HJT, SAS; og Dr-web log, hjælp søges
Hej, dette er en opfølgning fra http://www.eksperten.dk/spm/729971, hvor jeg havde nogle problemer med Error safe, vundo og ultimate defender, her er mine logs, det skal dog sige hjt ikke er i fejlsikret tilstand:Dr-web:
Update.exe;C:\Programmer\Fælles filer\{6CC68356-0959-1030-1028-04022004002d};Trojan.Starter.65;Deleted.;
win63.tmp.exe;C:\Documents and Settings\Chris\Lokale indstillinger\Temp;Trojan.Popuper;Deleted.;
WinAntiVirusPro2006FreeInstall_dk[1].exe;C:\Documents and Settings\Chris\Lokale indstillinger\Temporary Internet Files\Content.IE5\0NYPOSRP;Trojan.DownLoader.10963;Deleted.;
popup[1].htm;C:\Documents and Settings\Chris\Lokale indstillinger\Temporary Internet Files\Content.IE5\8TI34DQJ;Trojan.Click.1394;Deleted.;
popup[1].htm;C:\Documents and Settings\Chris\Lokale indstillinger\Temporary Internet Files\Content.IE5\SZY5UKCP;Trojan.Click.1394;Deleted.;
wlzip32[1].exe;C:\Documents and Settings\Chris\Lokale indstillinger\Temporary Internet Files\Content.IE5\T0DLR5DJ;Trojan.Popuper;Deleted.;
PokerSuperstarsSetup-dm[1].exe;C:\Documents and Settings\Chris\Lokale indstillinger\Temporary Internet Files\Content.IE5\Y3K79YZI;Adware.TryMedia;Renamed.;
PokerSuperstarsSetup-dm[1].exe;C:\Downloads;Adware.TryMedia;Renamed.;
mirc.exe;C:\Program Files\mIRC;Program.mIRC.617;Renamed.;
MyToolBar.dll;C:\Programmer\ToolBar888;Adware.FastSearch;Renamed.;
A0020043.exe;C:\System Volume Information\_restore{33A14BD6-84B6-4523-9331-378D09CEF18C}\RP78;Adware.SaveNow;Renamed.;
A0020656.exe;C:\System Volume Information\_restore{33A14BD6-84B6-4523-9331-378D09CEF18C}\RP92;Trojan.Popuper;Deleted.;
A0020657.exe;C:\System Volume Information\_restore{33A14BD6-84B6-4523-9331-378D09CEF18C}\RP92;Trojan.Popuper;Deleted.;
A0020749.exe;C:\System Volume Information\_restore{33A14BD6-84B6-4523-9331-378D09CEF18C}\RP92;Trojan.Starter.65;Deleted.;
A0020750.exe;C:\System Volume Information\_restore{33A14BD6-84B6-4523-9331-378D09CEF18C}\RP92;Adware.TryMedia;Renamed.;
A0020751.exe;C:\System Volume Information\_restore{33A14BD6-84B6-4523-9331-378D09CEF18C}\RP92;Program.mIRC.617;Renamed.;
Sas: SUPERAntiSpyware Scan Log
Generated 09/03/2006 at 03:11 AM
Core Rules Database Version : 3072
Trace Rules Database Version: 1111
Memory threats detected : 2
Registry threats detected : 33
File threats detected : 27
Adware.Vundo Variant
C:\WINDOWS\SYSTEM32\AWTQN.DLL
C:\WINDOWS\SYSTEM32\AWTQN.DLL
HKLM\Software\Classes\CLSID\{7C98E35B-5DFA-4B59-85A6-BE5918F88C57}
HKCR\CLSID\{7C98E35B-5DFA-4B59-85A6-BE5918F88C57}
HKCR\CLSID\{7C98E35B-5DFA-4B59-85A6-BE5918F88C57}\InprocServer32
HKCR\CLSID\{7C98E35B-5DFA-4B59-85A6-BE5918F88C57}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C98E35B-5DFA-4B59-85A6-BE5918F88C57}
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\awtqn
Trojan.Mezzia/Resident
C:\WINDOWS\SYSTEM32\WINZMS32.DLL
C:\WINDOWS\SYSTEM32\WINZMS32.DLL
Adware.Tracking Cookie
C:\Documents and Settings\Chris\Cookies\chris@tribalfusion[1].txt
C:\Documents and Settings\Chris\Cookies\chris@admarketplace[1].txt
C:\Documents and Settings\Chris\Cookies\chris@adtech[2].txt
C:\Documents and Settings\Chris\Cookies\chris@cgi-bin[1].txt
C:\Documents and Settings\Chris\Cookies\chris@mediaplex[1].txt
C:\Documents and Settings\Chris\Cookies\chris@revenue[2].txt
C:\Documents and Settings\Chris\Cookies\chris@amaena[1].txt
C:\Documents and Settings\Chris\Cookies\chris@ad.yieldmanager[2].txt
C:\Documents and Settings\Chris\Cookies\chris@adserver.banneradministration[1].txt
C:\Documents and Settings\Chris\Cookies\chris@winantivirus[1].txt
C:\Documents and Settings\Chris\Cookies\chris@fastclick[2].txt
C:\Documents and Settings\Chris\Cookies\chris@stats1.reliablestats[1].txt
C:\Documents and Settings\Chris\Cookies\chris@track.adform[1].txt
C:\Documents and Settings\Chris\Cookies\chris@ads1.revenue[1].txt
C:\Documents and Settings\Chris\Cookies\chris@atdmt[2].txt
C:\Documents and Settings\Chris\Cookies\chris@advertising[1].txt
C:\Documents and Settings\Chris\Cookies\chris@cpvfeed[2].txt
C:\Documents and Settings\Chris\Cookies\chris@doubleclick[1].txt
C:\Documents and Settings\Chris\Cookies\chris@dk.winantivirus[2].txt
C:\Documents and Settings\Chris\Cookies\chris@indexstats[2].txt
Trojan.Unknown Origin
HKLM\SOFTWARE\Microsoft\MSSMGR
HKLM\SOFTWARE\Microsoft\MSSMGR#Data
HKLM\SOFTWARE\Microsoft\MSSMGR#LSTV
HKLM\SOFTWARE\Microsoft\MSSMGR#Brnd
HKLM\SOFTWARE\Microsoft\MSSMGR#Rid
HKLM\SOFTWARE\Microsoft\MSSMGR#LID
HKLM\SOFTWARE\Microsoft\MSSMGR#SCLIST
HKLM\SOFTWARE\Microsoft\MSSMGR#SSLIST
HKLM\SOFTWARE\Microsoft\MSSMGR#BSTV
HKLM\SOFTWARE\Microsoft\MSSMGR#MSLIST
HKLM\SOFTWARE\Microsoft\MSSMGR#BPTV
HKLM\SOFTWARE\Microsoft\MSSMGR#PSTV
HKLM\SOFTWARE\Microsoft\MSSMGR#SSTV
C:\Programmer\Fælles filer\{6CC68356-0959-1030-1028-04022004002d}\services.dll
Adware.Toolbar888
C:\Programmer\Toolbar888\MyToolBar.#ll
C:\Programmer\Toolbar888
HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}
HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0
HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\0
HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\0\win32
HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\FLAGS
HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\HELPDIR
HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}
HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid
HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid32
HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib
HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib#Version
HKU\S-1-5-21-1715567821-1547161642-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}
Trojan.Malware
HKCR\MezziaCodec.Chl
HKCR\MezziaCodec.Chl\CLSID
Trojan.Freeprod
C:\Documents and Settings\Chris\Lokale indstillinger\Temp\win5E.tmp.exe
C:\Documents and Settings\Chris\Lokale indstillinger\Temporary Internet Files\Content.IE5\Y3K79YZI\wlzip32[1].exe
HJT :
Logfile of HijackThis v1.99.1
Scan saved at 10:33:30, on 03-09-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\DAEMON Tools\daemon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
C:\Programmer\Java\jre1.5.0_08\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\Steam\Steam.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Chris\Skrivebord\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {7C98E35B-5DFA-4B59-85A6-BE5918F88C57} - (no file)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmer\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Programmer\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: winzms32 - winzms32.dll (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
På forhånd tak
