Avatar billede ds-zim Nybegynder
24. juli 2007 - 19:44 Der er 1 løsning

Kontrol af Log Filer - Summer2008.zip Infektion

Som læst i artiklen http://www.eksperten.dk/artikler/1123 er her dump af mine logfiler;
-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-
"Freaky" - 2007-07-24 19:33:13 - ComboFix 07-07-23.6 - Service Pack 2  NTFS 


(((((((((((((((((((((((((  Files Created from 2007-06-24 to 2007-07-24  )))))))))))))))))))))))))))))))


2007-07-24 19:32    51,200    --a------    C:\WINDOWS\nircmd.exe
2007-07-24 19:12    <DIR>    d--------    C:\Program Files\SUPERAntiSpyware
2007-07-24 19:12    <DIR>    d--------    C:\DOCUME~1\Freaky\APPLIC~1\SUPERAntiSpyware.com
2007-07-24 19:12    <DIR>    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-24 18:59    <DIR>    d--------    C:\Program Files\CCleaner1.41
2007-07-24 11:58    26,000    --a------    C:\WINDOWS\system32\firewallav.dll
2007-07-24 11:58    117,760    --a------    C:\WINDOWS\system32\printers.exe
2007-07-16 20:23    <DIR>    d--------    C:\DOCUME~1\Freaky\APPLIC~1\Leadertech
2007-07-16 20:04    <DIR>    d--hs----    C:\DOCUME~1\Freaky\Phone Browser
2007-07-14 19:01    <DIR>    d--------    C:\DOCUME~1\Freaky\APPLIC~1\teamspeak2
2007-07-12 09:40    22,328    --a------    C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-07-12 09:40    103,736    --a------    C:\WINDOWS\system32\PnkBstrB.exe
2007-07-12 09:28    81,768    --a------    C:\WINDOWS\system32\xinput1_3.dll
2007-07-12 09:28    62,744    --a------    C:\WINDOWS\system32\xinput1_2.dll
2007-07-12 09:28    443,752    --a------    C:\WINDOWS\system32\d3dx10_34.dll
2007-07-12 09:28    443,752    --a------    C:\WINDOWS\system32\d3dx10_33.dll
2007-07-12 09:28    3,497,832    --a------    C:\WINDOWS\system32\d3dx9_34.dll
2007-07-12 09:28    3,495,784    --a------    C:\WINDOWS\system32\d3dx9_33.dll
2007-07-12 09:28    266,088    --a------    C:\WINDOWS\system32\xactengine2_8.dll
2007-07-12 09:28    261,480    --a------    C:\WINDOWS\system32\xactengine2_7.dll
2007-07-12 09:28    255,848    --a------    C:\WINDOWS\system32\xactengine2_6.dll
2007-07-12 09:28    251,672    --a------    C:\WINDOWS\system32\xactengine2_5.dll
2007-07-12 09:28    237,848    --a------    C:\WINDOWS\system32\xactengine2_4.dll
2007-07-12 09:28    236,824    --a------    C:\WINDOWS\system32\xactengine2_3.dll
2007-07-12 09:28    2,414,360    --a------    C:\WINDOWS\system32\d3dx9_31.dll
2007-07-12 09:28    18,280    --a------    C:\WINDOWS\system32\x3daudio1_2.dll
2007-07-12 09:28    15,128    --a------    C:\WINDOWS\system32\x3daudio1_1.dll
2007-07-12 09:28    1,124,720    --a------    C:\WINDOWS\system32\D3DCompiler_34.dll
2007-07-12 09:28    1,123,696    --a------    C:\WINDOWS\system32\D3DCompiler_33.dll
2007-07-12 09:27    2,297,552    --a------    C:\WINDOWS\system32\d3dx9_26.dll
2007-07-12 09:27    <DIR>    d--------    C:\WINDOWS\system32\LogFiles
2007-07-12 09:26    <DIR>    d--------    C:\Enemy Territory - QUAKE Wars Beta
2007-06-27 22:24    <DIR>    d--------    C:\Program Files\Common Files\3DO Shared
2007-06-27 22:24    <DIR>    d--------    C:\Program Files\3DO
2007-06-27 22:23    306,688    --a------    C:\WINDOWS\IsUninst.exe
2007-06-24 12:49    <DIR>    d--------    C:\Program Files\Octoshape Streaming Services


((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-24 17:12:31    --------    d-----w    C:\Program Files\Common Files\Wise Installation Wizard
2007-07-24 01:14:02    --------    d-----w    C:\DOCUME~1\Freaky\APPLIC~1\Azureus
2007-07-16 18:04:59    --------    d-----w    C:\DOCUME~1\Freaky\APPLIC~1\Nokia
2007-07-12 07:27:40    --------    d--h--w    C:\Program Files\InstallShield Installation Information
2007-07-08 20:05:00    --------    d-----w    C:\DOCUME~1\Freaky\APPLIC~1\Skype
2007-07-02 05:24:51    --------    d-----w    C:\Program Files\TrackMania Nations ESWC
2007-06-22 12:16:07    --------    d-----w    C:\DOCUME~1\Freaky\APPLIC~1\SmartFTP
2007-06-22 12:16:02    --------    d-----w    C:\Program Files\SmartFTP Client
2007-06-20 14:07:32    --------    d-----w    C:\DOCUME~1\Freaky\APPLIC~1\Ventrilo
2007-06-19 07:40:40    --------    d-----w    C:\Program Files\MSN Messenger
2007-06-17 13:07:55    --------    d-----w    C:\Program Files\Common Files\DirectX
2007-06-17 12:08:52    --------    d-----w    C:\Program Files\Common Files\InstallShield
2007-06-16 16:32:48    21,840    ----atw    C:\WINDOWS\system32\SIntfNT.dll
2007-06-16 16:32:48    17,212    ----atw    C:\WINDOWS\system32\SIntf32.dll
2007-06-16 16:32:48    12,067    ----atw    C:\WINDOWS\system32\SIntf16.dll
2007-06-04 18:39:46    --------    d-----w    C:\DOCUME~1\Freaky\APPLIC~1\Command & Conquer 3 Tiberium Wars
2007-06-04 18:32:22    --------    d--h--r    C:\DOCUME~1\Freaky\APPLIC~1\SecuROM
2007-06-04 18:32:21    98,304    ----a-w    C:\WINDOWS\system32CmdLineExt.dll
2007-06-04 18:17:58    --------    d-----w    C:\Program Files\Electronic Arts
2007-06-03 19:37:16    29,629    ----a-w    C:\WINDOWS\DIIUnin.dat
2007-06-03 19:12:46    94,208    ----a-w    C:\WINDOWS\DIIUnin.exe
2007-06-03 19:12:46    2,829    ----a-w    C:\WINDOWS\DIIUnin.pif
2007-05-31 14:02:53    --------    d-----w    C:\Program Files\Winamp
2007-05-24 13:56:20    63,040    ----a-w    C:\WINDOWS\system32\pnkbstra.exe
2007-04-30 15:46:10    745,600    ----a-w    C:\WINDOWS\system32\aswBoot.exe
2007-04-30 15:35:28    95,872    ----a-w    C:\WINDOWS\system32\AvastSS.scr


(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2006-08-11 15:43 C:\WINDOWS\system32\nwiz.exe]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 16:21 C:\WINDOWS\system32\HdAShCut.exe]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 03:11]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2005-09-07 16:35]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-05 04:35]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-11-08 13:27]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 17:42]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"Octoshape Streaming Services"="C:\Program Files\Octoshape Streaming Services\Freaky\OctoshapeClient.exe" [2006-02-13 18:33]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-04-23 15:46]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"PcSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"antivirus"= {B1EBA4F2-DD47-4D16-9818-DC9CC4F8D6BF} - firewallav.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

R0 sfvfs02;StarForce Protection VFS Driver (version 2.x);C:\WINDOWS\system32\drivers\sfvfs02.sys
R1 SASDIFSV;SASDIFSV;\??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
R1 SASKUTIL;SASKUTIL;\??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service;C:\WINDOWS\system32\drivers\ADIHdAud.sys
R3 AEAudioService;AEAudio Service;C:\WINDOWS\system32\drivers\AEAudio.sys
R3 Ch2kUSB;Cherry USB Driver for CDI;C:\WINDOWS\system32\drivers\Ch2kUSB.sys
R3 MTsensor;ATK0110 ACPI UTILITY;C:\WINDOWS\system32\DRIVERS\ASACPI.sys
R3 SASENUM;SASENUM;\??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
R3 SenFiltService;SenFilt Service;C:\WINDOWS\system32\drivers\Senfilt.sys
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service;C:\WINDOWS\system32\drivers\HdAudio.sys
S3 Nokia USB Generic;Nokia USB Generic;C:\WINDOWS\system32\drivers\nmwcdc.sys
S3 Nokia USB Modem;Nokia USB Modem;C:\WINDOWS\system32\drivers\nmwcdcm.sys
S3 Nokia USB Phone Parent;Nokia USB Phone Parent;C:\WINDOWS\system32\drivers\nmwcd.sys
S3 Nokia USB Port;Nokia USB Port;C:\WINDOWS\system32\drivers\nmwcdcj.sys


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-24 19:34:23
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden registry entries ...

scanning hidden files ...

C:\WINDOWS\Look how wasted Paris Hilton is, after she got jailed :(0.zip 117982 bytes hidden from API
C:\WINDOWS\Look how wasted Paris Hilton is, after she got jailed :(14.zip 117982 bytes hidden from API
C:\WINDOWS\Look how wasted Paris Hilton is, after she got jailed :(36.zip 117980 bytes hidden from API
C:\WINDOWS\Look how wasted Paris Hilton is, after she got jailed :(59.zip 117982 bytes hidden from API
C:\WINDOWS\Look how wasted Paris Hilton is, after she got jailed :(72.zip 117982 bytes hidden from API
C:\WINDOWS\Look how wasted Paris Hilton is, after she got jailed :(92.zip 117982 bytes hidden from API
C:\WINDOWS\Look how wasted Paris Hilton is, after she got jailed :(95.zip 117982 bytes hidden from API

scan completed successfully
hidden files: 7

**************************************************************************

Completion time: 2007-07-24 19:34:40

    --- E O F ---

-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-

Logfile of HijackThis v1.99.1
Scan saved at 7:30:53 PM, on 7/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Freaky\Desktop\DFENS#TOOLZ\alternativ.exe

O1 - Hosts: 207.210.117.53 www.winmx.com
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Program Files\Octoshape Streaming Services\Freaky\OctoshapeClient.exe" -inv:bootrun
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1163180305745
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: antivirus - {B1EBA4F2-DD47-4D16-9818-DC9CC4F8D6BF} - firewallav.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/24/2007 at 07:24 PM

Application Version : 3.7.1018

Core Rules Database Version : 3273
Trace Rules Database Version: 1284

Scan type      : Quick Scan
Total Scan Time : 00:06:01

Memory items scanned      : 142
Memory threats detected  : 0
Registry items scanned    : 599
Registry threats detected : 0
File items scanned        : 9796
File threats detected    : 5

Adware.Tracking Cookie
    C:\Documents and Settings\Freaky\Cookies\freaky@atdmt[2].txt
    C:\Documents and Settings\Freaky\Cookies\freaky@cgi-bin[1].txt
    C:\Documents and Settings\Freaky\Cookies\freaky@adtech[2].txt
    C:\Documents and Settings\Freaky\Cookies\freaky@mediaplex[1].txt
    C:\Documents and Settings\Freaky\Cookies\freaky@track.adform[1].txt

-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-

Rootchk _IKKE_ kørt pga stress skabt af Avast! AntiVirus, er det meget nødvendigt? Er helt sikkert inficeret, da jeg ik kan åbne msgr uden
at aktivt sprede denne satan >< HLEP !
Avatar billede ds-zim Nybegynder
25. juli 2007 - 16:54 #1
Lukker spm som følge af mangel på interesse
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester