWS\stsystra.exe

C:\Programfiler\Dell\Media Experience\DMXLauncher.exe

C:\WINDOWS\system32\WLTRAY.exe

C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe

C:\Programfiler\Dell\QuickSet\quickset.exe

C:\WINDOWS\System32\DLA\DLACTRLW.EXE

C:\Programfiler\Fellesfiler\Microsoft Shared\Works Shared\WkUFind.exe

C:\Programfiler\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe

C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe

C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe

C:\WINDOWS\system32\igfxsrvc.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\Creative\Sync Manager Unicode\CTSyncU.exe

C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\WINDOWS\system32\msiexec.exe

C:\Programfiler\Digital Line Detect\DLG.exe

C:\Programfiler\HP\Digital Imaging\bin\hpqtra08.exe

C:\Programfiler\HP\Digital Imaging\bin\hpqSTE08.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\explorer.exe

C:\Programfiler\internet explorer\iexplore.exe

C:\Programfiler\HP\Smart Web Printing\hpswp_clipbook.exe

C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Documents and Settings\Eier\Skrivebord\hijackkk\test.exe.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nettby.no/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Programfiler\HP\Smart Web Printing\hpswp_framework.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll

O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe"

O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe

O4 - HKLM\..\Run: [DMXLauncher] C:\Programfiler\Dell\Media Experience\DMXLauncher.exe

O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY

O4 - HKLM\..\Run: [synTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [Dell QuickSet] C:\Programfiler\Dell\QuickSet\quickset.exe

O4 - HKLM\..\Run: [showLOMControl]

O4 - HKLM\..\Run: [iSUSPM Startup] "C:\Programfiler\Fellesfiler\InstallShield\UpdateService\isuspm.exe" -startup

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Programfiler\Fellesfiler\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE

O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programfiler\Fellesfiler\Microsoft Shared\Works Shared\WkUFind.exe

O4 - HKLM\..\Run: [CTCheck] C:\Programfiler\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe

O4 - HKLM\..\Run: [HP Software Update] C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [Google Desktop Search] "C:\Programfiler\Google\Google Desktop Search\GoogleDesktop.exe" /startup

O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [steam] "c:\programfiler\steam\steam.exe" -silent

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Programfiler\Creative\Sync Manager Unicode\CTSyncU.exe"

O4 - HKCU\..\Run: [Dqdwve] C:\Programfiler\??stem32\d?xplore.exe

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: GameSpot Download Manager.lnk = C:\Documents and Settings\Eier\Skrivebord\GameSpot\GameSpotDownloadManager_Win32.exe

O4 - Global Startup: Digital Line Detect.lnk = ?

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programfiler\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Logitech Desktop Messenger Agent.lnk = C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra button: HP Utklippsbok - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Programfiler\HP\Smart Web Printing\hpswp_extensions.dll

O9 - Extra button: HP Smart valgmetode - {700259D7-1666-479a-93B1-3250410481E8} - C:\Programfiler\HP\Smart Web Printing\hpswp_extensions.dll

O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll

O14 - IERESET.INF: START_PAGE_URL=http://www.online.no/

O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/SU/SU1.5/ocx/15030/CTSUEng.cab

O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by136fd.bay136.hotmail.msn.com/resources/MsnPUpld.cab

O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvlution.com/KooPlayer.ocx

O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} - http://217.197.149.13/activex/AMC.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} - http://update.videoegg.com/Install/Windows...ggPublisher.exe

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab

O16 - DPF: {C111A91F-D4EC-4D22-8D27-C3BCB0389F43} - http://195.136.36.165/activex/AMC.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - http://cam.butovonet.ru/activex/AMC.cab

O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by136fd.bay136.hotmail.msn.com/activex/HMAtchmt.ocx

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/SU/SU1.5/ocx/15033/CTPID.cab

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe

O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe

O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Programfiler\Google\Google Desktop Search\GoogleDesktop.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Programfiler\Dell\NICCONFIGSVC\NICCONFIGSVC.exe

O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

O24 - Desktop Component 1: (no name) - http://www.vg.no/

 

--

End of file - 10535 bytes

 

 

Lenke til kommentar

Åpne notisblokk og kopier inn det som står i fet skrift under, lagre fila på skrivebordet som CFScript.txt.

Dra deretter fila over Combofix-iconet. Combofix vil starte igjen.

cfscriptyt1.gif

 

File::

C:\Documents and Settings\Eier\services.exe

C:\Documents and Settings\Eier\f.exe

C:\Programfiler\Fellesfiler\Yazzle1560OinAdmin.exe

 

Registry::

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Dqdwve"=-

 

 

Last ned Malwarebytes Anti-Malware til skrivebordet.

Kjør og installer programmet. Velg Norsk-språk

La programmet oppdatere seg og velg å kjør en 'full systemskann', klikk Skann.

Det kommer en meldingsboks om at scannen er ferdig, klikk Ok

 

Klikk på Vis resultat-knappen.Hvis det er funnet malware, vil du nå se hva som er funnet.

Klikk så på Fjern valgte -knappen for å fjerne malwaren som evt. ble funnet.

 

Det vil deretter åpnes en logg i notisblokk. Den kan du kopiere og poste om den finner noe.

 

Post ny hjt-logg.

Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
  • Hvem er aktive   0 medlemmer

    • Ingen innloggede medlemmer aktive
×
×
  • Opprett ny...