Gå til innhold

hijack-log og combofix-log for smarte hjerner!


Anbefalte innlegg

Hei!

 

lurte bare på om noen kunne sjekke om loggene ser fine ut, det går treigt inniblant!

 

hijackthis log:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 23:36:19, on 15.12.2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINNT\System32\smss.exe

C:\WINNT\system32\winlogon.exe

C:\WINNT\system32\services.exe

C:\WINNT\system32\lsass.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\System32\svchost.exe

C:\WINNT\system32\ZoneLabs\vsmon.exe

C:\WINNT\Explorer.EXE

C:\WINNT\system32\ZoneLabs\avsys\ScanningProcess.exe

C:\WINNT\system32\spoolsv.exe

C:\WINNT\system32\ZoneLabs\avsys\ScanningProcess.exe

C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

C:\Programfiler\Bonjour\mDNSResponder.exe

C:\Programfiler\FolderSize\FolderSizeSvc.exe

C:\WINNT\System32\nvsvc32.exe

C:\Programfiler\Wireless 802.11g Monitor\WLService.exe

C:\WINNT\System32\svchost.exe

C:\Programfiler\Wireless 802.11g Monitor\WLanCfgG.exe

C:\PROGRA~1\Grisoft\AVG7\avgcc.exe

C:\Programfiler\Zone Labs\ZoneAlarm\zlclient.exe

C:\Programfiler\TuneUp Utilities 2007\MemOptimizer.exe

C:\Programfiler\Last.fm\LastFMHelper.exe

C:\Programfiler\MSN Messenger\usnsvc.exe

C:\WINNT\system32\LVComsX.exe

C:\Programfiler\LogMeIn\x86\LogMeIn.exe

C:\Programfiler\LogMeIn\x86\RaMaint.exe

C:\WINNT\system32\ntvdm.exe

C:\Programfiler\Valve\Steam\Steam.exe

C:\Programfiler\Opera\Opera.exe

C:\Programfiler\MediaMonkey3\MediaMonkey.exe

C:\Programfiler\Last.fm\LastFM.exe

C:\Programfiler\MSN Messenger\msnmsgr.exe

C:\Programfiler\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.vg.no/

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_01\bin\ssv.dll

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP

O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programfiler\Zone Labs\ZoneAlarm\zlclient.exe"

O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Programfiler\LogMeIn\x86\LogMeInSystray.exe"

O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Programfiler\TuneUp Utilities 2007\MemOptimizer.exe" autostart

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'NETTVERKSTJENESTE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Last.fm Helper.lnk = C:\Programfiler\Last.fm\LastFMHelper.exe

O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_01\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_01\bin\ssv.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab

O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab

O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{C9C6329A-7B83-4F63-8703-1780698795B8}: NameServer = 10.0.0.138

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FELLES~1\Skype\SKYPE4~1.DLL

O23 - Service: Adobe LM Service - Adobe Systems - C:\Programfiler\Fellesfiler\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Programfiler\Bonjour\mDNSResponder.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programfiler\Fellesfiler\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Folder Size (FolderSize) - Brio - C:\Programfiler\FolderSize\FolderSizeSvc.exe

O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Programfiler\LogMeIn\x86\RaMaint.exe

O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Programfiler\LogMeIn\x86\LogMeIn.exe

O23 - Service: ASUS Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe

O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINNT\system32\oodag.exe

O23 - Service: R54G Wireless Service - Unknown owner - C:\Programfiler\Wireless 802.11g Monitor\WLService.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Programfiler\Windows Live\installer\WLSetupSvc.exe (file missing)

 

--

End of file - 6176 bytes

 

 

Combofix log:

 

ComboFix 07-12-15.5 - Wenche 2007-12-15 23:41:23.2 - NTFSx86

Running from: C:\Documents and Settings\Wenche\Programdata\Opera\Opera\profile\cache4\temporary_download\ComboFix.exe

* Created a new restore point

.

 

((((((((((((((((((((((((( Files Created from 2007-11-15 to 2007-12-15 )))))))))))))))))))))))))))))))

.

 

2007-12-15 23:35 . 2007-12-15 23:35 <DIR> d-------- C:\Programfiler\Trend Micro

2007-12-15 23:35 . 2007-12-15 23:35 <DIR> dr-h----- C:\Documents and Settings\Wenche\Siste

2007-12-15 00:35 . 2007-12-15 00:35 <DIR> d-------- C:\Programfiler\directx

2007-12-15 00:33 . 2007-12-15 00:33 <DIR> d-------- C:\Programfiler\Rage Software

2007-12-15 00:01 . 2007-12-15 00:01 <DIR> d-------- C:\Programfiler\NovaLogic

2007-12-15 00:00 . 2007-12-15 00:00 <DIR> d-------- C:\Documents and Settings\Wenche\WINDOWS

2007-12-15 00:00 . 1998-10-29 16:45 306,688 --a------ C:\WINNT\IsUninst.exe

2007-12-14 20:27 . 2007-12-14 20:27 <DIR> d-------- C:\Programfiler\MagicISO

2007-11-29 11:53 . 2002-04-25 07:17 <DIR> dr------- C:\Documents and Settings\LogMeInRemoteUser\Start-meny

2007-11-29 11:53 . 2002-04-24 13:53 <DIR> d--h----- C:\Documents and Settings\LogMeInRemoteUser\Skrivere

2007-11-29 11:53 . 2002-04-25 06:44 <DIR> d-------- C:\Documents and Settings\LogMeInRemoteUser\Skrivebord

2007-11-29 11:53 . 2002-04-24 13:04 <DIR> dr-h----- C:\Documents and Settings\LogMeInRemoteUser\Siste

2007-11-29 11:53 . 2002-04-24 13:04 <DIR> dr-h----- C:\Documents and Settings\LogMeInRemoteUser\Programdata

2007-11-29 11:53 . 2002-04-24 13:04 <DIR> dr------- C:\Documents and Settings\LogMeInRemoteUser\Mine dokumenter

2007-11-29 11:53 . 2002-04-24 12:57 <DIR> d--h----- C:\Documents and Settings\LogMeInRemoteUser\Maler

2007-11-29 11:53 . 2002-04-24 13:53 <DIR> d--h----- C:\Documents and Settings\LogMeInRemoteUser\Lokale innstillinger

2007-11-29 11:53 . 2002-04-24 13:04 <DIR> dr------- C:\Documents and Settings\LogMeInRemoteUser\Favoritter

2007-11-29 11:53 . 2002-04-24 13:53 <DIR> d--h----- C:\Documents and Settings\LogMeInRemoteUser\AndrMask

2007-11-29 11:47 . 2007-11-29 11:47 <DIR> d-------- C:\WINNT\LastGood

2007-11-29 11:47 . 2007-11-15 18:46 83,288 --a------ C:\WINNT\system32\LMIRfsClientNP.dll

2007-11-29 11:47 . 2007-08-03 15:09 46,112 --a------ C:\WINNT\system32\drivers\LMIRfsDriver.sys

2007-11-29 11:47 . 2007-11-15 18:46 21,496 --a------ C:\WINNT\system32\LMIport.dll

2007-11-29 11:46 . 2007-12-15 11:47 <DIR> d-------- C:\Programfiler\LogMeIn

2007-11-29 11:46 . 2007-11-15 18:46 87,352 --a------ C:\WINNT\system32\LMIinit.dll

2007-11-29 11:46 . 2007-11-29 11:46 1,024 --a------ C:\.rnd

2007-11-28 17:59 . 2007-11-28 17:59 <DIR> d-------- C:\Documents and Settings\Wenche\temp

2007-11-28 17:59 . 2007-11-28 18:03 <DIR> d-------- C:\Documents and Settings\Wenche\Programdata\TeamViewer

2007-11-15 18:46 . 2007-11-15 18:46 23,736 --a------ C:\WINNT\system32\lmimirr.dll

2007-11-15 18:46 . 2007-11-15 18:46 10,040 --a------ C:\WINNT\system32\lmimirr2.dll

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2007-12-15 22:48 302,880 --sha-w C:\WINNT\system32\drivers\fidbox2.dat

2007-12-15 22:48 12,619,296 --sha-w C:\WINNT\system32\drivers\fidbox.dat

2007-12-15 17:02 --------- d-----w C:\Documents and Settings\Wenche\Programdata\uTorrent

2007-12-14 23:33 --------- d--h--w C:\Programfiler\InstallShield Installation Information

2007-12-11 10:32 512 ----a-w C:\ScanSectorLog.dat

2007-11-29 10:29 --------- d-----w C:\Programfiler\EA GAMES

2007-11-29 10:25 --------- d-----w C:\Programfiler\PowerISO

2007-11-29 10:24 --------- d-----w C:\Programfiler\Uniblue

2007-11-29 10:24 --------- d-----w C:\Documents and Settings\Wenche\Programdata\Uniblue

2007-11-16 19:17 14,660 --sha-w C:\WINNT\system32\drivers\fidbox2.idx

2007-11-16 19:17 116,252 --sha-w C:\WINNT\system32\drivers\fidbox.idx

2007-11-01 18:33 --------- d-----w C:\Programfiler\MSECache

2007-11-01 18:23 --------- d-----w C:\Documents and Settings\Wenche\Programdata\AVG7

2007-10-22 20:18 --------- d-----w C:\Programfiler\Opera

2007-10-15 13:32 5,031,997 ----a-w C:\WINNT\Internet Logs\tvDebug.zip

2007-10-02 05:49 142,898 ----a-w C:\WINNT\Internet Logs\vsmon_2nd_2007_10_02_02_07_17_small.dmp.zip

2007-09-19 18:18 17,665,976 ----a-w C:\WINNT\Internet Logs\vsmon_on_demand_2007_09_17_22_33_21_full.dmp.zip

2007-09-19 18:18 137,000 ----a-w C:\WINNT\Internet Logs\vsmon_2nd_2007_09_17_22_32_28_small.dmp.zip

2007-09-19 18:18 130,994 ----a-w C:\WINNT\Internet Logs\vsmon_2nd_2007_09_17_22_48_25_small.dmp.zip

2007-09-11 04:55 17,575,145 ----a-w C:\WINNT\Internet Logs\vsmon_on_demand_2007_09_11_01_38_16_full.dmp.zip

2007-09-11 04:55 139,511 ----a-w C:\WINNT\Internet Logs\vsmon_2nd_2007_09_11_01_32_52_small.dmp.zip

2007-07-12 18:39 22,056 ----a-w C:\Documents and Settings\Wenche\Programdata\GDIPFONTCACHEV1.DAT

2007-07-05 15:30 72,947 ----a-w C:\WINNT\Internet Logs\zlclient_2nd_2007_07_04_16_10_21_small.dmp.zip

2007-07-05 15:30 70,876 ----a-w C:\WINNT\Internet Logs\zlclient_2nd_2007_07_04_16_10_17_small.dmp.zip

2007-06-01 05:44 17,230,396 ----a-w C:\WINNT\Internet Logs\vsmon_on_demand_2007_05_31_23_47_45_full.dmp.zip

2007-06-01 05:43 151,082 ----a-w C:\WINNT\Internet Logs\vsmon_2nd_2007_05_31_23_41_43_small.dmp.zip

2007-04-05 11:38 76,880 ----a-w C:\Documents and Settings\Wenche\Autorun.exe

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"TuneUp MemOptimizer"="C:\Programfiler\TuneUp Utilities 2007\MemOptimizer.exe" [2007-04-26 20:50]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"nwiz"="nwiz.exe" [2002-01-15 16:06 C:\WINNT\system32\nwiz.exe]

"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-05-09 18:37]

"ZoneAlarm Client"="C:\Programfiler\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]

"LogMeIn GUI"="C:\Programfiler\LogMeIn\x86\LogMeInSystray.exe" [2007-08-03 15:09]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINNT\System32\CTFMON.EXE" [2004-08-04 09:03]

"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-05-09 18:37]

 

C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\

Last.fm Helper.lnk - C:\Programfiler\Last.fm\LastFMHelper.exe [2007-08-07 20:03:29]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"GreyMSIAds"= 1 (0x1)

"NoTrayItemsDisplay"= 0 (0x0)

"NoRecentDocsMenu"= 01000000

"NoRecentDocsNetHood"= 01000000

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]

LMIinit.dll 2007-11-15 18:46 87352 C:\WINNT\system32\LMIinit.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Adobe Reader Speed Launch.lnk]

backup=C:\WINNT\pss\Adobe Reader Speed Launch.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Adobe Reader Synchronizer.lnk]

backup=C:\WINNT\pss\Adobe Reader Synchronizer.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Microsoft Office.lnk]

backup=C:\WINNT\pss\Microsoft Office.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Wenche^Start-meny^Programmer^Oppstart^Adobe Gamma.lnk]

backup=C:\WINNT\pss\Adobe Gamma.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Wenche^Start-meny^Programmer^Oppstart^Stardock ObjectDock.lnk]

backup=C:\WINNT\pss\Stardock ObjectDock.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]

2007-03-01 09:37 2321600 -ra------ C:\Programfiler\Fellesfiler\Adobe\Updater5\AdobeUpdater.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InfoMyCa.exe]

2004-06-14 15:16 45056 --a------ C:\Programfiler\Wireless 802.11g Monitor\InfoMyCa.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]

C:\Programfiler\Logitech\Video\ManifestEngine.exe boot

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]

2005-06-08 14:24 458752 --a------ C:\Programfiler\Logitech\Video\ISStart.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]

2005-06-08 14:14 217088 --a------ C:\Programfiler\Logitech\Video\LogiTray.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]

2005-07-19 16:32 221184 --a------ C:\WINNT\system32\LVCOMSX.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

"anvshell"=anvshell.exe

"NvCplDaemon"=RUNDLL32.EXE NvQTwk,NvCplDaemon initialize

 

R0 DiMaint;Eicon Maintenance Driver;C:\WINNT\system32\DRIVERS\DISDN\dimaint.sys

R1 ANVIOCTL;ANVIOCTL;C:\WINNT\system32\DRIVERS\anvioctl.sys

R2 DiCapi;Eicon CAPI 2.0 Driver;C:\WINNT\system32\DRIVERS\DISDN\capi202k.sys

R2 DiPort;Eicon Port Driver;C:\WINNT\system32\DRIVERS\DISDN\diport40.sys

R2 LMIInfo;LogMeIn Kernel Information Provider;\??\C:\Programfiler\LogMeIn\x86\RaInfo.sys

R2 LMIRfsDriver;LogMeIn Remote File System Driver;\??\C:\WINNT\system32\drivers\LMIRfsDriver.sys

R2 R54G Wireless Service;R54G Wireless Service;C:\Programfiler\Wireless 802.11g Monitor\WLService.exe

R2 UxTuneUp;TuneUp Theme Extension;C:\WINNT\System32\svchost.exe -k netsvcs

R3 DiWan;Eicon Driver for all Diva Client cards;C:\WINNT\system32\DRIVERS\DISDN\Diwan.sys

R3 lmimirr;lmimirr;C:\WINNT\system32\DRIVERS\lmimirr.sys

R3 rt2571;Wireless 802.11g USB Adapter Driver;C:\WINNT\system32\DRIVERS\rt2571.sys

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

UxTuneUp

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8ce92fbc-fe4b-11db-8aef-806d6172696f}]

\Shell\AutoRun\command - E:\start.exe

 

*Newly Created Service* - GTNDIS5

*Newly Created Service* - LMIINFO

*Newly Created Service* - LMIMAINT

*Newly Created Service* - LMIRFSCLIENTNP

*Newly Created Service* - LMIRFSDRIVER

*Newly Created Service* - LOGMEIN

.

Contents of the 'Scheduled Tasks' folder

"2007-06-22 15:16:12 C:\WINNT\Tasks\1-Click Maintenance.job"

- C:\Programfiler\TuneUp Utilities 2007\SystemOptimizer.exe

"2007-06-25 16:07:07 C:\WINNT\Tasks\Uniblue SpeedUpMyPC Nag.job"

- C:\Programfiler\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe

"2007-06-25 16:07:07 C:\WINNT\Tasks\Uniblue SpeedUpMyPC.job"

- C:\Programfiler\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe

.

**************************************************************************

 

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2007-12-15 23:49:20

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

**************************************************************************

.

Completion time: 2007-12-15 23:53:42

.

2007-08-29 10:12:02 --- E O F ---

 

 

Lenke til kommentar
Videoannonse
Annonse

Klikk for å se/fjerne innholdet nedenfor
Service load: 0% 100%

 

File: lmimirr.dll

Status: OK

MD5: 6990f36a0ef47dc5350560edcf03a268

Packers detected: -

Bit9 reports: File not found

 

Scanner results

Scan taken on 15 Dec 2007 23:52:22 (GMT)

A-Squared Found nothing

AntiVir Found nothing

ArcaVir Found nothing

Avast Found nothing

AVG Antivirus Found nothing

BitDefender Found nothing

ClamAV Found nothing

CPsecure Found nothing

Dr.Web Found nothing

F-Prot Antivirus Found nothing

F-Secure Anti-Virus Found nothing

Fortinet Found nothing

Ikarus Found nothing

Kaspersky Anti-Virus Found nothing

NOD32 Found nothing

Norman Virus Control Found nothing

Panda Antivirus Found nothing

Rising Antivirus Found nothing

Sophos Antivirus Found nothing

VirusBuster Found nothing

VBA32 Found nothing

Endret av cHilfiger
Lenke til kommentar

Kanskje en generell opprydding kan hjelpe litt:

 

1. Last ned CCleaner. Start programmet. Gå til 'Valg'->'Avansert'. Fjern avkryssingen framfor: "bare slett midlertidige filer......." Klikk på 'Renser' og deretter 'Kjør CCleaner'.

 

2. Kjør en diskdefragmentering. (Tilbehør->systemverktøy->diskdefragmentering)

Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
  • Hvem er aktive   0 medlemmer

    • Ingen innloggede medlemmer aktive
×
×
  • Opprett ny...