Gå til innhold

[LØST]Virus: win32:agent-zfe og -zge


Anbefalte innlegg

Jeg har fjernet disse trojanske hestene fra maskinen til min bror men jeg får fremdeles ikke administrator rettigheter på alt. Datoen er f.eks. endret til "Virus alert" og Control Panel finnes ikke lenger i menyen. Jeg får ikke åpnet snarveier som Windows+E eller ctrl+alt+del.

 

Jeg har installert Avast antivirus og den finner ikke flere virus.

 

Den fjernet totalt 16 virus. En som heter win32:trojan-gen gikk igjen 6 ganger. Eller var de to som er nevnt i emne tittel, win32:vapsup-gr,-gt og -gq, win32:agent-lts, og win32:virtumonde-kh.

 

Derfor er jeg litt usikker på om jeg er kvitt alle virus og hva mitt neste steg bør være. Jeg har prøvd å logge på i sikkermodus for å se om brukeren min er administrator og det er den.

 

Jeg lurer derfor på om jeg er kvitt virusene og hvordan jeg skal rette opp de feilene som ligger igjen etter at maskinen har blitt mishandlet av virusene.

 

Tusen takk for alle mulige innspill.

Endret av perkforr
Lenke til kommentar
Videoannonse
Annonse

Var jeg deg ville jeg bare kopiert ut alle de viktige filene og så formattert disken(e) samtidig som jeg reinstallerte windows.

 

Husk å scanne filene før du kjører/aksesserer de igjen, og vent gjerne med å koble deg til nett til du har fått installert et antivirusprogram [om du ikke sitter bak en router/dedikert firewall]

 

Husk windows update også ;)

Lenke til kommentar
Hent Combofix, og legg det på skrivebordet

 

Kjør combofix.exe, og følg veiledningen.

Du må ikke klikke på vinduet mens programmet kjører.

 

Post loggfilen fra combofix (c:\combofix.txt)

 

Jeg skal gjøre det når jeg kommer hjem. Jeg syntes det bare er litt rart at dette programmet kan være så utrolig at det kan fikse alle typer virus. PC'en er jo blitt kapret nesten og da er det litt rart at den klarer å fikse dette.

 

Jeg har forresten kjørt hijack og fjernet de filene som var skadelige ifølge den automatiske sjekklisten på en eller annen nettside.

Lenke til kommentar

Combofix fjerner en hel del malware, men det er ikke noe vidunderprogram som fjerner alt - selv om at det ofte finner og fjerner en god del av 'problemet'. Det finnes noen gode antispywareprogram som er å foretrekke. Combofix lager imidlertid en logg som forteller om det ligger filer på pc'n som skal fjernes. Til det, er dette et meget godt program og det er det som gjør at vi benytter dette programmet så mye i slike saker.

Lenke til kommentar

Her er fila fra combofix. Og det utrolige er at nå får jeg tilgang til Kontrol Panel. Utrolig at jeg aldri har oppdaget dette programmet tidligere siden jeg jobber med kunder som har problemer med virus støtt og stadig.

 

Da er vel spørsmålet om alt er fikset?

 

 

 

 

ComboFix 08-07-05.1 - Familie 2008-07-07 18:19:58.1 - NTFSx86

Running from: C:\Documents and Settings\Familie\Skrivebord\ComboFix.exe

* Created a new restore point

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\Documents and Settings\Familie\Programdata\Microsoft\Internet Explorer\Quick Launch\Antivirus-2008pro.lnk

C:\WINDOWS\cookies.ini

C:\WINDOWS\Downloaded Program Files\setup.inf

C:\WINDOWS\privacy_danger

C:\WINDOWS\system32\ctfaqwlk.ini

C:\WINDOWS\system32\qssDgfii.ini

C:\WINDOWS\system32\qssDgfii.ini2

 

.

((((((((((((((((((((((((( Files Created from 2008-06-07 to 2008-07-07 )))))))))))))))))))))))))))))))

.

 

2008-07-07 18:28 . 2008-07-07 18:28 294 ---hs---- C:\WINDOWS\system32\ctfaqwlk.ini

2008-07-06 16:50 . 2008-07-06 16:50 <DIR> d-------- C:\Programfiler\Alwil Software

2008-07-06 15:41 . 2008-07-06 15:41 268 --ah----- C:\sqmdata14.sqm

2008-07-06 15:41 . 2008-07-06 15:41 244 --ah----- C:\sqmnoopt14.sqm

2008-07-06 15:15 . 2008-07-06 15:51 <DIR> d-------- C:\Programfiler\Trend Micro

2008-07-06 15:02 . 2005-08-16 11:03 <DIR> dr------- C:\Documents and Settings\Administrator.MARIUS\Start-meny

2008-07-06 15:02 . 2005-08-16 11:03 <DIR> d--h----- C:\Documents and Settings\Administrator.MARIUS\Skrivere

2008-07-06 15:02 . 2008-07-06 15:15 <DIR> d-------- C:\Documents and Settings\Administrator.MARIUS\Skrivebord

2008-07-06 15:02 . 2008-07-06 15:22 <DIR> dr-h----- C:\Documents and Settings\Administrator.MARIUS\Siste

2008-07-06 15:02 . 2005-08-16 09:28 <DIR> d-------- C:\Documents and Settings\Administrator.MARIUS\Programdata\Symantec

2008-07-06 15:02 . 2005-08-16 09:43 <DIR> dr-h----- C:\Documents and Settings\Administrator.MARIUS\Programdata

2008-07-06 15:02 . 2005-08-16 09:16 <DIR> dr------- C:\Documents and Settings\Administrator.MARIUS\Mine dokumenter

2008-07-06 15:02 . 2005-08-16 09:08 <DIR> d--h----- C:\Documents and Settings\Administrator.MARIUS\Maler

2008-07-06 15:02 . 2008-07-07 18:23 <DIR> d--h----- C:\Documents and Settings\Administrator.MARIUS\Lokale innstillinger

2008-07-06 15:02 . 2008-07-06 15:27 <DIR> dr------- C:\Documents and Settings\Administrator.MARIUS\Favoritter

2008-07-06 15:02 . 2005-08-16 11:03 <DIR> d--h----- C:\Documents and Settings\Administrator.MARIUS\AndrMask

2008-07-06 15:02 . 2008-07-06 15:02 <DIR> d-------- C:\Documents and Settings\Administrator.MARIUS

2008-07-06 14:59 . 2008-07-06 14:59 89,088 --a------ C:\WINDOWS\system32\klwqaftc.dll

2008-07-06 14:10 . 2008-07-06 14:10 268 --ah----- C:\sqmdata13.sqm

2008-07-06 14:10 . 2008-07-06 14:10 244 --ah----- C:\sqmnoopt13.sqm

2008-06-18 18:46 . 2008-06-18 18:46 1,556,480 --a------ C:\WINDOWS\system32\saqgyagx.tmp

2008-06-17 20:34 . 2008-07-06 14:49 <DIR> d-------- C:\WINDOWS\privacy_danger(2)

2008-06-17 19:15 . 2008-07-06 14:51 <DIR> d-------- C:\Documents and Settings\Administrator\Programdata

2008-06-17 19:15 . 2008-07-06 14:51 <DIR> d-------- C:\Documents and Settings\Administrator\Maler

2008-06-17 19:15 . 2008-07-07 18:23 <DIR> d-------- C:\Documents and Settings\Administrator\Lokale innstillinger

2008-06-17 19:15 . 2008-07-06 14:51 <DIR> d-------- C:\Documents and Settings\Administrator\Favoritter

2008-06-17 19:15 . 2008-07-06 14:51 <DIR> d---s---- C:\Documents and Settings\Administrator

2008-06-17 17:51 . 2008-06-17 19:06 <DIR> d-------- C:\Documents and Settings\Familie\.housecall6.6

2008-06-17 16:42 . 2008-06-17 16:42 197 --a------ C:\WINDOWS\system32\MRT.INI

2008-06-15 14:02 . 2008-07-06 16:30 <DIR> d-------- C:\Programfiler\Norton AntiVirus

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-07-06 15:28 --------- d-----w C:\Programfiler\AVI Codec Pack

2008-07-06 14:39 --------- d-----w C:\Programfiler\Symantec

2008-07-06 14:39 --------- d-----w C:\Programfiler\Fellesfiler\Symantec Shared

2008-07-06 14:33 --------- d-----w C:\Documents and Settings\All Users\Programdata\Symantec

2008-07-06 14:32 --------- d-----w C:\Programfiler\CCleaner

2008-07-06 14:20 --------- d-----w C:\Documents and Settings\Familie\Programdata\Symantec

2008-07-06 13:39 --------- d-----w C:\Programfiler\lg_swupdate

2008-07-06 13:28 --------- d-----w C:\Programfiler\Google

2008-06-14 18:00 272,256 ----a-w C:\WINDOWS\system32\drivers\bthport.sys

2008-06-08 16:50 --------- d-----w C:\Documents and Settings\Familie\Programdata\OpenOffice.org2

2008-05-26 20:00 --------- d-----w C:\Programfiler\Fellesfiler\Adobe

2008-05-26 19:55 --------- d-----w C:\Documents and Settings\Familie\Programdata\AdobeUM

2008-05-21 09:25 --------- d-----w C:\Programfiler\Java

2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys

2006-11-07 18:48 774,144 ----a-w C:\Programfiler\RngInterstitial.dll

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ATIPTA"="C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-07 21:05 344064]

"batterymiser"="C:\Programfiler\LG Software\Battery Miser 2005\batterymiser.exe" [2006-06-01 17:54 335872]

"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]

"InCD"="C:\Programfiler\Ahead\InCD\InCD.exe" [2005-04-12 11:15 1383936]

"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-08-13 20:05 2532576]

"SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]

"PCSuiteTrayApplication"="C:\Programfiler\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 14:20 227328]

"f0bd0392"="C:\WINDOWS\system32\klwqaftc.dll" [2008-07-06 14:59 89088]

"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 14:00 158208]

"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 14:00 110592 C:\WINDOWS\system32\bthprops.cpl]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]

"Nokia.PCSync"="C:\Programfiler\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 16:58 1744896]

 

C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\

Hurtigstart for Adobe Reader.lnk - C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]

Logitech Harmony Remote V5.lnk - C:\Programfiler\Logitech\Harmony Remote\HarmonyClient.exe [2005-07-26 11:35:56 94295]

Ralink Wireless Utility.lnk - C:\Programfiler\RALINK\RT2500 Wireless LAN Card\Installer\WINXP\RaConfig2500.exe [2006-04-05 21:39:23 561152]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{26F5978F-6493-4ee3-B114-C0C3ACCF9D4D}"= "C:\WINDOWS\system32\bmpsap.dll" [2006-06-01 17:54 114688]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KeybdUtility]

--a------ 2005-07-26 10:18 81920 C:\Programfiler\LG Software\On Screen Display\HotKey.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]

--a------ 2003-08-19 12:06 57344 C:\Programfiler\Lexmark X1100 Series\lxbkbmgr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LG Intelligent Update]

--a------ 2006-01-26 13:52 106496 C:\Programfiler\lg_swupdate\autoupdate.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]

--a------ 2007-10-18 12:34 5724184 C:\Programfiler\Windows Live\Messenger\msnmsgr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

--a------ 2006-08-24 21:46 282624 C:\Programfiler\QuickTime\qttask.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]

--a------ 2005-02-14 01:58 667740 C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]

--a------ 2005-02-14 01:59 98396 C:\Programfiler\Synaptics\SynTP\SynTPLpr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]

--a------ 2004-11-09 01:19 88358 C:\WINDOWS\AGRSMMSG.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"WMPNetworkSvc"=3 (0x3)

"WLSetupSvc"=3 (0x3)

"usnjsvc"=3 (0x3)

"Symantec RemoteAssist"=3 (0x3)

"Symantec Core LC"=2 (0x2)

"SPBBCSvc"=2 (0x2)

"SNDSrvc"=3 (0x3)

"ServiceLayer"=3 (0x3)

"SAVScan"=3 (0x3)

"NSCService"=3 (0x3)

"NPFMntor"=2 (0x2)

"navi"=2 (0x2)

"navapsvc"=2 (0x2)

"LiveUpdate Notice Service"=2 (0x2)

"LiveUpdate"=3 (0x3)

"LicCtrlService"=2 (0x2)

"IDriverT"=3 (0x3)

"ccSetMgr"=2 (0x2)

"ccEvtMgr"=2 (0x2)

"Automatisk LiveUpdate-schemaläggare"=2 (0x2)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Programfiler\\Logitech\\Harmony Remote\\PatchHelper.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"C:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"=

"C:\\Programfiler\\Windows Live\\Messenger\\livecall.exe"=

"C:\\Programfiler\\Internet Explorer\\iexplore.exe"=

 

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]

R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]

S3 cxbu0wdm;CardMan 3x21;C:\WINDOWS\system32\DRIVERS\cxbu0wdm.sys [2006-07-11 09:03]

S4 LicCtrlService;LicCtrl Service;C:\WINDOWS\runservice.exe [2006-12-05 15:15]

 

.

- - - - ORPHANS REMOVED - - - -

 

BHO-{838A57F4-7F51-4C6D-937E-CCB826D59A1F} - (no file)

Toolbar-{8E1F6C9A-86C0-4811-B45A-278E754B457F} - (no file)

MSConfigStartUp-ccApp - C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe

MSConfigStartUp-NAV CfgWiz - C:\Programfiler\Norton AntiVirus\CfgWiz.exe

MSConfigStartUp-swg - C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

 

 

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-07 18:28:03

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

 

C:\WINDOWS\system32\ctfaqwlk.ini 294 bytes

 

scan completed successfully

hidden files: 1

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]

"ImagePath"=""

.

--------------------- DLLs Loaded Under Running Processes ---------------------

 

PROCESS: C:\WINDOWS\explorer.exe

-> C:\WINDOWS\system32\klwqaftc.dll

.

------------------------ Other Running Processes ------------------------

.

C:\WINDOWS\system32\ati2evxx.exe

C:\Programfiler\Ahead\InCD\InCDsrv.exe

C:\Programfiler\Sygate\SPF\Smc.exe

C:\Programfiler\Alwil Software\Avast4\aswUpdSv.exe

C:\Programfiler\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\LEXPPS.EXE

C:\WINDOWS\system32\scardsvr.exe

C:\Programfiler\Alwil Software\Avast4\ashMaiSv.exe

C:\Programfiler\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\system32\ati2evxx.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\system32\rundll32.exe

.

**************************************************************************

.

Completion time: 2008-07-07 18:37:00 - machine was rebooted

ComboFix-quarantined-files.txt 2008-07-07 16:36:49

 

Pre-Run: 32,357,453,824 byte ledig

Post-Run: 32,316,559,360 byte ledig

 

188 --- E O F --- 2008-07-06 19:04:37

 

Lenke til kommentar

Combofix er kanskje det beste programmet å bruke når man kan å bruke det.

 

Åpne notisblokk og kopier inn det som står i fet skrift under, lagre fila på skrivebordet som CFScript.txt.

Dra deretter fila over Combofix-iconet. Combofix vil starte igjen.

 

File::

C:\WINDOWS\system32\ctfaqwlk.ini

C:\WINDOWS\system32\klwqaftc.dll

C:\WINDOWS\system32\saqgyagx.tmp

 

Folder::

C:\WINDOWS\privacy_danger(2)

 

Registry::

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"f0bd0392"=-

 

 

Post ny combofix-logg.

 

Hvilket Antivirusprogram er det du bruker? Det virker som om det ligger 2 - Avast og Norton, på pc. Fjern det ene.

Endret av norbat
Lenke til kommentar
Hvilket Antivirusprogram er det du bruker? Det virker som om det ligger 2 - Avast og Norton, på pc. Fjern det ene.

 

Jeg har avinstallert Norton og ccleaner for å fjerne restene. Men kjenner jeg norton rett så er det vanskelig å fjerne alt.

 

Her er resultatet av den siste combofix loggen:

 

 

ComboFix 08-07-05.1 - Familie 2008-07-07 22:35:35.2 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1044.18.121 [GMT 2:00]

Running from: C:\Documents and Settings\Familie\Skrivebord\ComboFix.exe

Command switches used :: C:\Documents and Settings\Familie\Skrivebord\CFScript.txt

* Created a new restore point

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

 

FILE ::

C:\WINDOWS\system32\ctfaqwlk.ini

C:\WINDOWS\system32\klwqaftc.dll

C:\WINDOWS\system32\saqgyagx.tmp

.

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\WINDOWS\privacy_danger(2)

C:\WINDOWS\privacy_danger(2)\images(2)\capt.gif

C:\WINDOWS\privacy_danger(2)\images(2)\danger.jpg

C:\WINDOWS\privacy_danger(2)\images(2)\down.gif

C:\WINDOWS\privacy_danger(2)\images(2)\spacer.gif

C:\WINDOWS\privacy_danger(2)\index.htm

C:\WINDOWS\system32\ctfaqwlk.ini

C:\WINDOWS\system32\klwqaftc.dll

C:\WINDOWS\system32\saqgyagx.tmp

 

.

((((((((((((((((((((((((( Files Created from 2008-06-07 to 2008-07-07 )))))))))))))))))))))))))))))))

.

 

2008-07-06 16:50 . 2008-07-06 16:50 <DIR> d-------- C:\Programfiler\Alwil Software

2008-07-06 15:41 . 2008-07-06 15:41 268 --ah----- C:\sqmdata14.sqm

2008-07-06 15:41 . 2008-07-06 15:41 244 --ah----- C:\sqmnoopt14.sqm

2008-07-06 15:15 . 2008-07-06 15:51 <DIR> d-------- C:\Programfiler\Trend Micro

2008-07-06 15:02 . 2005-08-16 11:03 <DIR> dr------- C:\Documents and Settings\Administrator.MARIUS\Start-meny

2008-07-06 15:02 . 2005-08-16 11:03 <DIR> d--h----- C:\Documents and Settings\Administrator.MARIUS\Skrivere

2008-07-06 15:02 . 2008-07-06 15:15 <DIR> d-------- C:\Documents and Settings\Administrator.MARIUS\Skrivebord

2008-07-06 15:02 . 2008-07-06 15:22 <DIR> dr-h----- C:\Documents and Settings\Administrator.MARIUS\Siste

2008-07-06 15:02 . 2005-08-16 09:28 <DIR> d-------- C:\Documents and Settings\Administrator.MARIUS\Programdata\Symantec

2008-07-06 15:02 . 2005-08-16 09:43 <DIR> dr-h----- C:\Documents and Settings\Administrator.MARIUS\Programdata

2008-07-06 15:02 . 2005-08-16 09:16 <DIR> dr------- C:\Documents and Settings\Administrator.MARIUS\Mine dokumenter

2008-07-06 15:02 . 2005-08-16 09:08 <DIR> d--h----- C:\Documents and Settings\Administrator.MARIUS\Maler

2008-07-06 15:02 . 2008-07-07 22:38 <DIR> d--h----- C:\Documents and Settings\Administrator.MARIUS\Lokale innstillinger

2008-07-06 15:02 . 2008-07-06 15:27 <DIR> dr------- C:\Documents and Settings\Administrator.MARIUS\Favoritter

2008-07-06 15:02 . 2005-08-16 11:03 <DIR> d--h----- C:\Documents and Settings\Administrator.MARIUS\AndrMask

2008-07-06 15:02 . 2008-07-06 15:02 <DIR> d-------- C:\Documents and Settings\Administrator.MARIUS

2008-07-06 14:10 . 2008-07-06 14:10 268 --ah----- C:\sqmdata13.sqm

2008-07-06 14:10 . 2008-07-06 14:10 244 --ah----- C:\sqmnoopt13.sqm

2008-06-17 19:15 . 2008-07-06 14:51 <DIR> d-------- C:\Documents and Settings\Administrator\Programdata

2008-06-17 19:15 . 2008-07-06 14:51 <DIR> d-------- C:\Documents and Settings\Administrator\Maler

2008-06-17 19:15 . 2008-07-07 22:38 <DIR> d-------- C:\Documents and Settings\Administrator\Lokale innstillinger

2008-06-17 19:15 . 2008-07-06 14:51 <DIR> d-------- C:\Documents and Settings\Administrator\Favoritter

2008-06-17 19:15 . 2008-07-06 14:51 <DIR> d---s---- C:\Documents and Settings\Administrator

2008-06-17 17:51 . 2008-06-17 19:06 <DIR> d-------- C:\Documents and Settings\Familie\.housecall6.6

2008-06-17 16:42 . 2008-06-17 16:42 197 --a------ C:\WINDOWS\system32\MRT.INI

2008-06-15 14:02 . 2008-07-06 16:30 <DIR> d-------- C:\Programfiler\Norton AntiVirus

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-07-07 20:29 --------- d-----w C:\Programfiler\Windows Live Toolbar

2008-07-07 20:28 --------- d-----w C:\Programfiler\Windows Live

2008-07-06 15:28 --------- d-----w C:\Programfiler\AVI Codec Pack

2008-07-06 14:39 --------- d-----w C:\Programfiler\Symantec

2008-07-06 14:39 --------- d-----w C:\Programfiler\Fellesfiler\Symantec Shared

2008-07-06 14:33 --------- d-----w C:\Documents and Settings\All Users\Programdata\Symantec

2008-07-06 14:32 --------- d-----w C:\Programfiler\CCleaner

2008-07-06 14:20 --------- d-----w C:\Documents and Settings\Familie\Programdata\Symantec

2008-07-06 13:39 --------- d-----w C:\Programfiler\lg_swupdate

2008-07-06 13:28 --------- d-----w C:\Programfiler\Google

2008-06-14 18:00 272,256 ----a-w C:\WINDOWS\system32\drivers\bthport.sys

2008-06-08 16:50 --------- d-----w C:\Documents and Settings\Familie\Programdata\OpenOffice.org2

2008-05-26 20:00 --------- d-----w C:\Programfiler\Fellesfiler\Adobe

2008-05-26 19:55 --------- d-----w C:\Documents and Settings\Familie\Programdata\AdobeUM

2008-05-21 09:25 --------- d-----w C:\Programfiler\Java

2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys

2006-11-07 18:48 774,144 ----a-w C:\Programfiler\RngInterstitial.dll

.

 

((((((((((((((((((((((((((((( snapshot@2008-07-07_18.36.33.04 )))))))))))))))))))))))))))))))))))))))))

.

- 2008-07-07 16:25:08 2,048 --s-a-w C:\WINDOWS\bootstat.dat

+ 2008-07-07 20:39:46 2,048 --s-a-w C:\WINDOWS\bootstat.dat

+ 2008-07-07 20:39:56 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_7f4.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ATIPTA"="C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-07 21:05 344064]

"batterymiser"="C:\Programfiler\LG Software\Battery Miser 2005\batterymiser.exe" [2006-06-01 17:54 335872]

"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]

"InCD"="C:\Programfiler\Ahead\InCD\InCD.exe" [2005-04-12 11:15 1383936]

"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-08-13 20:05 2532576]

"SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]

"PCSuiteTrayApplication"="C:\Programfiler\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 14:20 227328]

"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 14:00 158208]

"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 14:00 110592 C:\WINDOWS\system32\bthprops.cpl]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]

"Nokia.PCSync"="C:\Programfiler\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 16:58 1744896]

 

C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\

Hurtigstart for Adobe Reader.lnk - C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]

Logitech Harmony Remote V5.lnk - C:\Programfiler\Logitech\Harmony Remote\HarmonyClient.exe [2005-07-26 11:35:56 94295]

Ralink Wireless Utility.lnk - C:\Programfiler\RALINK\RT2500 Wireless LAN Card\Installer\WINXP\RaConfig2500.exe [2006-04-05 21:39:23 561152]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{26F5978F-6493-4ee3-B114-C0C3ACCF9D4D}"= "C:\WINDOWS\system32\bmpsap.dll" [2006-06-01 17:54 114688]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KeybdUtility]

--a------ 2005-07-26 10:18 81920 C:\Programfiler\LG Software\On Screen Display\HotKey.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]

--a------ 2003-08-19 12:06 57344 C:\Programfiler\Lexmark X1100 Series\lxbkbmgr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LG Intelligent Update]

--a------ 2006-01-26 13:52 106496 C:\Programfiler\lg_swupdate\autoupdate.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

--a------ 2006-08-24 21:46 282624 C:\Programfiler\QuickTime\qttask.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]

--a------ 2005-02-14 01:58 667740 C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]

--a------ 2005-02-14 01:59 98396 C:\Programfiler\Synaptics\SynTP\SynTPLpr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]

--a------ 2004-11-09 01:19 88358 C:\WINDOWS\AGRSMMSG.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"WMPNetworkSvc"=3 (0x3)

"WLSetupSvc"=3 (0x3)

"usnjsvc"=3 (0x3)

"Symantec RemoteAssist"=3 (0x3)

"Symantec Core LC"=2 (0x2)

"SPBBCSvc"=2 (0x2)

"SNDSrvc"=3 (0x3)

"ServiceLayer"=3 (0x3)

"SAVScan"=3 (0x3)

"NSCService"=3 (0x3)

"NPFMntor"=2 (0x2)

"navi"=2 (0x2)

"navapsvc"=2 (0x2)

"LiveUpdate Notice Service"=2 (0x2)

"LiveUpdate"=3 (0x3)

"LicCtrlService"=2 (0x2)

"IDriverT"=3 (0x3)

"ccSetMgr"=2 (0x2)

"ccEvtMgr"=2 (0x2)

"Automatisk LiveUpdate-schemaläggare"=2 (0x2)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Programfiler\\Logitech\\Harmony Remote\\PatchHelper.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"C:\\Programfiler\\Internet Explorer\\iexplore.exe"=

 

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]

R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]

S3 cxbu0wdm;CardMan 3x21;C:\WINDOWS\system32\DRIVERS\cxbu0wdm.sys [2006-07-11 09:03]

S4 LicCtrlService;LicCtrl Service;C:\WINDOWS\runservice.exe [2006-12-05 15:15]

 

.

- - - - ORPHANS REMOVED - - - -

 

MSConfigStartUp-MsnMsgr - C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe

 

 

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-07 22:41:46

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]

"ImagePath"=""

.

------------------------ Other Running Processes ------------------------

.

C:\WINDOWS\system32\ati2evxx.exe

C:\Programfiler\Ahead\InCD\InCDsrv.exe

C:\Programfiler\Sygate\SPF\Smc.exe

C:\Programfiler\Alwil Software\Avast4\aswUpdSv.exe

C:\Programfiler\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\LEXPPS.EXE

C:\WINDOWS\system32\scardsvr.exe

C:\WINDOWS\system32\ati2evxx.exe

C:\Programfiler\Alwil Software\Avast4\ashMaiSv.exe

C:\Programfiler\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\system32\rundll32.exe

.

**************************************************************************

.

Completion time: 2008-07-07 22:50:37 - machine was rebooted

ComboFix-quarantined-files.txt 2008-07-07 20:50:25

ComboFix2.txt 2008-07-07 16:37:01

 

Pre-Run: 32,229,019,648 byte ledig

Post-Run: 32,234,962,944 byte ledig

 

186 --- E O F --- 2008-07-06 19:04:37

 

Lenke til kommentar
Ser greit ut.

 

Bruk Norton Removal Tool til å fjerne restene etter Norton.

 

OK, da skal jeg ha fjernet Norton.

 

Men alt er ikke rosenrødt ennå. Jeg får ikke tilgang til oversikt over prosessor,minne og så videre når jeg trykker ctrl+alt+del. Det eneste jeg får opp er hvilke programmer som kjører.

 

Kan systemet være skadet og kan jeg kjøre combofix en gang til for å være sikker?

Lenke til kommentar

kjør en runde med hitman pro (både i vanlig og sikkermodus... det samme med combofix også).

 

Hitman pro har automatisk installasjon og kjøring av de mest "vanlige" anti-badware programmene. Kommer du ikke noe lenger med det, kan du også prøve en demoversjon av NOD32, men det du ikke får fjernet med combofix og hitman pro er som regel veldig vanskelig å fjerne.

 

I såfall må du nok sette hardere lut til (manuellt arbeid med register -og filsøk). Selv bruker jeg sysinternals pakken og killbox, samt annet diverse høgg. Men dette tar ofte veldig lang tid, og krever en del kunnskap, så det går som regel raskere å reinstallere hvis du kommer borti slikt.

 

Prøv også diverse rootkit revival/removal tools.

 

Har selv vært borti å måtte gi helt opp EN gang grunnet slikt (da satt jeg i 4 dager).

 

NB: Når du har gjort det ovenfornevnte, prøv også å kjør SFC /scannow

 

Dette sjekker integriteten på windows systemfiler (ha windows cd'en klar.

Endret av JKJK
Lenke til kommentar
(både i vanlig og sikkermodus... det samme med combofix også).

Man ber ikke noen kjøre combofix i vanlig og sikkerhetmodus uten og poste loggen.

Dette er et kraftig verktøy hvor man må kunne tyde loggen.

Combofix har også rootkit scanner.

 

Er man raske med og poste logger og bruker de verktøy vi ber om er pcen ren for all maleware i løpet av 30min.

Endret av SNIPPSAT
Lenke til kommentar

Jeg skal sjekke noen av disse tingene når jeg kommer hjem. Jeg er usikker på om jeg prøvde å dobbeltklikke rammen. Jeg må også installere antivirus programmet på nytt da den ikke kjører i notification area lenger.

 

Jeg har litt erfaring med registry i windows men det begynner å bli noen år siden. Men jeg skal kjøre combofix en gang til og poste resultatet så får vi se om alt er i orden. Hvis noen windows filer er skadet eller borte må man vel bare installerer driverne på nytt.

Lenke til kommentar

Det fungerte å dobbeltklikke på rammen i task manager så fikk jeg frem alle menyer.

 

Under er siste utgave av logen fra combofix. Ser alt bra ut?

 

 

 

ComboFix 08-07-05.1 - Familie 2008-07-08 18:01:45.3 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1044.18.129 [GMT 2:00]

Running from: C:\Documents and Settings\Familie\Skrivebord\ComboFix.exe

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((((( Files Created from 2008-06-08 to 2008-07-08 )))))))))))))))))))))))))))))))

.

 

2008-07-06 16:50 . 2008-07-06 16:50 <DIR> d-------- C:\Programfiler\Alwil Software

2008-07-06 15:41 . 2008-07-06 15:41 268 --ah----- C:\sqmdata14.sqm

2008-07-06 15:41 . 2008-07-06 15:41 244 --ah----- C:\sqmnoopt14.sqm

2008-07-06 15:15 . 2008-07-06 15:51 <DIR> d-------- C:\Programfiler\Trend Micro

2008-07-06 15:02 . 2005-08-16 11:03 <DIR> dr------- C:\Documents and Settings\Administrator.MARIUS\Start-meny

2008-07-06 15:02 . 2005-08-16 11:03 <DIR> d--h----- C:\Documents and Settings\Administrator.MARIUS\Skrivere

2008-07-06 15:02 . 2008-07-06 15:15 <DIR> d-------- C:\Documents and Settings\Administrator.MARIUS\Skrivebord

2008-07-06 15:02 . 2008-07-06 15:22 <DIR> dr-h----- C:\Documents and Settings\Administrator.MARIUS\Siste

2008-07-06 15:02 . 2005-08-16 09:28 <DIR> d-------- C:\Documents and Settings\Administrator.MARIUS\Programdata\Symantec

2008-07-06 15:02 . 2005-08-16 09:43 <DIR> dr-h----- C:\Documents and Settings\Administrator.MARIUS\Programdata

2008-07-06 15:02 . 2005-08-16 09:16 <DIR> dr------- C:\Documents and Settings\Administrator.MARIUS\Mine dokumenter

2008-07-06 15:02 . 2005-08-16 09:08 <DIR> d--h----- C:\Documents and Settings\Administrator.MARIUS\Maler

2008-07-06 15:02 . 2008-07-08 18:04 <DIR> d--h----- C:\Documents and Settings\Administrator.MARIUS\Lokale innstillinger

2008-07-06 15:02 . 2008-07-06 15:27 <DIR> dr------- C:\Documents and Settings\Administrator.MARIUS\Favoritter

2008-07-06 15:02 . 2005-08-16 11:03 <DIR> d--h----- C:\Documents and Settings\Administrator.MARIUS\AndrMask

2008-07-06 15:02 . 2008-07-06 15:02 <DIR> d-------- C:\Documents and Settings\Administrator.MARIUS

2008-07-06 14:10 . 2008-07-06 14:10 268 --ah----- C:\sqmdata13.sqm

2008-07-06 14:10 . 2008-07-06 14:10 244 --ah----- C:\sqmnoopt13.sqm

2008-06-17 19:15 . 2008-07-06 14:51 <DIR> d-------- C:\Documents and Settings\Administrator\Programdata

2008-06-17 19:15 . 2008-07-06 14:51 <DIR> d-------- C:\Documents and Settings\Administrator\Maler

2008-06-17 19:15 . 2008-07-08 18:04 <DIR> d-------- C:\Documents and Settings\Administrator\Lokale innstillinger

2008-06-17 19:15 . 2008-07-06 14:51 <DIR> d-------- C:\Documents and Settings\Administrator\Favoritter

2008-06-17 19:15 . 2008-07-06 14:51 <DIR> d---s---- C:\Documents and Settings\Administrator

2008-06-17 17:51 . 2008-06-17 19:06 <DIR> d-------- C:\Documents and Settings\Familie\.housecall6.6

2008-06-17 16:42 . 2008-06-17 16:42 197 --a------ C:\WINDOWS\system32\MRT.INI

2008-06-15 14:02 . 2008-07-06 16:30 <DIR> d-------- C:\Programfiler\Norton AntiVirus

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-07-08 16:00 --------- d-----w C:\Programfiler\lg_swupdate

2008-07-07 21:42 --------- d-----w C:\Programfiler\Fellesfiler\Symantec Shared

2008-07-07 20:29 --------- d-----w C:\Programfiler\Windows Live Toolbar

2008-07-07 20:28 --------- d-----w C:\Programfiler\Windows Live

2008-07-06 15:28 --------- d-----w C:\Programfiler\AVI Codec Pack

2008-07-06 14:32 --------- d-----w C:\Programfiler\CCleaner

2008-07-06 13:28 --------- d-----w C:\Programfiler\Google

2008-06-14 18:00 272,256 ----a-w C:\WINDOWS\system32\drivers\bthport.sys

2008-06-08 16:50 --------- d-----w C:\Documents and Settings\Familie\Programdata\OpenOffice.org2

2008-05-26 20:00 --------- d-----w C:\Programfiler\Fellesfiler\Adobe

2008-05-26 19:55 --------- d-----w C:\Documents and Settings\Familie\Programdata\AdobeUM

2008-05-21 09:25 --------- d-----w C:\Programfiler\Java

2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys

2008-05-07 05:16 1,290,752 ----a-w C:\WINDOWS\system32\quartz.dll

2008-04-23 04:22 826,368 ----a-w C:\WINDOWS\system32\wininet.dll

2006-11-07 18:48 774,144 ----a-w C:\Programfiler\RngInterstitial.dll

.

 

((((((((((((((((((((((((((((( snapshot@2008-07-07_18.36.33.04 )))))))))))))))))))))))))))))))))))))))))

.

- 2008-07-07 16:25:08 2,048 --s-a-w C:\WINDOWS\bootstat.dat

+ 2008-07-08 15:57:09 2,048 --s-a-w C:\WINDOWS\bootstat.dat

+ 2008-07-08 15:57:17 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_118.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ATIPTA"="C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-07 21:05 344064]

"batterymiser"="C:\Programfiler\LG Software\Battery Miser 2005\batterymiser.exe" [2006-06-01 17:54 335872]

"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]

"InCD"="C:\Programfiler\Ahead\InCD\InCD.exe" [2005-04-12 11:15 1383936]

"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-08-13 20:05 2532576]

"SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]

"PCSuiteTrayApplication"="C:\Programfiler\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 14:20 227328]

"SynTPLpr"="C:\Programfiler\Synaptics\SynTP\SynTPLpr.exe" [2005-02-14 01:59 98396]

"SynTPEnh"="C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe" [2005-02-14 01:58 667740]

"QuickTime Task"="C:\Programfiler\QuickTime\qttask.exe" [2006-08-24 21:46 282624]

"LG Intelligent Update"="C:\Programfiler\lg_swupdate\autoupdate.exe" [2006-01-26 13:52 106496]

"Lexmark X1100 Series"="C:\Programfiler\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 12:06 57344]

"KeybdUtility"="C:\Programfiler\LG Software\On Screen Display\Hotkey.exe" [2005-07-26 10:18 81920]

"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 14:00 110592 C:\WINDOWS\system32\bthprops.cpl]

"AGRSMMSG"="AGRSMMSG.exe" [2004-11-09 01:19 88358 C:\WINDOWS\AGRSMMSG.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]

"Nokia.PCSync"="C:\Programfiler\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 16:58 1744896]

 

C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\

Hurtigstart for Adobe Reader.lnk - C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]

Logitech Harmony Remote V5.lnk - C:\Programfiler\Logitech\Harmony Remote\HarmonyClient.exe [2005-07-26 11:35:56 94295]

Ralink Wireless Utility.lnk - C:\Programfiler\RALINK\RT2500 Wireless LAN Card\Installer\WINXP\RaConfig2500.exe [2006-04-05 21:39:23 561152]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{26F5978F-6493-4ee3-B114-C0C3ACCF9D4D}"= "C:\WINDOWS\system32\bmpsap.dll" [2006-06-01 17:54 114688]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"WLSetupSvc"=3 (0x3)

"usnjsvc"=3 (0x3)

"Symantec RemoteAssist"=3 (0x3)

"Symantec Core LC"=2 (0x2)

"SPBBCSvc"=2 (0x2)

"SNDSrvc"=3 (0x3)

"SAVScan"=3 (0x3)

"NSCService"=3 (0x3)

"NPFMntor"=2 (0x2)

"navapsvc"=2 (0x2)

"LiveUpdate Notice Service"=2 (0x2)

"LiveUpdate"=3 (0x3)

"ccSetMgr"=2 (0x2)

"ccEvtMgr"=2 (0x2)

"Automatisk LiveUpdate-schemaläggare"=2 (0x2)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Programfiler\\Logitech\\Harmony Remote\\PatchHelper.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"C:\\Programfiler\\Internet Explorer\\iexplore.exe"=

 

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]

R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]

R2 LicCtrlService;LicCtrl Service;C:\WINDOWS\runservice.exe [2006-12-05 15:15]

S3 cxbu0wdm;CardMan 3x21;C:\WINDOWS\system32\DRIVERS\cxbu0wdm.sys [2006-07-11 09:03]

 

*Newly Created Service* - CATCHME

.

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-08 18:04:51

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\UserIO]

"ImagePath"="\??\C:\Programfiler\lg_swupdate\UserIO.sys"

 

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\vsdatant]

"ImagePath"=""

.

Completion time: 2008-07-08 18:08:52

ComboFix-quarantined-files.txt 2008-07-08 16:08:41

ComboFix2.txt 2008-07-07 20:50:39

ComboFix3.txt 2008-07-07 16:37:01

 

Pre-Run: 33,058,664,448 byte ledig

Post-Run: 33,065,484,288 byte ledig

 

139 --- E O F --- 2008-07-06 19:04:37

 

Lenke til kommentar

Slett mapper.

C:\Documents and Settings\Administrator.MARIUS\Programdata\Symantec

C:\Programfiler\Norton AntiVirus

C:\Programfiler\Fellesfiler\Symantec Shared

---

Kjør CCleaner som du har som dette.

'Valg'->'Avansert'. Fjern avkryssingen framfor: "bare slett midlertidige filer som er eldere enn 48 t.

Kjør og register-renser"svar ja til og reparere"-->backup svar ja når du blir spørt.

Kjør register-renser et par ganger til alle feil er borte.

---

Tar en logg til så sier vi det er bra.

Last ned HijackThis legg i egen mappe på skrivebordet.

Start programmet og velg "Trykk scan og save log"

Post HijackThis.txt

Lenke til kommentar

Da har jeg gjort dette. Måtte installere Mcafee da Avast ikke fungerte optimalt lenger.

 

Mcafee fant forresten vundo trojanere.

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 00:04, on 09.07.2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Programfiler\Ahead\InCD\InCDsrv.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\WINDOWS\runservice.exe

C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe

c:\PROGRA~1\FELLES~1\mcafee\mna\mcnasvc.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

c:\PROGRA~1\FELLES~1\mcafee\mcproxy\mcproxy.exe

C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe

C:\Programfiler\LG Software\Battery Miser 2005\batterymiser.exe

C:\Programfiler\Ahead\InCD\InCD.exe

C:\Programfiler\Java\jre1.6.0_06\bin\jusched.exe

C:\Programfiler\Nokia\Nokia PC Suite 6\LaunchApplication.exe

C:\WINDOWS\system32\rundll32.exe

C:\Programfiler\Synaptics\SynTP\SynTPLpr.exe

C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe

C:\Programfiler\QuickTime\qttask.exe

C:\Programfiler\Lexmark X1100 Series\lxbkbmgr.exe

C:\Programfiler\LG Software\On Screen Display\Hotkey.exe

C:\WINDOWS\AGRSMMSG.exe

C:\Programfiler\Lexmark X1100 Series\lxbkbmon.exe

C:\Programfiler\McAfee.com\Agent\mcagent.exe

C:\Programfiler\McAfee\MPF\MPFSrv.exe

C:\Programfiler\SiteAdvisor\6172\SiteAdv.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\Logitech\Harmony Remote\HarmonyClient.exe

C:\Programfiler\McAfee\MSK\MskSrver.exe

C:\Programfiler\SiteAdvisor\6172\SAService.exe

C:\WINDOWS\system32\svchost.exe

C:\Programfiler\PC Connectivity Solution\ServiceLayer.exe

C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe

C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe

C:\Programfiler\lg_swupdate\tmcheck.exe

c:\PROGRA~1\mcafee\msc\mcshell.exe

C:\Programfiler\Internet Explorer\IEXPLORE.EXE

C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe

C:\Programfiler\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.no/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENWW/SAOS01?FORM=TOOLBR

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Programfiler\SiteAdvisor\6172\SiteAdv.dll

O2 - BHO: McAfee Phishing Filter - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_06\bin\ssv.dll

O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Programfiler\McAfee\VirusScan\scriptsn.dll

O2 - BHO: (no name) - {9A50B2AF-3B2B-47DD-AECD-5D80A886F504} - C:\WINDOWS\system32\awtutuTJ.dll

O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Programfiler\SiteAdvisor\6172\SiteAdv.dll

O4 - HKLM\..\Run: [ATIPTA] C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM\..\Run: [batterymiser] "C:\Programfiler\LG Software\Battery Miser 2005\batterymiser.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [inCD] C:\Programfiler\Ahead\InCD\InCD.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_06\bin\jusched.exe"

O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programfiler\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup

O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

O4 - HKLM\..\Run: [synTPLpr] C:\Programfiler\Synaptics\SynTP\SynTPLpr.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [LG Intelligent Update] C:\Programfiler\lg_swupdate\autoupdate.exe Gilautouc

O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Programfiler\Lexmark X1100 Series\lxbkbmgr.exe"

O4 - HKLM\..\Run: [KeybdUtility] "C:\Programfiler\LG Software\On Screen Display\Hotkey.exe"

O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

O4 - HKLM\..\Run: [mcagent_exe] C:\Programfiler\McAfee.com\Agent\mcagent.exe /runkey

O4 - HKLM\..\Run: [siteAdvisor] C:\Programfiler\SiteAdvisor\6172\SiteAdv.exe

O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Hurtigstart for Adobe Reader.lnk = C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Logitech Harmony Remote V5.lnk = C:\Programfiler\Logitech\Harmony Remote\HarmonyClient.exe

O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Programfiler\RALINK\RT2500 Wireless LAN Card\Installer\WINXP\RaConfig2500.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_06\bin\ssv.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe (file missing)

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://benteh80.spaces.live.com//PhotoUpload/MsnPUpld.cab

O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O20 - AppInit_DLLs: ????????P

O20 - Winlogon Notify: awtutuTJ - C:\WINDOWS\SYSTEM32\awtutuTJ.dll

O23 - Service: McAfee Application Installer Cleanup (0000991215552446) (0000991215552446mcinstcleanup) - McAfee, Inc. - C:\WINDOWS\TEMP0099~1.EXE

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Programfiler\Ahead\InCD\InCDsrv.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe

O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe

O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\FELLES~1\mcafee\mna\mcnasvc.exe

O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe

O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FELLES~1\mcafee\mcproxy\mcproxy.exe

O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe

O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe

O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Programfiler\McAfee\MPF\MPFSrv.exe

O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Programfiler\McAfee\MSK\MskSrver.exe

O23 - Service: ServiceLayer - Nokia. - C:\Programfiler\PC Connectivity Solution\ServiceLayer.exe

O23 - Service: SiteAdvisor Service - Unknown owner - C:\Programfiler\SiteAdvisor\6172\SAService.exe

 

--

End of file - 10194 bytes

 

Lenke til kommentar

Start HijackThis

Velg: Do a systemscan only

 

Sett en hake i boksene foran disse linjene:

O2 - BHO: (no name) - {9A50B2AF-3B2B-47DD-AECD-5D80A886F504} - C:\WINDOWS\system32\awtutuTJ.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe (file missing)

O20 - Winlogon Notify: awtutuTJ - C:\WINDOWS\SYSTEM32\awtutuTJ.dll

Avslutt alle vinduer og nettlesere (også dette du leser fra), og trykk Fix checked.

Merk: Hvis du blir spurt om å bekrefte å fikse en linje, bekrefter du dette.

 

Bruk windows utforsker/min datamaskin til å finne, og slette følgende fil: C:\WINDOWS\SYSTEM32\awtutuTJ.dll

Gi tilbakemelding på om du finner den eller ikke.

 

Trykk på Start og deretter Kjør og skriv inn en og en linje av det som står i fet skrift nedenfor. Trykk enter eller OK mellom hver linje du skriver inn.

sc stop 0000991215552446) (0000991215552446mcinstcleanup

sc delete 0000991215552446) (0000991215552446mcinstcleanup

 

Deretter restarter du maskinen, og lager en ny logg:

Start HijackThis

Velg: Do a systemscan, and save a logfile

 

Post denne loggen i din neste post.

Lenke til kommentar

Jeg fant ikke den første i listen(awtutuTJ.dll). Trolig Mcafee som har fjernet den. Fant heller ikke filen i windows mappa.

 

Her er resultatet av siste hijackthis log:

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 16:56, on 09.07.2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Programfiler\Ahead\InCD\InCDsrv.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\runservice.exe

C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe

C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe

c:\PROGRA~1\FELLES~1\mcafee\mna\mcnasvc.exe

C:\Programfiler\LG Software\Battery Miser 2005\batterymiser.exe

C:\Programfiler\Ahead\InCD\InCD.exe

C:\Programfiler\Java\jre1.6.0_06\bin\jusched.exe

C:\Programfiler\Nokia\Nokia PC Suite 6\LaunchApplication.exe

C:\WINDOWS\system32\rundll32.exe

C:\Programfiler\Synaptics\SynTP\SynTPLpr.exe

C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe

c:\PROGRA~1\FELLES~1\mcafee\mcproxy\mcproxy.exe

C:\Programfiler\QuickTime\qttask.exe

C:\Programfiler\Lexmark X1100 Series\lxbkbmgr.exe

C:\Programfiler\LG Software\On Screen Display\Hotkey.exe

C:\Programfiler\McAfee\VirusScan\McShield.exe

C:\WINDOWS\AGRSMMSG.exe

C:\Programfiler\Lexmark X1100 Series\lxbkbmon.exe

C:\Programfiler\McAfee.com\Agent\mcagent.exe

C:\Programfiler\McAfee\MPF\MPFSrv.exe

C:\Programfiler\SiteAdvisor\6172\SiteAdv.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\Logitech\Harmony Remote\HarmonyClient.exe

C:\Programfiler\RALINK\RT2500 Wireless LAN Card\Installer\WINXP\RaConfig2500.exe

C:\Programfiler\McAfee\MSK\MskSrver.exe

C:\Programfiler\SiteAdvisor\6172\SAService.exe

C:\WINDOWS\system32\svchost.exe

C:\Programfiler\PC Connectivity Solution\ServiceLayer.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Programfiler\lg_swupdate\Gilautouc.exe

C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe

C:\Programfiler\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.no/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENWW/SAOS01?FORM=TOOLBR

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Programfiler\SiteAdvisor\6172\SiteAdv.dll

O2 - BHO: McAfee Phishing Filter - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_06\bin\ssv.dll

O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Programfiler\McAfee\VirusScan\scriptsn.dll

O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Programfiler\SiteAdvisor\6172\SiteAdv.dll

O4 - HKLM\..\Run: [ATIPTA] C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM\..\Run: [batterymiser] "C:\Programfiler\LG Software\Battery Miser 2005\batterymiser.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [inCD] C:\Programfiler\Ahead\InCD\InCD.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_06\bin\jusched.exe"

O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programfiler\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup

O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

O4 - HKLM\..\Run: [synTPLpr] C:\Programfiler\Synaptics\SynTP\SynTPLpr.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [LG Intelligent Update] C:\Programfiler\lg_swupdate\autoupdate.exe Gilautouc

O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Programfiler\Lexmark X1100 Series\lxbkbmgr.exe"

O4 - HKLM\..\Run: [KeybdUtility] "C:\Programfiler\LG Software\On Screen Display\Hotkey.exe"

O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

O4 - HKLM\..\Run: [mcagent_exe] C:\Programfiler\McAfee.com\Agent\mcagent.exe /runkey

O4 - HKLM\..\Run: [siteAdvisor] C:\Programfiler\SiteAdvisor\6172\SiteAdv.exe

O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Hurtigstart for Adobe Reader.lnk = C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Logitech Harmony Remote V5.lnk = C:\Programfiler\Logitech\Harmony Remote\HarmonyClient.exe

O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Programfiler\RALINK\RT2500 Wireless LAN Card\Installer\WINXP\RaConfig2500.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_06\bin\ssv.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://benteh80.spaces.live.com//PhotoUpload/MsnPUpld.cab

O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O20 - AppInit_DLLs: ????????P

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Programfiler\Ahead\InCD\InCDsrv.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe

O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe

O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\FELLES~1\mcafee\mna\mcnasvc.exe

O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe

O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FELLES~1\mcafee\mcproxy\mcproxy.exe

O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Programfiler\McAfee\VirusScan\McShield.exe

O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe

O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Programfiler\McAfee\MPF\MPFSrv.exe

O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Programfiler\McAfee\MSK\MskSrver.exe

O23 - Service: ServiceLayer - Nokia. - C:\Programfiler\PC Connectivity Solution\ServiceLayer.exe

O23 - Service: SiteAdvisor Service - Unknown owner - C:\Programfiler\SiteAdvisor\6172\SAService.exe

 

--

End of file - 9615 bytes

 

Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
  • Hvem er aktive   0 medlemmer

    • Ingen innloggede medlemmer aktive
×
×
  • Opprett ny...