Jeg har endnu ikke slået systemgendannelse til!
Linierne 04 og 016 og Reboot er slettet.
Fandt frem til at reboot.exe er en rest af en afinstalleret scannerdriver der er 5 andre filer fra samme installationsklokkeslet - Skal de også ud? Det drejer sig om RunAp.exe Restart.exe, LostRun.exe, DeleteFiles.exe og CheckPaths.exe de er installeret inden for samme sekund.
her er en copy af loggen.
Logfile of HijackThis v1.97.7
Scan saved at 23:06:54, on 04-02-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
E:\Programmer\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE
E:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programmer\Messenger\MSMSGS.EXE
E:\programmer\Office\FINDFAST.EXE
E:\programmer\microsoft office\Office\MSOFFICE.EXE
e:\Programmer\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
e:\Programmer\Panda Software\Panda Antivirus Titanium\AVENGINE.EXE
e:\Programmer\Panda Software\Panda Antivirus Titanium\pavProxy.exe
C:\Documents and Settings\Thomas Bang Pedersen\Skrivebord\hijackthis1\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - e:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [APVXDWIN] "e:\Programmer\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [Zone Labs Client] E:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [MicroSys-CheckAjour] e:\Programmer\Micro-Sys Software\Ajour\ChkAjour.exe
O4 - Startup: Microsoft Hurtig søgning.lnk = E:\programmer\Office\FINDFAST.EXE
O4 - Startup: Microsoft Office Programlinje.lnk = E:\programmer\microsoft office\Office\MSOFFICE.EXE
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) -
http://office.microsoft.com/officeupdate/content/opuc.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38013.4257175926O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabsidste nyt:
Fra: Secunia Security Advisories <sec-adv@secunia.com> er der lige kommet 10 emails. email-adressen skifter ikke og den er blacklistet i Mailwasher
Fra:WebProWorld sendes konstant mails denne gang fra <1.20082.3132393634303034.1.b@emailizer.com> mailadressen skifter til en ny hver gang. jeg modtager ca 1 stk. pr time.