Avatar billede george Nybegynder
07. februar 2007 - 20:43 Der er 22 kommentarer og
2 løsninger

Er jeg en del af et botnet ?

Hej,

Hvordan checker jeg om jeg er en del af en botnet ?
Avatar billede george Nybegynder
07. februar 2007 - 20:53 #1
Findes der nogen specielle værktøjer til at finde ud af det ?
Avatar billede fromsej Praktikant
07. februar 2007 - 20:58 #2
Hent dette værktøj, og gem det på dit skrivebord: http://www.uploads.ejvindh.net/rootchk.exe

Følg så vejledningen i denne artikel:
http://www.eksperten.dk/artikler/954

Slut af med dette:
Kør programmet rootchk.exe som du gemte på skrivebordet. Efter kort tid vil der dukke en logfil op, som kan findes her C:\rootlog txt. Kopier indholdet af denne log ind i tråden sammen med SaS loggen og hijackthis loggen.
NB: Filen "rootchk exe" bliver af visse antivirus-programmer identificeret som "Trojan". Det har dog ikke noget på sig!
Avatar billede george Nybegynder
09. februar 2007 - 19:25 #3
Så lykkedes det endeligt.

Log fil fra DrWeb:
Dc4.htm    C:\RECYCLER\S-1-5-21-2848382773-3542333892-2726771382-1703    Trojan.AppActXComp    Deleted.
SuperScan4.exe    C:\RECYCLER\S-1-5-21-2848382773-3542333892-2726771382-1703\Dc5    Program.SuperScan    Renamed.
A0045078.exe    C:\System Volume Information\_restore{13394417-0BB8-45EE-84DF-4C5F3F9A3D66}\RP356    Program.SuperScan    Renamed.
A0049402.exe    C:\System Volume Information\_restore{13394417-0BB8-45EE-84DF-4C5F3F9A3D66}\RP374    Tool.ASEye.2    Renamed.
A0049408.exe    C:\System Volume Information\_restore{13394417-0BB8-45EE-84DF-4C5F3F9A3D66}\RP374    Trojan.DownLoader.9414    Deleted.
A0049424.exe    C:\System Volume Information\_restore{13394417-0BB8-45EE-84DF-4C5F3F9A3D66}\RP375    Program.SuperScan    Renamed.

Log fil fra SUPERAntiSpyware :
SUPERAntiSpyware Scan Log
Generated 02/09/2007 at 06:53 PM

Application Version : 3.5.1016

Core Rules Database Version : 3181
Trace Rules Database Version: 1191

Scan type      : Complete Scan
Total Scan Time : 01:24:44

Memory items scanned      : 221
Memory threats detected  : 0
Registry items scanned    : 8179
Registry threats detected : 0
File items scanned        : 67173
File threats detected    : 139

Adware.Tracking Cookie
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@indextools[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@gostats[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@cgi-bin[4].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@hotlog[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@cgi-bin[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@adfair[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@anad.tacoda[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@adv.surinter[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@xiti[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@www.burstnet[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@edge.ru4[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@www.wareznext[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@postclicktracking[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@7895639[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@www.masternewmedia[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@kanoodle[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@25103381[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@ad[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@stat.postdanmark[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@nextag[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@bannere.fyens[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@top[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@dist.belnk[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@adtech[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@adlegend[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@adopt.euroclick[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@ad1.clickhype[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@msnportal.112.2o7[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@adbrite[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@usenext[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@serving-sys[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@stats[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@belnk[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@revsci[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@mb[4].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@track.adform[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@ad1.emediate[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@roiservice[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@partner2profit[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@masternewmedia[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@www.crackedproductions[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@mediaworkers[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@v7.stats.load[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@1066129734[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@e2.emediate[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@123stat[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@82763522[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@ads.estart[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@cgi-bin[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@image.masterstats[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@overture[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@1069196813[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@www.drivecleaner[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@tacoda[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@tracking.dc-storm[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@ad.zanox[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@usenext[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@dk.drivecleaner[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@burstnet[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@toplist[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@worldlingomedia[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@99[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@1071214352[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@mb[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@1071933964[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@mywebsearch[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@www.infinitewarez[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@vww.kanoodle[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@1070926688[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@ads2.jubii[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@ads.addynamix[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@1068788019[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@azjmp[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@www.bestcrackz.altervista[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@yadro[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@hugetoplist[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@as1.falkag[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@drivecleaner[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@adsrevenue[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@hypertracker[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@itxt.vibrantmedia[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@qnsr[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@alladultchannel[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@ilead.itrack[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@click.cybertvpartner[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@1071967725[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@easywarez[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@stat.katalysatormedia[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@hostedctr[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@cgi-bin[3].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@tribalfusion[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@clicksor[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@episode-sevenfive[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@toplist[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@www.adbrite[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@1071890404[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@91632676[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@1071843236[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@1071933170[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@xxxcounter[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@mb[3].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@1068632727[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@bs.serving-sys[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@1071904028[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@10599399[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@1069384766[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@data2.perf.overture[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@questionmarket[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@clicktoconvert[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@paycounter[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@ncom.banneradministration[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@1072009599[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@1070958424[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@1071898435[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@46679520[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@rambler[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@top[3].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@6425137[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@1065236812[2].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@1071917915[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@trackalyzer[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@1071400441[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@1069241586[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@88871126[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@r-kimedia.co[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@adsense[1].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@adsense[3].txt
    C:\Documents and Settings\smedbjki\Cookies\smedbjki@stats[2].txt

Log fil fra Rootchk :
********************************* ROOTCHK-LOG, by ejvindh
09-02-2007 19:09:28,61

Driver-II NPF is present. A rootkit scan is recommended.

********************************* ROOTCHK-LOG-end

Log fil fra HijackThis:
Logfile of HijackThis v1.99.1
Scan saved at 19:10:55, on 09-02-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\AccessManager\Client\AMBroker.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\AccessManager\Client\sygman.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\Exchsrvr\bin\exmgmt.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\SYMANT~2\VPTray.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\DownloadStudio\DownloadStudioScheduleMonitor.exe
C:\WINDOWS\system32\cfpsys.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\lycos\Lyc_SysTray.exe
C:\Program Files\ClipX\clipx.exe
C:\WINDOWS\system32\lxcrcoms.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\MedalFolders\MedalFolders.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\!!!1\hijackthis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.1.30.34:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = intranet.royalscandinavia.com;195.51.205.174;www.royalscandinavia.com;<local>
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Værktøjslinje - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: Lexico Toolbar - {11359F4A-B191-42d7-905A-594F8CF0387B} - C:\WINDOWS\Downloaded Program Files\CONFLICT.1\lexbar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: IeMonitor - {8170D7DC-BDD6-461e-88EB-F047257898C9} - C:\Program Files\DownloadStudio\DLMonitr.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Lexmark Værktøjslinje - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: &DownloadStudio - {CB789373-04D5-4ef4-9C16-871463FD0830} - C:\Program Files\DownloadStudio\WebDLBar.dll
O3 - Toolbar: Dictionary.com - {11359F4A-B191-42D7-905A-594F8CF0387B} - C:\WINDOWS\Downloaded Program Files\CONFLICT.1\lexbar.dll
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [DownloadStudio] C:\Program Files\DownloadStudio\DownloadStudioScheduleMonitor.exe
O4 - HKLM\..\Run: [Warning: do not remove it! (system)] cfpsys.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [lycosInside] C:\Program Files\lycos\Lyc_SysTray.exe
O4 - HKCU\..\Run: [clipx] C:\Program Files\ClipX\clipx.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: MedalFolders.lnk = C:\Program Files\MedalFolders\MedalFolders.exe
O4 - Startup: Shortcut to Alert32.exe.lnk = C:\Program Files\HEAT\Alert32.exe
O4 - Startup: Shortcut to CallLog32.exe.lnk = C:\Program Files\HEAT\CallLog32.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Add Page To DownloadStudio Scrapbook... - C:\Program Files\DownloadStudio\ds_snap.htm
O8 - Extra context menu item: Download Image Using DownloadStudio... - C:\Program Files\DownloadStudio\ds_img.htm
O8 - Extra context menu item: Download Page Using DownloadStudio... - C:\Program Files\DownloadStudio\ds_all.htm
O8 - Extra context menu item: Download Selection Using DownloadStudio... - C:\Program Files\DownloadStudio\ds_sel.htm
O8 - Extra context menu item: Download Target Using DownloadStudio... - C:\Program Files\DownloadStudio\ds_file.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Search &Dictionary - C:\Program files\Lexico\Toolbar\dictionary.htm
O8 - Extra context menu item: Search &Thesaurus - C:\Program files\Lexico\Toolbar\thesaurus.htm
O8 - Extra context menu item: Show Page Links Using DownloadStudio... - C:\Program Files\DownloadStudio\ds_link.htm
O8 - Extra context menu item: Subscribe To RSS Feed... - C:\Program Files\DownloadStudio\ds_rss.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: (no name) - {4D0C4820-53F7-4d79-A2E1-5252683CF69C} - C:\Program Files\DownloadStudio\DownloadStudio.exe
O9 - Extra 'Tools' menuitem: &DownloadStudio - {4D0C4820-53F7-4d79-A2E1-5252683CF69C} - C:\Program Files\DownloadStudio\DownloadStudio.exe
O9 - Extra button: DownloadStudio - {7FCA7BD7-8F4D-4a81-BE72-A470F4E517D5} - C:\Program Files\DownloadStudio\WebDLBar.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
O15 - Trusted Zone: http://www.xigla.com
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlmanager.akamaitools.com.edgesuite.net/dlmanager/versions/activex/dlm-activex-2.0.5.1.cab
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KX-HCM10 Control) - http://219.166.247.165/kxhcm10.ocx
O16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) - https://netbank.bgbank.dk/html/activex/BG/Menu.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com/ActiveX/VMRCActiveXClient1.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://johnnykristiansen.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1146043135658
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1150136927197
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - http://www-307.ibm.com/pc/support/IbmEgath.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f010.mail.jubii.dk/app/uploader/FileUploader.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://opdatering.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D30CA0FD-1CA0-11D4-AC78-006008A9A8BC} (WebBasedClientInstall Class) - file://D:\Rollout\AVServer\CLIENTS\WEBINST\webinst.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.bgbank.dk/html/activex/e-Safekey/BG/e-Safekey.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://dwtools.dynamicsystems.dk/XUpload.ocx
O16 - DPF: {F0E2D69A-DC2F-4E9B-A993-684FB1C21DBC} - http://dictionary.reference.com/tools/toolbar/lexico.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: psfus - C:\WINDOWS\SYSTEM32\psqlpwd.dll
O20 - Winlogon Notify: tpfnf2 - C:\WINDOWS\SYSTEM32\notifyf2.dll
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Access Manager Configuration Service (AMBroker) - MCI, Inc. - C:\Program Files\AccessManager\Client\AMBroker.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Visual Insight DA Plugin (DAPlugin) - MCI, Inc. - C:\Program Files\AccessManager\Client\DAPlugin.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\IP VPN Remote Services\Extranet_serv.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: lxcr_device -  - C:\WINDOWS\system32\lxcrcoms.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SP Software Installer - Smartpipes, Inc. - C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Visual Insight Dial Analysis (sp_spi_da) - Smartpipes, Inc. - C:\Program Files\AccessManager\SMOC\spi_da.exe
O23 - Service: System Update (SUService) -  - c:\program files\lenovo\system update\suservice.exe
O23 - Service: SSA Integration Manager (Sygman) - MCI, Inc. - C:\Program Files\AccessManager\Client\sygman.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe

Det var vist det hele.
Avatar billede fromsej Praktikant
10. februar 2007 - 11:48 #4
Der er et Rootkit til stede, nu er valget dit.
Vi kan måske fjerne det, sandsynligheden ligger på omkring 95%. for at det lykkes.
Det kan tage rigtig lang tid, måske uger, alt efter både din og vores responstid.
Så enten kører vi proceduren, eller også bider du i det sure æble og formaterer maskinen.

Hent dette værktøj fra følgende link, og gem det på skrivebordet:
http://www.uploads.ejvindh.net/rustbfix.exe

Dobbeltklik på værktøjet. Hvis værktøjet finder en Rustock-infektion, vil du efter kort tid blive bedt om at genstarte computeren. Dette skal du så acceptere. Genstarten vil muligvis tage et godt stykke tid, og måske skal der 2 genstarter til, men dette vil ske helt automatisk. Når genstarten er færdig vil der åbnes 2 logfiler (%root%\avenger.txt & %root%\rustbfix\pelog.txt), som du skal kopiere ind i tråden.
Avatar billede haverslev Novice
10. februar 2007 - 12:33 #5
fromsej, har du et par minutter ?: http://www.eksperten.dk/spm/761611
Avatar billede ejvindh Ekspert
11. februar 2007 - 00:57 #6
Oplysninger på infektionen kan ses her:
http://www.sophos.com/virusinfo/analyses/trojntrootki.html
http://vil.nai.com/vil/content/v_100252.htm

Som du kan se, så ER du en del af et spambot-netværk. Hvis du vil have det fjernet, kan du lige melde tilbage. Så vil jeg prøve at hjælpe dig videre. Men som Fromsej skriver, så kan det godt tage et par omgange at få computeren ren. Så en formatering er muligvis hurtigere.
Avatar billede george Nybegynder
11. februar 2007 - 19:04 #7
Vi kører proceduren. Jeg prøver at hente værktøjet som du (fromsej) forslår. Jeg er ikke meget for at skulle til at reinstallerer lige nu.

ejvindh : Jeg har prøvet at kigge på de to link to har skrevet og kan se at der er tale om "Troj/NtRootK-I" og "BackDoor-ASW". Jeg har prøvet at lave en søgning gennem alle logfilerne og den finder intet. Hvor er det i kan se at jeg er en del af et botnet. Jeg vil jo også gerne lærer lidt af dette her :-)
Avatar billede george Nybegynder
11. februar 2007 - 19:39 #8
Den vendte tilbage med dette.

************************* Rustock.b-fix -- By ejvindh *************************
11-02-2007 19:39:03,40

No Rustock.b-rootkits found

******************************* End of Logfile ********************************
Avatar billede george Nybegynder
11. februar 2007 - 20:07 #9
Ok, efter nærmere læsning af specielt "Troj/NtRootK-I" og hvordan den skal fjernes faldt 10-øren, "så kører vi proceduren". He he ;-)

Og så er der lige "BackDoor-ASW" som jeg også lige fik nærlæst.

Der er lidt at gå i gang med, men der er ingen vej udenom, jeg må i gang.

2 spørgsmål :
1. Hvorfår fandt rustfix.exe ingenting ?
2. Hvor ser i Rootkit'et og Bagdøren i log filerne ?
Avatar billede ejvindh Ekspert
11. februar 2007 - 22:53 #10
-- Hent Avenger her:
http://swandog46.geekstogo.com/avenger.zip

-- Pak Avenger-programmet ud og dobbeltklik på avenger.exe

-- Sæt en prik i "Input Script Manually" og klik på Luppen - nu dukker der et lille vindue op, hvor du skal kopiere indholdet mellem de stiplede linier ind:

-----------------------------
Files to delete:
c:\windows\system32\RtKit\Rtkit.exe
c:\windows\system32\RtKit\globalc.dll
c:\windows\system32\RtKit\npf.sys
c:\windows\system32\RtKit\ntcs.dll
c:\windows\system32\RtKit\packet.dll
c:\windows\system32\RtKit\rtkit.log

Folders to Delete:
c:\windows\system32\RtKit

registry keys to delete:
HKLM\SOFTWARE\rtkit

drivers to unload:
RtKit
NPF
-----------------------------

-- Klik på Trafiklyset i Avenger. Programmet vil opfordre dig til at genstarte computeren straks, hvilket du skal gøre. Programmet vil lukke din computer, slette filerne og starte computeren igen.

-- Efter genstarten vil der dukke et notepad-vindue op, med en log for Avengers handlinger. Den må du gerne lægge ind i dit næste svar.

-- Kør Hijackthis, vælg "Do a system scan only", sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked.

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O15 - Trusted Zone: http://www.xigla.com

-- Genstart computeren, og lav en ny log med Hijackthis, som du lægger herind sammen med loggen fra Avenger

-- Lav også en ny log med rootchk, som du lægger herind til check.
Avatar billede ejvindh Ekspert
11. februar 2007 - 22:54 #11
Til dine spørgsmål: Rustbfix finder ikke infektionen, da den egentlig sigter mod et andet rootkit. Og vi fandt dit rootkit i rootchk-loggen ;-)
Avatar billede george Nybegynder
12. februar 2007 - 18:52 #12
Avenger log:
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\fenqpjns

*******************

Script file located at: \??\C:\WINDOWS\system32\krsjdoiq.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



Could not open file c:\windows\system32\RtKit\Rtkit.exe for deletion
Deletion of file c:\windows\system32\RtKit\Rtkit.exe failed!

Could not process line:
c:\windows\system32\RtKit\Rtkit.exe
Status: 0xc000003a



Could not open file c:\windows\system32\RtKit\globalc.dll for deletion
Deletion of file c:\windows\system32\RtKit\globalc.dll failed!

Could not process line:
c:\windows\system32\RtKit\globalc.dll
Status: 0xc000003a



Could not open file c:\windows\system32\RtKit\npf.sys for deletion
Deletion of file c:\windows\system32\RtKit\npf.sys failed!

Could not process line:
c:\windows\system32\RtKit\npf.sys
Status: 0xc000003a



Could not open file c:\windows\system32\RtKit\ntcs.dll for deletion
Deletion of file c:\windows\system32\RtKit\ntcs.dll failed!

Could not process line:
c:\windows\system32\RtKit\ntcs.dll
Status: 0xc000003a



Could not open file c:\windows\system32\RtKit\packet.dll for deletion
Deletion of file c:\windows\system32\RtKit\packet.dll failed!

Could not process line:
c:\windows\system32\RtKit\packet.dll
Status: 0xc000003a



Could not open file c:\windows\system32\RtKit\rtkit.log for deletion
Deletion of file c:\windows\system32\RtKit\rtkit.log failed!

Could not process line:
c:\windows\system32\RtKit\rtkit.log
Status: 0xc000003a



Folder c:\windows\system32\RtKit not found!
Deletion of folder c:\windows\system32\RtKit failed!

Could not process line:
c:\windows\system32\RtKit
Status: 0xc0000034



Registry key \Registry\Machine\System\CurrentControlSet\Services\RtKit not found!
Unload of driver RtKit failed!

Could not process line:
RtKit
Status: 0xc0000034



Registry key \Registry\Machine\System\CurrentControlSet\Services\NPF not found!
Unload of driver NPF failed!

Could not process line:
NPF
Status: 0xc0000034



Registry key HKLM\SOFTWARE\rtkit not found!
Deletion of registry key HKLM\SOFTWARE\rtkit failed!
Status: 0xc0000034


Completed script processing.

*******************

Finished!  Terminate.


HijackThis log file:

Logfile of HijackThis v1.99.1
Scan saved at 18:47:44, on 12-02-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\AccessManager\Client\AMBroker.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\AccessManager\Client\sygman.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\Exchsrvr\bin\exmgmt.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\SYMANT~2\VPTray.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\DownloadStudio\DownloadStudioScheduleMonitor.exe
C:\WINDOWS\system32\cfpsys.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DoScan.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\lxcrcoms.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\lycos\Lyc_SysTray.exe
C:\Program Files\ClipX\clipx.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\MedalFolders\MedalFolders.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\!!!1\hijackthis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.1.30.34:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = intranet.royalscandinavia.com;195.51.205.174;www.royalscandinavia.com;<local>
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Værktøjslinje - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: Lexico Toolbar - {11359F4A-B191-42d7-905A-594F8CF0387B} - C:\WINDOWS\Downloaded Program Files\CONFLICT.1\lexbar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: IeMonitor - {8170D7DC-BDD6-461e-88EB-F047257898C9} - C:\Program Files\DownloadStudio\DLMonitr.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Lexmark Værktøjslinje - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: &DownloadStudio - {CB789373-04D5-4ef4-9C16-871463FD0830} - C:\Program Files\DownloadStudio\WebDLBar.dll
O3 - Toolbar: Dictionary.com - {11359F4A-B191-42D7-905A-594F8CF0387B} - C:\WINDOWS\Downloaded Program Files\CONFLICT.1\lexbar.dll
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [DownloadStudio] C:\Program Files\DownloadStudio\DownloadStudioScheduleMonitor.exe
O4 - HKLM\..\Run: [Warning: do not remove it! (system)] cfpsys.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [lycosInside] C:\Program Files\lycos\Lyc_SysTray.exe
O4 - HKCU\..\Run: [clipx] C:\Program Files\ClipX\clipx.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: MedalFolders.lnk = C:\Program Files\MedalFolders\MedalFolders.exe
O4 - Startup: Shortcut to Alert32.exe.lnk = C:\Program Files\HEAT\Alert32.exe
O4 - Startup: Shortcut to CallLog32.exe.lnk = C:\Program Files\HEAT\CallLog32.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Add Page To DownloadStudio Scrapbook... - C:\Program Files\DownloadStudio\ds_snap.htm
O8 - Extra context menu item: Download Image Using DownloadStudio... - C:\Program Files\DownloadStudio\ds_img.htm
O8 - Extra context menu item: Download Page Using DownloadStudio... - C:\Program Files\DownloadStudio\ds_all.htm
O8 - Extra context menu item: Download Selection Using DownloadStudio... - C:\Program Files\DownloadStudio\ds_sel.htm
O8 - Extra context menu item: Download Target Using DownloadStudio... - C:\Program Files\DownloadStudio\ds_file.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Search &Dictionary - C:\Program files\Lexico\Toolbar\dictionary.htm
O8 - Extra context menu item: Search &Thesaurus - C:\Program files\Lexico\Toolbar\thesaurus.htm
O8 - Extra context menu item: Show Page Links Using DownloadStudio... - C:\Program Files\DownloadStudio\ds_link.htm
O8 - Extra context menu item: Subscribe To RSS Feed... - C:\Program Files\DownloadStudio\ds_rss.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: (no name) - {4D0C4820-53F7-4d79-A2E1-5252683CF69C} - C:\Program Files\DownloadStudio\DownloadStudio.exe
O9 - Extra 'Tools' menuitem: &DownloadStudio - {4D0C4820-53F7-4d79-A2E1-5252683CF69C} - C:\Program Files\DownloadStudio\DownloadStudio.exe
O9 - Extra button: DownloadStudio - {7FCA7BD7-8F4D-4a81-BE72-A470F4E517D5} - C:\Program Files\DownloadStudio\WebDLBar.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlmanager.akamaitools.com.edgesuite.net/dlmanager/versions/activex/dlm-activex-2.0.5.1.cab
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KX-HCM10 Control) - http://219.166.247.165/kxhcm10.ocx
O16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) - https://netbank.bgbank.dk/html/activex/BG/Menu.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com/ActiveX/VMRCActiveXClient1.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://johnnykristiansen.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1146043135658
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1150136927197
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - http://www-307.ibm.com/pc/support/IbmEgath.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9393AF10-1A0E-4F10-B32B-E57CB4543F49} (Croom3_40 Object) - http://launcher.room-3.com/room3_40/room3_40.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f010.mail.jubii.dk/app/uploader/FileUploader.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://opdatering.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D30CA0FD-1CA0-11D4-AC78-006008A9A8BC} (WebBasedClientInstall Class) - file://D:\Rollout\AVServer\CLIENTS\WEBINST\webinst.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.bgbank.dk/html/activex/e-Safekey/BG/e-Safekey.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://dwtools.dynamicsystems.dk/XUpload.ocx
O16 - DPF: {F0E2D69A-DC2F-4E9B-A993-684FB1C21DBC} - http://dictionary.reference.com/tools/toolbar/lexico.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: psfus - C:\WINDOWS\SYSTEM32\psqlpwd.dll
O20 - Winlogon Notify: tpfnf2 - C:\WINDOWS\SYSTEM32\notifyf2.dll
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Access Manager Configuration Service (AMBroker) - MCI, Inc. - C:\Program Files\AccessManager\Client\AMBroker.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Visual Insight DA Plugin (DAPlugin) - MCI, Inc. - C:\Program Files\AccessManager\Client\DAPlugin.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\IP VPN Remote Services\Extranet_serv.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: lxcr_device -  - C:\WINDOWS\system32\lxcrcoms.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SP Software Installer - Smartpipes, Inc. - C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Visual Insight Dial Analysis (sp_spi_da) - Smartpipes, Inc. - C:\Program Files\AccessManager\SMOC\spi_da.exe
O23 - Service: System Update (SUService) -  - c:\program files\lenovo\system update\suservice.exe
O23 - Service: SSA Integration Manager (Sygman) - MCI, Inc. - C:\Program Files\AccessManager\Client\sygman.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe



********************************* ROOTCHK-LOG, by ejvindh
12-02-2007 18:48:43,42

The rootkits that are detected by this tool were not found.

********************************* ROOTCHK-LOG-end
Avatar billede ejvindh Ekspert
12. februar 2007 - 19:38 #13
Den gode nyhed er, at nu er logsene rene. Det lidt forvirrende nyhed er, at tilsyneladende fandt Avenger ikke nogle af de ting, som burde ligge der. En mulig forklaring på dette kan være, hvis du kørte Avenger-delen 2 gange, og loggen stammer fra sidste kørsel. Er dette tilfældet?

Hvis det ikke er tilfældet, synes jeg at du skal køre et par ekstra check, for at være helt sikker på, at skidtet faktisk er væk:

-- Download Rootkit Unhooker herfra:
http://rku.xell.ru/?l=e&a=dl
Installér programmet. Kør så RKU. Klik på Setup-"Extended mode". Du vil så blive bedt om at genstarte, hvilket du skal gøre. Kør så Rootkit Unhooker igen, klik på fanebladet "Report", klik på knappen "Scan". Lad programmet skanne færdig, klik på "File-Save Report", og gem rapporten et sted, hvor du kan finde den igen. Læg indholdet af denne rapport herind.

-- Download Gmer-rootkit scanner, og pak den ud til skrivebordet:
http://www.young-andersen.dk/gamer/gamer.zip
Start med at omdøbe programmet gmer.exe (fx til abc.exe). Kør programmet, klik på fanebladet "Rootkit", og klik på "Scan". Imens der scannes, er det vigtigt at du ikke bruger computeren til andre ting. Når scanningen er færdig, skal du klikke på "Copy". Så dukker et vindue op, som fortæller at resultatet af rootkit-scanningen er blevet lagt ind i udklipsholderen. Du kan herefter gå ind i denne tråd, og kopiere indholdet herind, ved at stille dig i indtastningsfeltet, og trykke ctrl-v.
Avatar billede george Nybegynder
12. februar 2007 - 21:29 #14
Nej jeg kørte kun Avenger én gang. Jeg prøver lige de to du foreslår.
Avatar billede george Nybegynder
13. februar 2007 - 17:09 #15
Jeg kørte Unhooker i aftes og nat, men her til morgen var der opstået en fejl i programmet, så nu bliver jeg nødt til at kører den igen. Det tager lidt tid...
Avatar billede george Nybegynder
13. februar 2007 - 19:45 #16
Unhooker kører desværre ikke så godt på min computer. Den lavede fejl igen.

Fejlen den kommer med er :
Sorry, but unhandled exceptions has occured Program will be terminated o.s.v.

Her er log filen fra GMER:
GMER 1.0.12.12011 - http://www.gmer.net
Rootkit scan 2007-02-13 19:20:55
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.12 ----

SSDT    82D2CFA8                                                                                                                                                                                                                                                                                                                                                                  ZwAlertResumeThread
SSDT    82D2E138                                                                                                                                                                                                                                                                                                                                                                  ZwAlertThread
SSDT    82BC0730                                                                                                                                                                                                                                                                                                                                                                  ZwAllocateVirtualMemory
SSDT    82C184D8                                                                                                                                                                                                                                                                                                                                                                  ZwConnectPort
SSDT    82CF00D8                                                                                                                                                                                                                                                                                                                                                                  ZwCreateMutant
SSDT    82BB2338                                                                                                                                                                                                                                                                                                                                                                  ZwCreateThread
SSDT    \??\C:\Program Files\Symantec\SYMEVENT.SYS                                                                                                                                                                                                                                                                                                                                ZwDeleteValueKey
SSDT    IPVNMon.sys                                                                                                                                                                                                                                                                                                                                                                ZwDeviceIoControlFile
SSDT    82CD4708                                                                                                                                                                                                                                                                                                                                                                  ZwFreeVirtualMemory
SSDT    82D28B68                                                                                                                                                                                                                                                                                                                                                                  ZwImpersonateAnonymousToken
SSDT    82D6D108                                                                                                                                                                                                                                                                                                                                                                  ZwImpersonateThread
SSDT    82EE0198                                                                                                                                                                                                                                                                                                                                                                  ZwMapViewOfSection
SSDT    82C97EF8                                                                                                                                                                                                                                                                                                                                                                  ZwOpenEvent
SSDT    \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys                                                                                                                                                                                                                                                                                                                ZwOpenProcess
SSDT    82E7D880                                                                                                                                                                                                                                                                                                                                                                  ZwOpenProcessToken
SSDT    82EEB768                                                                                                                                                                                                                                                                                                                                                                  ZwOpenThreadToken
SSDT    82E42230                                                                                                                                                                                                                                                                                                                                                                  ZwQueryValueKey
SSDT    82CD3EE0                                                                                                                                                                                                                                                                                                                                                                  ZwResumeThread
SSDT    82D2D768                                                                                                                                                                                                                                                                                                                                                                  ZwSetContextThread
SSDT    82CA7960                                                                                                                                                                                                                                                                                                                                                                  ZwSetInformationProcess
SSDT    82E1EEB0                                                                                                                                                                                                                                                                                                                                                                  ZwSetInformationThread
SSDT    \??\C:\Program Files\Symantec\SYMEVENT.SYS                                                                                                                                                                                                                                                                                                                                ZwSetValueKey
SSDT    82DF5398                                                                                                                                                                                                                                                                                                                                                                  ZwSuspendProcess
SSDT    82D32640                                                                                                                                                                                                                                                                                                                                                                  ZwSuspendThread
SSDT    \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys                                                                                                                                                                                                                                                                                                                ZwTerminateProcess
SSDT    82D2CBC8                                                                                                                                                                                                                                                                                                                                                                  ZwTerminateThread
SSDT    82D25118                                                                                                                                                                                                                                                                                                                                                                  ZwUnmapViewOfSection
SSDT    82BCB3B0                                                                                                                                                                                                                                                                                                                                                                  ZwWriteVirtualMemory

---- Kernel code sections - GMER 1.0.12 ----

PAGE    ntoskrnl.exe!NtOpenThread + 6                                                                                                                                                                                                                                                                                                                                              8058897A 4 Bytes  [ D4, 02, 47, 78 ]

---- Devices - GMER 1.0.12 ----

Device  \Driver\usbhub \Device\000000aa IRP_MJ_PNP                                                                                                                                                                                                                                                                                                                                [F0C91600] hcmon.sys
Device  \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL                                                                                                                                                                                                                                                                                                            [F0C92010] hcmon.sys
Device  \Driver\usbhub \Device\000000ab IRP_MJ_PNP                                                                                                                                                                                                                                                                                                                                [F0C91600] hcmon.sys
Device  \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL                                                                                                                                                                                                                                                                                                            [F0C92010] hcmon.sys
Device  \Driver\usbhub \Device\000000ac IRP_MJ_PNP                                                                                                                                                                                                                                                                                                                                [F0C91600] hcmon.sys
Device  \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL                                                                                                                                                                                                                                                                                                            [F0C92010] hcmon.sys
Device  \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL                                                                                                                                                                                                                                                                                                            [F0C92010] hcmon.sys
Device  \Driver\usbhub \Device\000000ae IRP_MJ_PNP                                                                                                                                                                                                                                                                                                                                [F0C91600] hcmon.sys
Device  \Driver\usbehci \Device\USBFDO-4 IRP_MJ_INTERNAL_DEVICE_CONTROL                                                                                                                                                                                                                                                                                                            [F0C923F0] hcmon.sys

---- Files - GMER 1.0.12 ----

ADS    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\georgebaker@hotmail.com\SharingMetadata\teresalaihk@hotmail.com\DFSR\Staging\CS{E955220D-0F46-33B7-7180-113C7AE17BE9}\01\10-{E955220D-0F46-33B7-7180-113C7AE17BE9}-v1-{C32AC1FE-FDCD-4FFD-BF56-E61511878723}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 
ADS    C:\Documents and Settings\All Users\Application Data\TEMP:4B7BEAFF                                                                                                                                                                                                                                                                                                       
ADS    C:\Documents and Settings\smedbjki\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf:_SummaryInformation                                                                                                                                                                                                                                         
ADS    C:\Documents and Settings\smedbjki\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}                                                                                                                                                                                                                     
ADS    C:\Documents and Settings\smedbjki\Local Settings\Application Data\Microsoft\Messenger\georgebaker@hotmail.com\SharingMetadata\malu_tins@hotmail.com\DFSR\Staging\CS{B37B9C1A-687F-669D-6402-6BEBFEC58A25}\01\12-{B37B9C1A-687F-669D-6402-6BEBFEC58A25}-v1-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS       
ADS    C:\Documents and Settings\smedbjki\Local Settings\Application Data\Microsoft\Messenger\georgebaker@hotmail.com\SharingMetadata\malu_tins@hotmail.com\DFSR\Staging\CS{B37B9C1A-687F-669D-6402-6BEBFEC58A25}\13\13-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v13-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1       
ADS    C:\Documents and Settings\smedbjki\Local Settings\Application Data\Microsoft\Messenger\georgebaker@hotmail.com\SharingMetadata\malu_tins@hotmail.com\DFSR\Staging\CS{B37B9C1A-687F-669D-6402-6BEBFEC58A25}\13\13-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v13-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2       
ADS    C:\Documents and Settings\smedbjki\Local Settings\Application Data\Microsoft\Messenger\georgebaker@hotmail.com\SharingMetadata\malu_tins@hotmail.com\DFSR\Staging\CS{B37B9C1A-687F-669D-6402-6BEBFEC58A25}\13\13-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v13-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.3       
ADS    C:\Documents and Settings\smedbjki\Local Settings\Application Data\Microsoft\Messenger\georgebaker@hotmail.com\SharingMetadata\malu_tins@hotmail.com\DFSR\Staging\CS{B37B9C1A-687F-669D-6402-6BEBFEC58A25}\13\13-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v13-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.4       
ADS    C:\Documents and Settings\smedbjki\Local Settings\Application Data\Microsoft\Messenger\georgebaker@hotmail.com\SharingMetadata\malu_tins@hotmail.com\DFSR\Staging\CS{B37B9C1A-687F-669D-6402-6BEBFEC58A25}\13\13-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v13-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS       
ADS    C:\Documents and Settings\smedbjki\Local Settings\Application Data\Microsoft\Messenger\georgebaker@hotmail.com\SharingMetadata\teresalaihk@hotmail.com\DFSR\Staging\CS{E955220D-0F46-33B7-7180-113C7AE17BE9}\01\10-{E955220D-0F46-33B7-7180-113C7AE17BE9}-v1-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS     
ADS    C:\Documents and Settings\smedbjki\Local Settings\Application Data\Microsoft\Messenger\georgebaker@hotmail.com\SharingMetadata\teresalaihk@hotmail.com\DFSR\Staging\CS{E955220D-0F46-33B7-7180-113C7AE17BE9}\11\11-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v11-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1     
ADS    C:\Documents and Settings\smedbjki\Local Settings\Application Data\Microsoft\Messenger\georgebaker@hotmail.com\SharingMetadata\teresalaihk@hotmail.com\DFSR\Staging\CS{E955220D-0F46-33B7-7180-113C7AE17BE9}\11\11-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v11-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2     
ADS    C:\Documents and Settings\smedbjki\Local Settings\Application Data\Microsoft\Messenger\georgebaker@hotmail.com\SharingMetadata\teresalaihk@hotmail.com\DFSR\Staging\CS{E955220D-0F46-33B7-7180-113C7AE17BE9}\11\11-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v11-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.3     
ADS    C:\Documents and Settings\smedbjki\Local Settings\Application Data\Microsoft\Messenger\georgebaker@hotmail.com\SharingMetadata\teresalaihk@hotmail.com\DFSR\Staging\CS{E955220D-0F46-33B7-7180-113C7AE17BE9}\11\11-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v11-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.4     
ADS    C:\Documents and Settings\smedbjki\Local Settings\Application Data\Microsoft\Messenger\georgebaker@hotmail.com\SharingMetadata\teresalaihk@hotmail.com\DFSR\Staging\CS{E955220D-0F46-33B7-7180-113C7AE17BE9}\11\11-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v11-{C93F6057-1E23-4EED-BBD7-604EE50E8727}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS     

---- EOF - GMER 1.0.12 ----
Avatar billede ejvindh Ekspert
13. februar 2007 - 22:03 #17
Ok, vi klarer os med Gmer-loggen så. Den er ren, og jeg tror derfor roligt vi kan konkludere, at der ikke er flere rootkits på din computer. Hvordan kører computeren ellers?
Avatar billede ejvindh Ekspert
13. februar 2007 - 22:50 #18
Jeg har nu været ved at søge lidt yderligere op på den driver, som vi fandt, og det viser sig ikke at være et rootkit, men en driver fra Winpcap. Så du har tilsyneladende ikke været en del af et botnet alligevel. Jeg beklager vildledningen.
Avatar billede george Nybegynder
15. februar 2007 - 15:57 #19
Ok tak for forklaring og maskinen kører fint. Skidt være med vildledningen, jeg har lært hvilke værktøjer jeg kan bruge hvis jeg har mistanke til nogen en anden gang.

Hvis du er interesseret i de sølle 30 point så send gerne et svar. Tak for din hjælp.
Avatar billede ejvindh Ekspert
15. februar 2007 - 16:03 #20
OK, det kommer da her. Vent med at acceptere til Fromsej også har lagt et svar. Han har trods alt hjulpet dig af med et par infektionsrester :-)
Avatar billede fromsej Praktikant
15. februar 2007 - 17:50 #21
Det kommer her.*S*
Avatar billede george Nybegynder
16. februar 2007 - 18:37 #22
Tak for hjælpen til jer begge to.
Avatar billede fromsej Praktikant
16. februar 2007 - 19:04 #23
Velbekomme, tak for point. :-)
Avatar billede ejvindh Ekspert
16. februar 2007 - 20:21 #24
Du er velkommen :-)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester