Gå til innhold

Har også fått MSN viruset.


Anbefalte innlegg

Videoannonse
Annonse

Nå har tanta mi vært på msn på nytt.

 

Ny HJT-log:

 

 

Logfile of HijackThis v1.99.1

Scan saved at 18:02:33, on 20.01.2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\Programfiler\NETGEAR\WG311v3\WinDomainlogon.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Programfiler\NETGEAR\WG311v3\WinDomainlogon.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Programfiler\internet explorer\iexplore.exe

C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe

C:\PROGRA~1\Grisoft\AVG7\avgcc.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\Spybot - Search & Destroy\TeaTimer.exe

C:\Programfiler\NETGEAR\WG311v3\wlancfg5.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\msiexec.exe

C:\Documents and Settings\Eli\Skrivebord\hijackthis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startsiden.no/

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

O2 - BHO: Koblingshjelpeprogram for Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Programfiler\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [AdobeUpdater] C:\Programfiler\Fellesfiler\Adobe\Updater5\AdobeUpdater.exe

O4 - Global Startup: NETGEAR WG311v3 Smart Wizard.lnk = ?

O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {A903E5AB-C67E-40FB-94F1-E1305982F6E0} (KooPlayer Control) - http://www.euchannels.net/UKooPlayer.ocx

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Programfiler\Fellesfiler\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FELLES~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

 

 

 

Lenke til kommentar

Legger ved min textfil ifra Combofix,hvordan ser det ut?

 

 

 

* Created a new restore point

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\Documents and Settings\Paddington\Application Data\inst.exe

 

.

((((((((((((((((((((((((( Files Created from 2007-12-20 to 2008-01-20 )))))))))))))))))))))))))))))))

.

 

2008-01-20 18:17 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe

2008-01-20 17:46 . 2008-01-20 17:46 <DIR> d-------- C:\Program Files\Abexo

2008-01-20 15:59 . 2008-01-20 16:01 <DIR> d-------- C:\Documents and Settings\Paddington\.housecall6.6

2008-01-20 12:28 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe

2008-01-20 12:28 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe

2008-01-20 12:28 . 2007-12-20 23:11 81,920 --a------ C:\WINDOWS\system32\IEDFix.exe

2008-01-20 12:28 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe

2008-01-20 12:28 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe

2008-01-20 12:28 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe

2008-01-20 12:16 . 2008-01-20 12:34 1,454 --a------ C:\WINDOWS\system32\tmp.reg

2008-01-20 11:00 . 2008-01-20 11:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft

2008-01-20 10:15 . 2008-01-20 10:19 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP

2008-01-19 21:57 . 2008-01-19 21:57 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com

2008-01-19 21:55 . 2007-12-31 12:21 211 --ah----- C:\boot.ini.SAB

2008-01-19 13:01 . 2008-01-19 13:01 <DIR> d-------- C:\Program Files\XRECODE

2008-01-15 22:36 . 2007-12-05 03:48 9,535,488 --a------ C:\WINDOWS\system32\atioglx2.dll

2008-01-15 22:36 . 2007-12-05 03:33 3,107,788 --a------ C:\WINDOWS\system32\ativva5x.dat

2008-01-15 22:36 . 2007-12-05 03:33 887,724 --a------ C:\WINDOWS\system32\ativva6x.dat

2008-01-15 22:36 . 2008-01-15 22:36 472,576 --a------ C:\WINDOWS\Radeon Omega Drivers v4.8.442 Uninstall.exe

2008-01-15 22:36 . 2007-12-05 04:05 368,640 --a------ C:\WINDOWS\system32\ATIDEMGX.dll

2008-01-15 22:36 . 2007-12-05 03:14 180,224 --a------ C:\WINDOWS\system32\atiok3x2.dll

2008-01-15 22:36 . 2007-11-28 22:50 11,717 --a------ C:\WINDOWS\atiogl.xml

2008-01-06 00:44 . 2008-01-06 00:44 <DIR> d-------- C:\WINDOWS\Easy CD-DA Extractor 11.0.3

2007-12-30 14:08 . 2007-12-30 14:08 <DIR> d-------- C:\Program Files\HD Tune

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-01-20 14:59 102,664 ----a-w C:\WINDOWS\system32\drivers\tmcomm.sys

2008-01-20 14:51 --------- d-----w C:\Program Files\SUPERAntiSpyware

2008-01-20 14:51 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard

2008-01-20 14:51 --------- d-----w C:\Documents and Settings\Paddington\Application Data\SUPERAntiSpyware.com

2008-01-20 14:50 --------- d-----w C:\Program Files\Common Files\Ahead

2008-01-20 14:50 --------- d-----w C:\Program Files\Ahead

2008-01-20 14:48 --------- d-----w C:\Program Files\FileZilla

2008-01-20 11:39 --------- d-----w C:\Program Files\SpywareBlaster

2008-01-20 09:45 --------- d-----w C:\Program Files\Lavasoft

2008-01-19 11:40 --------- d-----w C:\Documents and Settings\Paddington\Application Data\uTorrent

2008-01-17 21:14 --------- d-----w C:\Documents and Settings\Paddington\Application Data\Vso

2008-01-17 19:00 --------- d-----w C:\Documents and Settings\Paddington\Application Data\dvdcss

2008-01-15 21:37 --------- d-----w C:\Program Files\MultiRes

2008-01-15 21:36 --------- d-----w C:\Program Files\Radeon Omega Drivers

2008-01-06 11:39 --------- d-----w C:\Program Files\Easy CD-DA Extractor 11

2008-01-05 23:18 --------- d-----w C:\Program Files\FLAC

2007-12-24 11:45 --------- d-----w C:\Program Files\Winamp

2007-12-14 10:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe

2007-12-08 13:58 --------- d-----w C:\Program Files\MSBuild

2007-12-08 13:55 --------- d-----w C:\Program Files\Reference Assemblies

2007-12-08 12:39 --------- d-----w C:\Program Files\Common Files\Adobe

2007-12-05 05:26 2,782,208 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys

2007-12-05 03:04 269,312 ----a-w C:\WINDOWS\system32\ati2dvag.dll

2007-12-05 02:56 147,456 ----a-w C:\WINDOWS\system32\atipdlxx.dll

2007-12-05 02:55 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll

2007-12-05 02:55 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe

2007-12-05 02:55 122,880 ----a-w C:\WINDOWS\system32\Oemdspif.dll

2007-12-05 02:55 122,880 ----a-w C:\WINDOWS\system32\ati2evxx.dll

2007-12-05 02:53 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL

2007-12-05 02:53 495,616 ----a-w C:\WINDOWS\system32\ati2evxx.exe

2007-12-05 02:33 1,640,192 ----a-w C:\WINDOWS\system32\ativvaxx.dll

2007-12-05 02:19 5,435,392 ----a-w C:\WINDOWS\system32\atioglxx.dll

2007-12-05 02:19 385,024 ----a-w C:\WINDOWS\system32\atikvmag.dll

2007-12-05 02:17 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll

2007-12-05 02:16 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll

2007-12-05 02:11 499,712 ----a-w C:\WINDOWS\system32\ati2cqag.dll

2007-12-02 15:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Test Drive Unlimited

2007-12-01 13:31 --------- d-----w C:\Documents and Settings\Paddington\Application Data\Winamp

2007-11-25 12:01 --------- d-----w C:\Program Files\SystemRequirementsLab

2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll

2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll

2007-10-27 16:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll

2007-10-24 15:05 47,360 ----a-w C:\Documents and Settings\Paddington\Application Data\pcouffin.sys

2007-10-24 00:47 96,760 ----a-w C:\WINDOWS\system32\dfshim.dll

2007-10-24 00:47 84,480 ----a-w C:\WINDOWS\system32\mscories.dll

2007-10-24 00:47 282,112 ----a-w C:\WINDOWS\system32\mscoree.dll

2007-10-24 00:47 158,720 ----a-w C:\WINDOWS\system32\mscorier.dll

2006-01-22 08:46 245,760 ----a-w C:\Program Files\keriokey.exe

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Ptipbmf"="ptipbmf.dll" [2003-06-20 08:06 118784 C:\WINDOWS\system32\ptipbmf.dll]

"PtiuPbmd"="ptipbm.dll" [2003-01-15 12:41 24576 C:\WINDOWS\system32\ptipbm.dll]

"JulaPan"="JulaPan.Exe" [2006-09-05 10:08 417792 C:\WINDOWS\system32\JulaPan.exe]

"AtiPTA"="atiptaxx.exe" [2006-02-22 02:05 344064 C:\WINDOWS\system32\atiptaxx.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-03 23:56 15360]

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]

backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Hurtigstart for Adobe Reader.lnk]

backup=C:\WINDOWS\pss\Hurtigstart for Adobe Reader.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]

backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Phone Connection Monitor.lnk]

backup=C:\WINDOWS\pss\Phone Connection Monitor.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

--a------ 2007-10-10 19:51 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AtiTrayTools]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]

--------- 2004-08-03 23:56 110592 C:\WINDOWS\system32\bthprops.cpl

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]

--a------ 2006-11-12 11:48 157592 C:\Program Files\DAEMON Tools\daemon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EnvyHFCPL]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]

--a--c--- 2005-02-16 15:15 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]

C:\WINDOWS\system32\dumprep 0 -k

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]

--a------ 2004-09-15 09:12 37888 C:\WINDOWS\KHALMNPR.Exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]

--a------ 2007-01-19 11:54 5674352 C:\Program Files\MSN Messenger\MsnMsgr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe]

--a--c--- 2003-03-11 15:24 86016 C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

--a--c--- 2006-10-12 03:10 49263 C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"aawservice"=2 (0x2)

"AVG Anti-Spyware Guard"=2 (0x2)

 

R1 atitray;atitray;C:\Program Files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys [2007-11-05 08:55]

R3 JULA_01;Service for Juli@ 1;C:\WINDOWS\system32\drivers\JulaWdm.sys [2006-09-05 10:08]

R3 JULA_AA;Service for Juli@ Audio Driver (EWDM);C:\WINDOWS\system32\drivers\Jula.sys [2006-09-05 10:08]

 

*Newly Created Service* - PROCEXP90

.

**************************************************************************

 

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-01-20 18:19:12

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2008-01-20 18:19:34

ComboFix-quarantined-files.txt 2008-01-20 17:19:32

 

mvh

Lenke til kommentar
Nå har tanta mi vært på msn på nytt.

 

Ny HJT-log:

 

 

Logfile of HijackThis v1.99.1

Scan saved at 18:02:33, on 20.01.2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\Programfiler\NETGEAR\WG311v3\WinDomainlogon.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Programfiler\NETGEAR\WG311v3\WinDomainlogon.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Programfiler\internet explorer\iexplore.exe

C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe

C:\PROGRA~1\Grisoft\AVG7\avgcc.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\Spybot - Search & Destroy\TeaTimer.exe

C:\Programfiler\NETGEAR\WG311v3\wlancfg5.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\msiexec.exe

C:\Documents and Settings\Eli\Skrivebord\hijackthis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startsiden.no/

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

O2 - BHO: Koblingshjelpeprogram for Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Programfiler\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [AdobeUpdater] C:\Programfiler\Fellesfiler\Adobe\Updater5\AdobeUpdater.exe

O4 - Global Startup: NETGEAR WG311v3 Smart Wizard.lnk = ?

O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {A903E5AB-C67E-40FB-94F1-E1305982F6E0} (KooPlayer Control) - http://www.euchannels.net/UKooPlayer.ocx

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Programfiler\Fellesfiler\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FELLES~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

 

 

 

Loggen viser ingen spesielle ting. Fortsatt MSN-problemer?

 

 

Clutch:

Loggen ser grei ut. Er det noe som tyder på at du har noe rusk?

Lenke til kommentar
Nå har tanta mi vært på msn på nytt.

 

Loggen viser ingen spesielle ting. Fortsatt MSN-problemer?

 

 

Hu trykte på en link. Denne gangen stod det en norsk teks med linken. Da trodde hun at det ikke var tull.

 

Men jeg tok systemgjenoppretting på pc-en hennes. Tror det funka :thumbup:

Endret av JFM
Lenke til kommentar
Clutch:

Loggen ser grei ut. Er det noe som tyder på at du har noe rusk?

 

 

 

 

Jeg hadde nemlig dette msn-viruset,drev å rotet fælt med å fjerne det. Ville egentlig bare ha en bekreftelse på at det ikke fantes mere rusk innpå maskina mi. Fikk litt noia av å holde på å fjerne "Fxxxskapet",da jeg ikke hadde noen erfaring med dette.XP-skiva lå klar til å puttes inn i pc`n for å si det sånn,men alltid hyggelig å få fikset ting selv.

Takk for tilbakemeldingen.

 

mvh

Lenke til kommentar

Kan noen av dere hjelpe meg også?

Har fått MSN-viruset, og tror ikke jeg har fått slettet det. Vil noen sjekke loggen?

 

ComboFix 08-01-20.1 - Sunniva M. Hustoft 2008-01-21 18:58:30.2 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.431 [GMT 1:00]

Running from: C:\Documents and Settings\Sunniva M. Hustoft\Skrivebord\ComboFix.exe

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\Documents and Settings\Sunniva M. Hustoft\Programdata\macromedia\Flash Player\#SharedObjects\2WLSY6KQ\www.broadcaster.com

C:\Documents and Settings\Sunniva M. Hustoft\Programdata\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com

C:\Documents and Settings\Sunniva M. Hustoft\Programdata\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol

C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy .exe

C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

C:\Program Files\Google\Google Desktop Search\GoogleDesktop .exe

C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Hewlett-Packard\Default Settings\cpqset .exe

C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe

C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe

C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe

C:\Program Files\HP\QuickPlay\QPService .exe

C:\Program Files\HP\QuickPlay\QPService.exe

C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant .exe

C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe

C:\Program Files\iTunes\iTunesHelper .exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe

C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

C:\Program Files\QuickTime\qttask .exe

C:\Program Files\QuickTime\QTTask .exe

C:\Program Files\QuickTime\QTTask .exe

C:\Program Files\QuickTime\QTTask.exe

C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher .exe

C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh .exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe

C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe

C:\Program Files\Windows Media Player\WMPNSCFG .exe

C:\Program Files\Windows Media Player\WMPNSCFG.exe

C:\Program Files\Windows Plus\Dancer\Dancer .exe

C:\Program Files\Windows Plus\Dancer\Dancer.exe

C:\WINDOWS\CREATOR\Remind_XP .exe

C:\WINDOWS\CREATOR\Remind_XP.exe

C:\WINDOWS\ehome\ehtray .exe

C:\WINDOWS\ehome\ehtray.exe

C:\WINDOWS\SMINST\RecGuard .exe

C:\WINDOWS\SMINST\RecGuard.exe

C:\WINDOWS\svchost.exe

C:\WINDOWS\system32\_000003_.tmp.dll

C:\WINDOWS\system32\_000005_.tmp.dll

C:\WINDOWS\system32\_000008_.tmp.dll

C:\WINDOWS\system32\efcyaax.dll

C:\WINDOWS\system32\fgjlm.ini

C:\WINDOWS\system32\fgjlm.ini2

C:\WINDOWS\system32\gebxvuv.dll

C:\WINDOWS\system32\mcrh.tmp

C:\WINDOWS\system32\mljgf.dll

C:\WINDOWS\system32\mljgf.exe

C:\WINDOWS\system32\vturoop.dll

C:\WINDOWS\system32\vtutqrs.dll

D:\Autorun.inf

 

 <pre>
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy .exe ---> QooBox
C:\Program Files\Google\Google Desktop Search\GoogleDesktop .exe ---> QooBox
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe ---> QooBox
C:\Program Files\Hewlett-Packard\Default Settings\cpqset .exe ---> QooBox
C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe ---> QooBox
C:\Program Files\HP\QuickPlay\QPService .exe ---> QooBox
C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant .exe ---> QooBox
C:\Program Files\iTunes\iTunesHelper .exe ---> QooBox
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe ---> QooBox
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher .exe ---> QooBox
C:\Program Files\Synaptics\SynTP\SynTPEnh .exe ---> QooBox
C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe ---> MsnMsgr.Exe
C:\Program Files\Windows Media Player\WMPNSCFG .exe ---> QooBox
C:\Program Files\Windows Plus\Dancer\Dancer .exe ---> QooBox
C:\WINDOWS\CREATOR\Remind_XP .exe ---> QooBox
C:\WINDOWS\ehome\ehtray .exe ---> QooBox
C:\WINDOWS\SMINST\RecGuard .exe ---> QooBox
</pre>

.

.

((((((((((((((((((((((((( Files Created from 2007-12-21 to 2008-01-21 )))))))))))))))))))))))))))))))

.

 

2008-01-21 18:54 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe

2008-01-19 21:24 . 2008-01-21 18:45 54,156 --ah----- C:\WINDOWS\QTFont.qfn

2008-01-19 21:24 . 2008-01-19 21:24 1,409 --a------ C:\WINDOWS\QTFont.for

2008-01-19 21:23 . 2008-01-19 21:23 <DIR> d-------- C:\Program Files\iPod

2008-01-19 18:26 . 2007-08-01 16:47 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys

2008-01-19 18:25 . 2008-01-20 11:25 <DIR> d-------- C:\Documents and Settings\Sunniva M. Hustoft\Programdata\HouseCall 6.6

2008-01-18 16:36 . 2008-01-18 16:42 <DIR> d-------- C:\Documents and Settings\Sunniva M. Hustoft\Programdata\Windows Live Writer

2008-01-18 16:31 . 2008-01-18 16:35 <DIR> d-------- C:\Program Files\MediaMonkey

2008-01-12 18:20 . 2008-01-12 18:20 <DIR> d-------- C:\Documents and Settings\Sunniva M. Hustoft\Programdata\Symantec

2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx

2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts

2008-01-05 15:20 . 2008-01-05 15:20 <DIR> d--hs---- C:\Documents and Settings\LocalService\Temporary Internet Files

2008-01-05 15:20 . 2008-01-05 15:20 <DIR> d--hs---- C:\Documents and Settings\LocalService\Logg

2008-01-05 15:02 . 2008-01-05 15:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7

2008-01-05 14:46 . 2008-01-05 14:59 <DIR> d-------- C:\Program Files\Norton 360

2008-01-05 14:31 . 2008-01-05 14:31 <DIR> d-------- C:\Documents and Settings\All Users\Symantec Temporary Files

2008-01-05 13:27 . 2007-02-08 12:56 90,800 -ra------ C:\WINDOWS\system32\drivers\sea1unic.sys

2008-01-05 13:27 . 2007-02-08 12:56 88,624 -ra------ C:\WINDOWS\system32\drivers\sea1mgmt.sys

2008-01-05 13:27 . 2007-02-08 12:56 86,432 -ra------ C:\WINDOWS\system32\drivers\sea1obex.sys

2008-01-05 13:27 . 2007-02-08 12:56 18,704 -ra------ C:\WINDOWS\system32\drivers\sea1nd5.sys

2008-01-05 13:27 . 2007-02-08 12:55 4,128 -ra------ C:\WINDOWS\system32\drivers\sea1cr.sys

2008-01-05 13:26 . 2007-02-08 12:55 97,088 -ra------ C:\WINDOWS\system32\drivers\sea1mdm.sys

2008-01-05 13:26 . 2007-02-08 12:55 9,360 -ra------ C:\WINDOWS\system32\drivers\sea1mdfl.sys

2008-01-05 13:26 . 2007-02-08 12:55 6,240 -ra------ C:\WINDOWS\system32\drivers\sea1cmnt.sys

2008-01-05 13:26 . 2007-02-08 12:55 6,240 -ra------ C:\WINDOWS\system32\drivers\sea1cm.sys

2008-01-05 12:59 . 2008-01-05 12:59 <DIR> d-------- C:\Program Files\Disc2Phone

2008-01-05 12:45 . 2007-02-08 12:55 61,536 -ra------ C:\WINDOWS\system32\drivers\sea1bus.sys

2008-01-05 12:45 . 2007-02-08 12:56 5,872 -ra------ C:\WINDOWS\system32\drivers\sea1whnt.sys

2008-01-05 12:45 . 2007-02-08 12:56 5,872 -ra------ C:\WINDOWS\system32\drivers\sea1wh.sys

2008-01-05 12:43 . 2008-01-05 12:43 <DIR> d-------- C:\Documents and Settings\Sunniva M. Hustoft\Programdata\Teleca

2008-01-05 12:40 . 2008-01-05 12:40 <DIR> d-------- C:\Documents and Settings\Sunniva M. Hustoft\Programdata\Sony Ericsson

2008-01-05 12:36 . 2008-01-05 12:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Sony Ericsson

2008-01-05 12:35 . 2008-01-05 12:35 <DIR> d-------- C:\Program Files\Sony Ericsson

2008-01-05 12:35 . 2008-01-05 12:36 <DIR> d-------- C:\Program Files\Common Files\Teleca Shared

2008-01-05 12:35 . 2008-01-05 12:36 <DIR> d-------- C:\Program Files\Common Files\Sony Ericsson Shared

2008-01-05 12:35 . 2008-01-05 12:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Teleca

2008-01-05 12:34 . 2008-01-05 12:34 <DIR> d-------- C:\WINDOWS\Downloaded Installations

2008-01-05 12:28 . 2008-01-05 12:28 <DIR> d-------- C:\Documents and Settings\Sunniva M. Hustoft\Programdata\AdobeAUM

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-01-21 18:00 --------- d-----w C:\Program Files\QuickTime

2008-01-21 18:00 --------- d-----w C:\Program Files\iTunes

2008-01-21 17:46 --------- d-----w C:\Program Files\Common Files\Symantec Shared

2008-01-21 17:46 --------- d-----w C:\Documents and Settings\Sunniva M. Hustoft\Programdata\OpenOffice.org2

2008-01-19 21:07 --------- d-----w C:\Program Files\Windows Live

2008-01-05 14:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec

2008-01-05 13:49 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF

2008-01-05 13:49 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS

2008-01-05 13:49 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT

2008-01-05 13:49 --------- d-----w C:\Program Files\Symantec

2007-12-26 10:50 --------- d-----w C:\Program Files\Norton Internet Security

2007-12-13 13:27 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition

2007-12-13 13:22 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller

2007-12-13 13:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller

2007-12-12 19:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help

2007-12-06 14:02 --------- d-----w C:\Documents and Settings\Sunniva M. Hustoft\Programdata\CyberLink

2007-12-02 17:20 510 ----a-w C:\Documents and Settings\Sunniva M. Hustoft\Programdata\wklnhst.dat

2007-11-24 10:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer

2007-11-24 10:03 --------- d-----w C:\Program Files\Apple Software Update

2007-11-24 10:02 --------- d-----w C:\Program Files\Common Files\Apple

2007-11-24 10:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple

.

<pre>
----a-w		 5,724,184 2008-01-21 17:45:00  C:\Program Files\Windows Live\Messenger\MsnMsgr	.Exe
</pre>

 

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr .exe" [ ]

"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]

"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [ ]

"Expressivo"="C:\Program Files\ivo\Expressivo Demo\expressivo.exe" [ ]

"Dancer"="C:\Program Files\Windows Plus\Dancer\Dancer.exe" [ ]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [ ]

"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [ ]

"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ]

"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-09-27 17:10 7585792]

"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-09-27 17:10 86016]

"nwiz"="nwiz.exe" [2006-09-27 17:10 1617920 C:\WINDOWS\system32\nwiz.exe]

"MsmqIntCert"="regsvr32 /s mqrt.dll" []

"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-07-26 22:44 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]

"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [ ]

"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [ ]

"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [ ]

"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 10:33 163840]

"Cpqset"="C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe" [ ]

"RecGuard"="C:\Windows\SMINST\RecGuard.exe" [ ]

"Reminder"="C:\Windows\CREATOR\Remind_XP.exe" [ ]

"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 22:59 115816]

"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [ ]

"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [ ]

"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [ ]

"Windows Taskmanager"="svchost.exe" [2006-03-16 05:00 14336 C:\WINDOWS\system32\svchost.exe]

"QuickTime Task"="C:\Program Files\QuickTime\QTTask .exe" [ ]

"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [ ]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-16 05:00 15360]

"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]

 

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\

BTTray.lnk - C:\Program Files\D-Link\Bluetooth-programvare\BTTray.exe [2004-11-30 12:30:00 565309]

HP Photosmart Premier Hurtigstart.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2005-09-24 08:39:30 73728]

Hurtigstart for Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles

"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

 

R2 Automatisk LiveUpdate-planlegging;Automatisk LiveUpdate-planlegging;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-09-26 13:03]

R3 nvsmu;nvsmu;C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2006-03-06 00:49]

R3 USBAAPL;Apple Mobile USB Driver;C:\WINDOWS\system32\Drivers\usbaapl.sys [2007-10-31 14:09]

S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM);C:\WINDOWS\system32\DRIVERS\sea1bus.sys [2007-02-08 12:55]

S3 sea1mdfl;Sony Ericsson Device 0A1 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\sea1mdfl.sys [2007-02-08 12:55]

S3 sea1mdm;Sony Ericsson Device 0A1 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\sea1mdm.sys [2007-02-08 12:55]

S3 sea1mgmt;Sony Ericsson Device 0A1 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\sea1mgmt.sys [2007-02-08 12:56]

S3 sea1nd5;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (NDIS);C:\WINDOWS\system32\DRIVERS\sea1nd5.sys [2007-02-08 12:56]

S3 sea1obex;Sony Ericsson Device 0A1 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\sea1obex.sys [2007-02-08 12:56]

S3 sea1unic;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (WDM);C:\WINDOWS\system32\DRIVERS\sea1unic.sys [2007-02-08 12:56]

S4 viaagp;VIA AGP Bus Filter;C:\WINDOWS\system32\DRIVERS\viaagp.sys [2004-08-04 06:07]

 

*Newly Created Service* - COMHOST

.

Contents of the 'Scheduled Tasks' folder

"2008-01-19 19:53:30 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"

- C:\Program Files\Apple Software Update\SoftwareUpdate.exe

.

**************************************************************************

 

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-01-21 19:03:43

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2008-01-21 19:07:22 - machine was rebooted [sunniva M. Hustoft]

ComboFix-quarantined-files.txt 2008-01-21 18:07:16

.

2008-01-09 18:18:25 --- E O F ---

 

Noe som ser galt ut? Har ALDRI vært borti noe lignende. Dessuten, hva er denne XP CD-en? Jeg får opp sånn at jeg skal sette i Disc 2 av XP diskene... What am I going to do?!

Lenke til kommentar
Det hadde vært veldig kjekt om du postet en Hijackthis-logg i tillegg :)

 

Ser noen kopierte litt av signaturen min :tease:

 

Egentlig er sitatet slik:

Du får rope ut til de du kjenner at man ALDRI skal trykke på linker uten å vite om det er bevisst sendt fra avsender.
Endret av JFM
Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
  • Hvem er aktive   0 medlemmer

    • Ingen innloggede medlemmer aktive
×
×
  • Opprett ny...