win32 trojan
Hej eksperterJeg har desværre fået en genstridig virus af typen win32_trojan.
Norton antivirus og programmerne i guiden "sådan fjerner du virus og malware" http://www.eksperten.dk/guide/1232 formåede desværre ikke at udbedre alt. Jeg endte op med ikke at kunne komme på internettet og virussen viste sig igen, når jeg satte en CD rom i.
Derfor valgte jeg at formatere harddisken/installere windows XP mv.
For at være helt sikker på at alt virus nu er slettet, vil jeg gerne bede en ekspert om at se vedhæftede logfiler igennem:
Malwarebytes
Malwarebytes' Anti-Malware 1.36
Database version: 2069
Windows 5.1.2600 Service Pack 3
03-05-2009 14:11:55
mbam-log-2009-05-03 (14-11-55).txt
Skan type: Fuldstændig skanning (C:\|)
Objekter skannet: 139242
Tid tilbagelagt: 38 minute(s), 10 second(s)
Inficerede Hukommelses Processer: 0
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 0
Inficerede Registeringsdatabase Værdier: 0
Inficerede Registeringsdatabase Filer: 0
Inficerede Mapper: 0
Inficerede Filer: 0
Inficerede Hukommelses Processer:
(Ingen mistænkelige filer fundet)
Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)
Inficerede Registeringsdatabase Nøgler:
(Ingen mistænkelige filer fundet)
Inficerede Registeringsdatabase Værdier:
(Ingen mistænkelige filer fundet)
Inficerede Registeringsdatabase Filer:
(Ingen mistænkelige filer fundet)
Inficerede Mapper:
(Ingen mistænkelige filer fundet)
Inficerede Filer:
(Ingen mistænkelige filer fundet)
Combofix
ComboFix 09-05-02.4 - Vivian Thomsen 03-05-2009 14:19.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.45.1030.18.511.212 [GMT 2:00]
Kører fra: c:\documents and settings\Vivian Thomsen\Skrivebord\ComboFix.exe
AV: Norton 360 *On-access scanning disabled* (Updated)
FW: Norton 360 *enabled*
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\patchw32.dll
c:\windows\pw32a.dll
c:\windows\system32\AutoRun.inf
.
((((((((((((((((((((((((((((( Filer skabt fra 2009-04-03 til 2009-05-03 )))))))))))))))))))))))))))))))))))
.
2009-05-03 11:28 . 2009-05-03 11:28 -------- d-----w c:\documents and settings\Vivian Thomsen\Application Data\Malwarebytes
2009-05-03 11:28 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-03 11:28 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-03 11:28 . 2009-05-03 11:28 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-03 11:28 . 2009-05-03 11:28 -------- d-----w c:\programmer\Malwarebytes' Anti-Malware
2009-05-02 19:00 . 2009-05-02 19:00 -------- d-----w c:\documents and settings\Vivian Thomsen\Application Data\Symantec
2009-05-02 17:04 . 2008-10-16 12:06 268648 ----a-w c:\windows\system32\mucltui.dll
2009-05-02 16:20 . 2009-05-02 16:20 -------- d-----w c:\documents and settings\Vivian Thomsen\Lokale indstillinger\Application Data\Symantec_Corporation
2009-05-02 15:55 . 2008-01-19 18:12 128104 ----a-w c:\windows\system32\drivers\WimFltr.sys
2009-05-02 15:55 . 2008-01-19 17:40 15088 ----a-w c:\windows\system32\drivers\vproeventmonitor.sys
2009-05-02 15:55 . 2008-08-13 15:07 38112 ----a-w c:\windows\system32\drivers\v2imount.sys
2009-05-02 15:55 . 2008-08-07 15:31 138080 ----a-w c:\windows\system32\drivers\symsnap.sys
2009-05-02 15:54 . 2009-05-02 15:54 -------- d-----w c:\programmer\Norton Ghost
2009-05-02 11:42 . 2003-06-25 14:05 266360 ----a-w c:\windows\system32\TweakUI.exe
2009-05-02 10:22 . 2008-04-14 06:42 14720 -c--a-w c:\windows\system32\dllcache\kbdhid.sys
2009-05-02 10:22 . 2008-04-14 06:42 14720 ----a-w c:\windows\system32\drivers\kbdhid.sys
2009-05-02 10:22 . 2008-04-13 09:45 10368 -c--a-w c:\windows\system32\dllcache\hidusb.sys
2009-05-02 10:22 . 2008-04-13 09:45 10368 ----a-w c:\windows\system32\drivers\hidusb.sys
2009-05-02 10:10 . 2009-05-02 10:10 -------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-05-02 09:50 . 2009-05-02 09:50 -------- d-----w C:\WEBBANK
2009-05-02 09:14 . 2007-03-13 02:35 476416 ----a-w c:\windows\system32\drivers\rt2870.sys
2009-05-02 09:14 . 2009-05-02 09:14 -------- d-----w c:\programmer\D-Link
2009-05-02 09:13 . 2009-05-02 09:13 -------- d-----w c:\documents and settings\Vivian Thomsen\Application Data\InstallShield
2009-05-02 09:04 . 2009-05-02 09:04 -------- d-sh--w c:\documents and settings\Administrator\IETldCache
2009-05-02 08:47 . 2009-05-02 08:48 -------- d-----w c:\programmer\Paint.NET
2009-05-02 08:47 . 2009-05-02 11:49 -------- d-----w c:\documents and settings\Vivian Thomsen\Lokale indstillinger\Application Data\Paint.NET
2009-05-02 08:04 . 2009-05-02 08:04 -------- d-----w c:\documents and settings\Vivian Thomsen\Application Data\r2 Studios
2009-05-02 08:04 . 2009-05-02 08:04 -------- d-----w c:\documents and settings\All Users\Application Data\r2 Studios
2009-05-02 08:04 . 2009-05-02 08:04 -------- d-----w c:\programmer\r2 Studios
2009-05-02 08:00 . 2009-05-02 08:00 -------- d-----w c:\documents and settings\NetworkService\Lokale indstillinger\Application Data\Google
2009-05-01 23:07 . 2009-05-01 23:07 -------- d-----w c:\windows\ie8updates
2009-05-01 23:02 . 2009-05-01 23:02 143 ----a-w c:\documents and settings\Vivian Thomsen\Lokale indstillinger\Application Data\fusioncache.dat
2009-05-01 23:02 . 2009-05-01 23:03 -------- d-----w c:\documents and settings\Vivian Thomsen\Lokale indstillinger\Application Data\ApplicationHistory
2009-05-01 22:59 . 2009-02-28 04:55 105984 -c----w c:\windows\system32\dllcache\iecompat.dll
2009-05-01 22:57 . 2009-05-02 08:38 -------- d-----w c:\documents and settings\Vivian Thomsen\Lokale indstillinger\Application Data\Adobe
2009-05-01 22:56 . 2009-05-01 22:57 -------- d-----w c:\programmer\Fælles filer\Adobe
2009-05-01 22:52 . 2009-05-01 22:52 -------- d-----w c:\documents and settings\LocalService\Lokale indstillinger\Application Data\Google
2009-05-01 22:50 . 2009-05-02 10:08 -------- d-----w c:\documents and settings\Vivian Thomsen\Lokale indstillinger\Application Data\Google
2009-05-01 22:49 . 2009-05-03 09:02 -------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-05-01 22:49 . 2009-05-01 22:54 -------- d-----w c:\programmer\Google
2009-05-01 22:44 . 2009-05-01 22:44 -------- d--h--w c:\windows\PIF
2009-05-01 22:44 . 2009-05-01 22:44 -------- d-----w c:\documents and settings\Vivian Thomsen\Application Data\Windows Search
2009-05-01 22:41 . 2009-05-01 22:41 -------- d-----w c:\windows\nvidia icons
2009-05-01 22:40 . 2009-05-01 22:40 -------- d-----w c:\windows\nview
2009-05-01 22:40 . 2008-05-03 03:46 442368 ----a-w c:\windows\system32\nvudisp.exe
2009-05-01 22:40 . 2008-04-30 15:27 442368 ----a-w c:\windows\system32\NVUNINST.EXE
2009-05-01 22:39 . 2009-05-01 22:39 -------- d-----w C:\NVIDIA
2009-05-01 22:39 . 2009-05-01 22:39 -------- d-----w c:\windows\system32\Adobe
2009-05-01 22:36 . 2009-05-01 22:36 -------- d-----w c:\programmer\SystemRequirementsLab
2009-05-01 22:34 . 2009-05-01 22:34 -------- d-sh--w c:\documents and settings\Vivian Thomsen\IECompatCache
2009-05-01 22:33 . 2009-05-01 22:33 -------- d-sh--w c:\documents and settings\Vivian Thomsen\PrivacIE
2009-05-01 22:30 . 2009-05-01 22:30 -------- d-sh--w c:\documents and settings\LocalService\IETldCache
2009-05-01 22:21 . 2009-05-01 22:21 -------- d-sh--w c:\documents and settings\NetworkService\IETldCache
2009-05-01 22:21 . 2009-05-01 22:21 -------- d-sh--w c:\documents and settings\Vivian Thomsen\IETldCache
2009-05-01 22:15 . 2009-05-01 22:18 -------- dc-h--w c:\windows\ie8
2009-05-01 22:13 . 2009-05-01 22:13 -------- d-----w c:\programmer\MSXML 4.0
2009-05-01 22:10 . 2009-05-01 22:10 -------- d-----w c:\programmer\Fælles filer\Windows Live
2009-05-01 22:08 . 2009-05-01 22:08 -------- d-----w c:\programmer\Microsoft Silverlight
2009-05-01 22:08 . 2006-06-29 11:07 14048 ------w c:\windows\system32\spmsg2.dll
2009-05-01 21:58 . 2009-05-01 22:07 -------- d-----w c:\windows\system32\XPSViewer
2009-05-01 21:58 . 2009-05-01 21:58 -------- d-----w c:\programmer\MSBuild
2009-05-01 21:58 . 2009-05-01 21:58 -------- d-----w c:\programmer\Reference Assemblies
2009-05-01 21:57 . 2008-07-06 12:06 117760 ------w c:\windows\system32\prntvpt.dll
2009-05-01 21:57 . 2008-07-06 12:06 89088 -c----w c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-05-01 21:57 . 2008-07-06 10:50 597504 -c----w c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-05-01 21:57 . 2008-07-06 12:06 575488 -c----w c:\windows\system32\dllcache\xpsshhdr.dll
2009-05-01 21:57 . 2008-07-06 12:06 575488 ------w c:\windows\system32\xpsshhdr.dll
2009-05-01 21:57 . 2008-07-06 12:06 1676288 -c----w c:\windows\system32\dllcache\xpssvcs.dll
2009-05-01 21:57 . 2008-07-06 12:06 1676288 ------w c:\windows\system32\xpssvcs.dll
2009-05-01 21:57 . 2009-05-01 21:57 -------- d-----w C:\97a06b72b156b99c0f83a44fb3640cc0
2009-05-01 21:51 . 2009-05-01 21:51 -------- d-----w c:\programmer\Microsoft
2009-05-01 21:50 . 2009-05-01 21:50 -------- d-----w c:\documents and settings\Vivian Thomsen\Lokale indstillinger\Application Data\Identities
2009-05-01 21:49 . 2009-05-01 22:48 -------- d-----w c:\programmer\Windows Desktop Search
2009-05-01 21:49 . 2009-05-01 21:49 -------- d-----w c:\windows\system32\GroupPolicy
2009-05-01 21:49 . 2008-03-07 17:02 29696 -c----w c:\windows\system32\dllcache\mimefilt.dll
2009-05-01 21:49 . 2008-03-07 17:02 98304 -c----w c:\windows\system32\dllcache\nlhtml.dll
2009-05-01 21:49 . 2008-03-07 17:02 192000 -c----w c:\windows\system32\dllcache\offfilt.dll
2009-05-01 21:47 . 2008-04-14 07:05 221184 ----a-w c:\windows\system32\wmpns.dll
2009-05-01 21:47 . 2009-05-01 21:47 -------- d-----w c:\programmer\Windows Media Connect 2
2009-05-01 21:45 . 2009-05-01 21:46 -------- d-----w c:\windows\system32\drivers\UMDF
2009-05-01 21:45 . 2009-05-01 21:45 -------- d-----w c:\windows\system32\LogFiles
2009-05-01 21:44 . 2009-05-01 21:44 -------- d-----w c:\programmer\Microsoft CAPICOM 2.1.0.2
2009-05-01 21:40 . 2009-05-01 21:42 -------- d-----w c:\windows\system32\URTTemp
2009-05-01 21:28 . 2009-05-01 21:28 -------- d-----w c:\windows\Sun
2009-05-01 21:28 . 2009-05-01 21:27 410984 ----a-w c:\windows\system32\deploytk.dll
2009-05-01 21:27 . 2009-05-01 21:27 -------- d-----w c:\programmer\Java
2009-05-01 21:25 . 2009-05-02 11:42 -------- d-----w c:\windows\Downloaded Installations
2009-05-01 21:20 . 2009-05-02 11:58 -------- d-----w C:\System & co
2009-05-01 21:17 . 2009-05-01 21:17 -------- d-----w c:\documents and settings\All Users\Application Data\WEBREG
2009-05-01 21:16 . 2007-03-08 04:20 16496 ----a-r c:\windows\system32\drivers\HPZipr12.sys
2009-05-01 21:16 . 2007-03-08 04:20 49920 ----a-r c:\windows\system32\drivers\HPZid412.sys
2009-05-01 21:16 . 2009-05-01 21:16 -------- d-----w c:\documents and settings\All Users\Application Data\Hewlett-Packard
2009-05-01 21:16 . 2007-05-02 10:03 267864 ----a-r c:\windows\system32\hpzids01.dll
2009-05-01 21:16 . 2007-03-15 13:32 118272 ----a-w c:\windows\system32\hpz3l5ha.dll
2009-05-01 21:15 . 2007-03-08 04:20 21568 ----a-r c:\windows\system32\drivers\HPZius12.sys
2009-05-01 21:15 . 2007-03-08 04:20 309760 ----a-r c:\windows\system32\difxapi.dll
2009-05-01 21:15 . 2007-03-08 04:20 364544 ----a-r c:\windows\system32\hppldcoi.dll
2009-05-01 21:15 . 2007-05-02 09:00 303104 ----a-r c:\windows\system32\hpovst12.dll
2009-05-01 21:15 . 2007-05-02 08:56 954368 ----a-r c:\windows\system32\hpotiop5.dll
2009-05-01 21:15 . 2007-05-02 09:01 675840 ----a-r c:\windows\system32\hpowiax5.dll
2009-05-01 21:15 . 2008-04-13 09:45 15104 -c--a-w c:\windows\system32\dllcache\usbscan.sys
2009-05-01 21:15 . 2008-04-13 09:45 15104 ----a-w c:\windows\system32\drivers\usbscan.sys
2009-05-01 21:13 . 2009-05-01 21:13 -------- d-----w c:\documents and settings\All Users\Application Data\HPSSUPPLY
2009-05-01 21:13 . 2009-05-01 21:13 -------- d-----w c:\documents and settings\Vivian Thomsen\Application Data\HPAppData
2009-05-01 21:11 . 2009-05-01 21:11 -------- d-----w c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-05-01 21:11 . 2009-05-01 21:12 -------- d-----w c:\documents and settings\All Users\Application Data\HP
2009-05-01 21:11 . 2009-05-01 21:11 -------- d-----w c:\programmer\Fælles filer\HP
2009-05-01 21:10 . 2009-05-01 21:10 -------- d-----w c:\programmer\Hewlett-Packard
2009-05-01 21:10 . 2009-05-01 21:10 -------- d-----w c:\programmer\Fælles filer\Hewlett-Packard
2009-05-01 21:09 . 2009-05-01 21:13 -------- d-----w c:\programmer\HP
2009-05-01 21:08 . 2008-04-13 09:47 25856 -c--a-w c:\windows\system32\dllcache\usbprint.sys
2009-05-01 21:08 . 2008-04-13 09:47 25856 ----a-w c:\windows\system32\drivers\usbprint.sys
2009-05-01 21:07 . 2008-05-01 14:36 331776 -c----w c:\windows\system32\dllcache\msadce.dll
2009-05-01 21:07 . 2009-05-01 21:17 160539 ----a-w c:\windows\hpoins21.dat
2009-05-01 21:07 . 2007-09-05 18:26 8138 ------w c:\windows\hpomdl21.dat
2009-05-01 21:04 . 2009-05-02 16:15 -------- dc----w c:\windows\system32\DRVSTORE
2009-05-01 21:04 . 2009-05-01 21:04 -------- d-----w c:\documents and settings\All Users\Application Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-05-01 21:04 . 2009-05-01 21:04 -------- d-----w c:\documents and settings\Vivian Thomsen\Lokale indstillinger\Application Data\Downloaded Installations
2009-05-01 21:04 . 2009-05-01 21:04 36400 ----a-r c:\windows\system32\drivers\SymIM.sys
2009-05-01 21:04 . 2009-05-01 21:04 60808 ----a-w c:\windows\system32\S32EVNT1.DLL
2009-05-01 21:04 . 2009-05-01 21:04 124464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-05-01 21:04 . 2009-05-02 15:56 -------- d-----w c:\programmer\Symantec
2009-05-01 21:03 . 2009-05-01 21:03 -------- d-----w c:\windows\system32\drivers\N360
2009-05-01 21:03 . 2009-05-01 21:03 -------- d-----w c:\programmer\Norton 360
2009-05-01 21:03 . 2009-05-01 21:03 -------- d-----w c:\programmer\Windows Sidebar
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-03 12:23 . 2009-05-01 22:52 892 ----a-w c:\windows\Tasks\GoogleUpdateTaskMachine.job
2009-05-03 12:23 . 2009-05-01 22:49 902 ----a-w c:\windows\Tasks\Google Software Updater.job
2009-05-03 12:22 . 2009-05-01 17:50 6 ---ha-w c:\windows\Tasks\SA.DAT
2009-05-02 09:15 . 2009-05-02 09:14 -------- d-----w c:\programmer\ANI
2009-05-02 09:15 . 2009-05-01 18:12 -------- d--h--w c:\programmer\InstallShield Installation Information
2009-05-01 23:01 . 2006-03-02 12:00 82286 ----a-w c:\windows\system32\perfc006.dat
2009-05-01 23:01 . 2006-03-02 12:00 455992 ----a-w c:\windows\system32\perfh006.dat
2009-05-01 22:40 . 2009-05-01 18:12 -------- d-----w c:\programmer\Fælles filer\InstallShield
2009-05-01 22:09 . 2009-05-01 18:03 19880 ----a-w c:\documents and settings\Vivian Thomsen\Lokale indstillinger\Application Data\GDIPFONTCACHEV1.DAT
2009-05-01 21:04 . 2009-05-01 21:04 805 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-05-01 21:04 . 2009-05-01 21:04 7386 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-05-01 19:50 . 2009-05-01 17:47 76487 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-01 18:23 . 2009-05-01 18:23 -------- d-----w c:\programmer\CCleaner
2009-05-01 18:20 . 2009-05-01 18:19 -------- d-----w c:\programmer\Ahead
2009-05-01 18:15 . 2009-05-01 18:15 -------- d-----w c:\programmer\Realtek Sound Manager
2009-05-01 18:15 . 2009-05-01 18:15 -------- d-----w c:\programmer\AvRack
2009-05-01 18:14 . 2009-05-01 18:12 -------- d-----w c:\programmer\Intel
2009-05-01 18:14 . 2009-05-01 18:14 -------- d-----w c:\programmer\Gigabyte
2009-05-01 17:48 . 2009-05-01 17:48 -------- d-----w c:\programmer\microsoft frontpage
2009-05-01 17:47 . 2006-03-02 12:00 67 --sha-w c:\windows\Fonts\desktop.ini
2009-05-01 17:46 . 2009-05-01 17:46 -------- d-----w c:\programmer\Onlinetjenester
2009-05-01 17:45 . 2009-05-01 17:45 -------- d-----w c:\programmer\Fælles filer\Tjenester
2009-05-01 17:45 . 2009-05-01 17:45 21644 ----a-w c:\windows\system32\emptyregdb.dat
2009-03-08 02:34 . 2006-03-02 12:00 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 02:34 . 2006-03-02 12:00 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 02:33 . 2006-03-02 12:00 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 02:33 . 2006-03-02 12:00 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 02:32 . 2006-03-02 12:00 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 02:32 . 2006-03-02 12:00 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 02:31 . 2006-03-02 12:00 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 02:31 . 2006-03-02 12:00 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 02:31 . 2006-03-02 12:00 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 02:22 . 2006-03-02 12:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 14:20 . 2006-03-02 12:00 284672 ----a-w c:\windows\system32\pdh.dll
2009-02-21 06:25 . 2008-12-31 15:04 691592 ----a-w c:\windows\system32\OGACheckControl.DLL
2009-02-09 14:07 . 2006-03-02 12:00 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:26 . 2004-08-26 17:50 2026496 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 11:25 . 2006-03-02 12:00 2147840 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 11:25 . 2006-03-02 12:00 110592 ----a-w c:\windows\system32\services.exe
2009-02-09 10:53 . 2006-03-02 12:00 730624 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:53 . 2006-03-02 12:00 719360 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 10:53 . 2006-03-02 12:00 682496 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:53 . 2006-03-02 12:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-06 10:39 . 2006-03-02 12:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-03 19:58 . 2006-03-02 12:00 56832 ----a-w c:\windows\system32\secur32.dll
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-01 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartupDelayer"="c:\programmer\r2 Studios\Startup Delayer\Startup Launcher GUI.exe" [2009-03-08 147456]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"ANIWZCS2Service"="c:\programmer\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152]
"Norton Ghost 14.0"="c:\programmer\Norton Ghost\Agent\VProTray.exe" [2008-12-11 2245992]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
R2 gupdate1c9caaf83912f6c;Tjenesten Google Update (gupdate1c9caaf83912f6c);c:\programmer\Google\Update\GoogleUpdate.exe [2009-05-01 133104]
R3 EraserUtilDrv10710;EraserUtilDrv10710; [x]
R3 GoogleDesktopManager-110408-113106;Google Desktop-administrator 5.8.811.4345;c:\programmer\Google\Google Desktop Search\GoogleDesktop.exe [2009-05-01 30192]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0300000.087\SYMEFA.SYS [2009-05-01 21:04 310320]
S1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\N360\0300000.087\BHDrvx86.sys [2009-05-01 21:04 258608]
S1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0300000.087\ccHPx86.sys [2009-05-01 21:04 482352]
S1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090501.001\IDSxpx86.sys [2009-05-01 276344]
S2 N360;Norton 360;c:\programmer\Norton 360\Engine\3.0.0.135\ccSvcHst.exe [2009-05-01 115560]
S2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [2008-04-14 5120]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\programmer\Fælles filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-05-01 101936]
S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\DRIVERS\rt2870.sys [2007-03-13 476416]
S3 SymSnapService;SymSnapService;c:\programmer\Norton Ghost\Shared\Drivers\SymSnapService.exe [2008-08-07 1558000]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Indhold af mappen 'Planlagte Opgaver'
2009-05-03 c:\windows\Tasks\Google Software Updater.job
- c:\programmer\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-01 22:49]
2009-05-03 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2009-05-01 22:52]
.
.
------- Yderligere scanning -------
.
uStart Page = hxxp://www.google.dk/
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-03 14:24
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- DLLs startet under kørende Processer ---------------------
- - - - - - - > 'explorer.exe'(3812)
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\programmer\Java\jre6\bin\jqs.exe
c:\programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
c:\programmer\Norton Ghost\Agent\VProSvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\msdtc.exe
c:\windows\system32\wscntfy.exe
c:\programmer\D-Link\D-Link Wireless N DWA-140\AirNCFG.exe
c:\windows\system32\TaskSwitch.exe
.
**************************************************************************
.
Gennemført tid: 2009-05-03 14:26 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2009-05-03 12:26
Pre-Kørsel: 69.573.627.904 byte ledig
Post-Kørsel: 69.513.187.328 byte ledig
WindowsXP-KB310994-SP2-Home-BootDisk-DAN.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
301 --- E O F --- 2009-05-02 08:02
Hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:28:31, on 03-05-2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmer\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Norton Ghost\Agent\VProSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Programmer\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
C:\Programmer\Norton Ghost\Shared\Drivers\SymSnapService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Programmer\Norton Ghost\Agent\VProTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\D-Link\D-Link Wireless N DWA-140\AirNCFG.exe
C:\Programmer\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Programmer\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\explorer.exe
C:\Programmer\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Programmer\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Programmer\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Programmer\Norton 360\Engine\3.0.0.135\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Programmer\Norton 360\Engine\3.0.0.135\IPSBHO.DLL
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmer\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programmer\Norton 360\Engine\3.0.0.135\coIEPlg.dll
O4 - HKLM\..\Run: [StartupDelayer] "C:\Programmer\r2 Studios\Startup Delayer\Startup Launcher GUI.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Programmer\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [Norton Ghost 14.0] "C:\Programmer\Norton Ghost\Agent\VProTray.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: HP Klipsamling - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Programmer\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart markering - {700259D7-1666-479a-93B1-3250410481E8} - C:\Programmer\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1241212776937
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-09.sun.com/s/ESD7/JSCDL/jdk/6u13-b03/jinstall-6u13-windows-i586-jc.cab?e=1241213297232&h=0bf2c50e47940aef926652476bdf0065/&filename=jinstall-6u13-windows-i586-jc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Programmer\Norton 360\Engine\3.0.0.135\coIEPlg.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Programmer\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Google Desktop-administrator 5.8.811.4345 (GoogleDesktopManager-110408-113106) - Google - C:\Programmer\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Tjenesten Google Update (gupdate1c9caaf83912f6c) (gupdate1c9caaf83912f6c) - Google Inc. - C:\Programmer\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmer\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Programmer\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Programmer\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Programmer\Norton Ghost\Agent\VProSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SymSnapService - Symantec - C:\Programmer\Norton Ghost\Shared\Drivers\SymSnapService.exe
--
End of file - 7351 bytes
På forhånd tak for hjælpen.
Mange hilsner
Erantis1
