Virus eller ren?
HejJeg har formatteret en ny harddisk (for 2. gang) men jeg er bange for at den allerede er formatteret.
Jeg ville gerne have om nogen kunne hjælpe med at kigge på en kort logfil:
smsss.exe og msmsgs.exe er (registreret i) msconfig som startup-programmer, og de vil ikke fjernes. Jeg tror at filerne faktisk ikke er på PCen, de kan i hvert afld ikke findes i Start>Search.
Under Hijackthis logfilen, har jeg nogle oplysninger fra Reghance2.1
Virus-scanning finder intet..
På forhånd tak
Tore
------------------------------------------
Logfile of HijackThis v1.99.0
Scan saved at 15:53:29, on 02-01-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\ZoneLabs\isafe.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\sstray.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HiJackThis\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [start uploading] smsss.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunServices: [start uploading] smsss.exe
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} (InstallFromTheWeb ActiveX Control) - http://tw.msi.com.tw/autobios/client/iftwclix.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1104447908607
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O23 - Service: CA ISafe - Computer Associates International, Inc. - C:\WINDOWS\System32\ZoneLabs\isafe.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--------------------------------
Searchresults for "smsss" ,02-01-2005:
HKEY_CURRENT_USER
Software\Microsoft\Windows\CurrentVersion\Runstart uploading
HKEY_CURRENT_USER
Software\Microsoft\Windows\CurrentVersion\RunServicesstart uploading
HKEY_USERS
S-1-5-21-117609710-823518204-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Runstart uploading
HKEY_USERS
S-1-5-21-117609710-823518204-839522115-1003\Software\Microsoft\Windows\CurrentVersion\RunServicesstart uploading
Ovenstående vil ikke slettes, de kommer tilbage..
************
Searchresults for "msmsgs" ,02-01-2005:
HKEY_CURRENT_USER
Software\Microsoft\Windows\CurrentVersion\RunMSMSGS
HKEY_LOCAL_MACHINE
SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSMSGS
HKEY_USERS
S-1-5-21-117609710-823518204-839522115-1003\Software\Microsoft\Windows\CurrentVersion\RunMSMSGS
