![]() |
|
#1
| |||
| |||
| Ja, jag har aldrig sett det förut men när jag klickar på sökknappen från Windows och göra en sökning den håller "leta" efter filer även om jag klickar på stoppknappen, jag är inte säker på om det är ett virus men verkligen stör mig orsak om jag vill söka efter en annan fil så måste jag stänga fönstret och öppna det igen ... ![]() En annan sak som håller stör mig är att när jag i Firefox till exempel om IM tittar på ett videoklipp på youtube helskärmsläge det går med små skärmar i viss tid och om igen eller om jag skriver något, av någon mystisk anledning I cant typ längre, som om jag valt ett annat fönster eller något ... då måste jag klicka i Firefox igen för att fortsätta mitt maskinskrivning (som hade hänt mer än 10 gånger i just denna lilla msg ... gör mig galen, IM berätta!)min pc agerar konstigt och karpersky antivirus säger att jag har inget fel ... Jag har arbetat med datorer under lång tid nu men detta är något jag har icke sett och har icke hört ännu ... kan IM bli paranoid |
|
#2
| |||
| |||
| Låt oss ta en närmare titt. Ladda ner och byta namn HijackThis (HJT)
|
|
#3
| |||
| |||
| Detta är vad jag får: ************************************************** Loggfil av Trend Micro HijackThis v2.0.2 Scan saved at 02:08:32, 05/01/2008 Plattform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Kör processer: C: \ WINDOWS \ System32 \ Smss.exe C: \ WINDOWS \ system32 \ Winlogon.exe C: \ WINDOWS \ system32 \ services.exe C: \ WINDOWS \ system32 \ Lsass.exe C: \ WINDOWS \ system32 \ Svchost.exe C: \ WINDOWS \ System32 \ Svchost.exe C: \ WINDOWS \ system32 \ Svchost.exe C: \ WINDOWS \ system32 \ Spoolsv.exe C: \ Program \ ABBYY FineReader 9.0 \ NetworkLicenseServer.exe C: \ Program \ LogMeIn \ x86 \ RaMaint.exe C: \ Program \ LogMeIn \ x86 \ LogMeIn.exe C: \ Archivos de programa \ Archivos comunes \ Microsoft Shared \ VS7DEBUG \ MDM.EXE C: \ WINDOWS \ system32 \ HPZipm12.exe C: \ WINDOWS \ system32 \ Svchost.exe C: \ WINDOWS \ System32 \ Svchost.exe C: \ WINDOWS \ system32 \ dllhost.exe C: \ WINDOWS \ Explorer.EXE C: \ Program \ LogMeIn \ x86 \ LogMeInSystray.exe C: \ WINDOWS \ system32 \ SVOHOST.exe C: \ Program \ DAEMON Tools \ daemon.exe C: \ WINDOWS \ system32 \ Ctfmon.exe C: \ Program \ Microsoft Office \ Office11 \ Winword.exe C: \ Program \ Skype \ Phone \ Skype.exe C: \ Archivos de programa \ Mozilla Firefox \ firefox.exe C: \ Program \ Trend Micro \ HijackThis \ asdf.exe R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = cirka: blank R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Toolbar, LinksFolderName = F2 - REG: system.ini: Userinit = C: \ WINDOWS \ system32 \ userinit.exe, C: \ Windo WS \ system32 \ ODBCJET.exe, O2 - BHO: Adobe PDF Reader Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program \ Adobe \ Acrobat 7.0 \ ActiveX \ AcroIEHelper.dll O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program \ Java \ jre1.5.0_09 \ bin \ ssv.dll O2 - BHO: (inget namn) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (no file) O4 - HKLM \ .. \ Run: [LogMeIn GUI] "C: \ Program \ LogMeIn \ x86 \ LogMeInSystray.exe" O4 - HKLM \ .. \ Run: [SoundMam] C: \ WINDOWS \ system32 \ SVOHOST.exe O4 - HKLM \ .. \ Run: [DAEMON Tools] "C: \ Program \ DAEMON Tools \ daemon.exe"-lang 1033 O4 - HKCU \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe O4 - HKLM \ .. \ Run: [MsnMsgr] "C: \ Program \ Windows Live \ Messenger \ msmsgs.exe" / background O4 - HKLM \ .. \ Run: [Comrade.exe] C: \ Program \ GameSpy \ Comrade \ Comrade.exe O4 - HKUS \ S-1-5-19 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe (User "Servicio LOCAL) O4 - HKUS \ S-1-5-19 \ .. \ RunOnce: [nltide3] cmd.exe / C rundll32 advpack.dll, LaunchINFSectionEx nLite.inf, C,, 4, N (User 'Servicio LOCAL) O4 - HKUS \ S-1-5-19 \ .. \ Run: [nltide1] cmd.exe / C move / Y "% SystemRoot% \ System32 \ syssetub.dll" "% SystemRoot% \ System32 \ syssetup.dll" (User 'LOKAL servicio') O4 - HKUS \ S-1-5-20 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe (User "Servicio de röda") O4 - HKUS \ S-1-5-20 \ .. \ RunOnce: [nltide3] cmd.exe / C rundll32 advpack.dll, LaunchINFSectionEx nLite.inf, C,, 4, N (User "Servicio de röda") O4 - HKUS \ S-1-5-18 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe (User "SYSTEM") O4 - HKUS \ S-1-5-18 \ .. \ RunOnce: [nltide3] cmd.exe / C rundll32 advpack.dll, LaunchINFSectionEx nLite.inf, C,, 4, N (User 'SYSTEM') O4 - HKUS \. DEFAULT \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe (User 'Default user') O4 - HKUS \. DEFAULT \ .. \ RunOnce: [nltide3] cmd.exe / C rundll32 advpack.dll, LaunchINFSectionEx nLite.inf, C,, 4, N (User 'Default user') O6 - HKCU \ Software \ Policies \ Microsoft \ Internet Explorer \ Restrictions nuvarande O6 - HKCU \ Software \ Policies \ Microsoft \ Internet Explorer \ Control Panel nuvarande O6 - HKCU \ Software \ Policies \ Microsoft \ Internet Explorer \ Toolbars \ Restrictions nuvarande O8 - Extra sammanhang menyobjektet: E & xportar en Microsoft Excel - res: / / C: \ Archiv ~ 1 \ mikro ~ 1 \ Office11 \ EXCEL.EXE/3000 O9 - Extra button: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program \ Java \ jre1.5.0_09 \ bin \ ssv.dll O9 - Extra 'Tools' menuitem: Consola de Sun Java - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program \ Java \ jre1.5.0_09 \ bin \ ssv.dll Ø9 - Extra button: Referencia - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ Archiv ~ 1 \ mikro ~ 1 \ Office11 \ REFIEBAR.DLL O16 - DPF: (05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8) (Office Genuine Advantage Validation Tool) -- http://go.microsoft.com/fwlink/?linkid=58813 O16 - DPF: (5D6F45B3-9043-443D-a792-115447494D24) (UnoCtrl Class) -- http://messenger.zone.msn.com/ES-LA/.../GAME_UNO1.cab O16 - DPF: (B8BE5E93-A60C-4D26-A2DC-220313175592) (MSN Games - Installer) -- http://messenger.zone.msn.com/binary...o.cab56649.cab O16 - DPF: (C3F79A2B-B9B4-4A66-B012-3EE46475B072) (MessengerStatsClient Class) -- http://messenger.zone.msn.com/binary...t.cab56907.cab O17 - HKLM \ System \ CCS \ Services \ Tcpip \ .. \ (BAA62A6B-DD15-4E55-a719-401AF676E3A9): NameServer = 10.0.0.1,10.0.0.2 O20 - Winlogon Notify: usbmon - C: \ WINDOWS \ system32 \ usbmons.dll O23 - Service: ABBYY FineReader 9,0 Licensing Service (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - C: \ Program \ ABBYY FineReader 9.0 \ NetworkLicenseServer.exe O23 - Service: Ares Chattrum server (AresChatServer) - Ares Development Group - C: \ Archivos de programa \ Ares \ chatServer.exe O23 - Service: BCL easyPDF SDK 5 Loader (bepldr) - Unknown owner - C: \ Program \ WINDOWS comunes \ BCL Technologies \ easyPDF 5 \ bepldr.exe O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C: \ Program \ LogMeIn \ x86 \ RaMaint.exe O23 - Service: LogMeIn - LogMeIn, Inc. - C: \ Program \ LogMeIn \ x86 \ LogMeIn.exe O23 - Service: PML Driver HPZ12 - HP - C: \ WINDOWS \ system32 \ HPZipm12.exe O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C: \ Program \ Spyware Doctor \ svcntaux.exe O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C: \ Program \ Spyware Doctor \ swdsvc.exe -- End of file - 5942 bytes |
|
#4
| |||
| |||
| Japp, har du något otäckt som figurerar där. 1. Har inaktiverat ditt antivirusprogram. 2. Det är en massa-post mask med bakdörr och keylogging kapacitet. 3. Det har satt restriktioner på Kontrollpanelen. --------------- Ladda ner Combofix av SUBS från antingen här eller här VIKTIGT - Spara Combofix.exe till skrivbordet.
Nästa post lägg till combofix log ny HijackThis-logg |
|
#5
| |||
| |||
| ComboFix 08-01-06.3 - Administrator 2008-01-05 14:48:48.1 - NTFSx86 Se ejecuta desde: C: \ Documents and Settings \ Administratör \ Escritório \ ComboFix.exe . (((((((((((((((((((((((((((((((((((( Otras eliminaciones )))))))))))) ))))))))))))))))))))))))))))))))))))) . C: \ WINDOWS \ install.exe C: \ WINDOWS \ system32 \ svohost.exe C: \ WINDOWS \ system32 \ winscok.dll . (((((((((((((((((((((((((((((((((((((( Reporte Find3M )))))))))) ))))))))))))))))))))))))))))))))))))))))) . 2008-01-05 18:49 --------- d ----- w C: \ Documents and Settings \ Administratör \ Datos de programa \ Skype 2008-01-05 15:21 --------- d --- aw C: \ Documents and Settings \ All Users \ Datos de programa \ TEMP 2008-01-05 13:00 --------- d ----- w C: \ Documents and Settings \ Administratör \ Datos de programa \ Azureus 2007-12-26 22:39 --------- d ----- w C: \ Documents and Settings \ Administratör \ Datos de programa \ U3 2007-12-24 14:38 --------- d - h - w C: \ Program \ InstallShield Installation Information 2007-12-23 04:15 --------- d ----- w C: \ Program \ Azureus 2007-12-13 14:40 11.973 ---- aw C: \ WINDOWS \ system32 \ drivers \ secdrv.sys 2007-12-11 15:46 --------- d ----- w C: \ Program \ WINDOWS comunes \ InstallShield 2007-12-05 20:12 --------- d ----- w C: \ Documents and Settings \ Administratör \ Datos de programa \ JAM Software 2007-12-05 20:09 --------- d ----- w C: \ Program \ JAM Software 2007-12-04 19:25 --------- d ----- w C: \ Documents and Settings \ All Users \ Datos de programa \ Office Genuine Advantage 2007-12-03 15:32 --------- d ----- w C: \ Program \ FinalData 2007-12-02 17:05 --------- d ----- w C: \ Documents and Settings \ Administratör \ Datos de programa \ Media Player Classic 2007-12-02 16:43 --------- d ----- w C: \ Documents and Settings \ All Users \ Datos de programa \ WM 2007-12-02 14:42 --------- d ----- w C: \ Documents and Settings \ Administratör \ Datos de programa \ WM 2007-12-02 14:39 --------- d ----- w C: \ Program \ Word Magic Software 2007-12-02 00:44 --------- d ----- w C: \ Documents and Settings \ Administratör \ Datos de programa \ BSplayer Pro 2007-12-02 00:19 70.656 ---- aw C: \ WINDOWS \ ScUnin.exe 2007-11-30 22:17 --------- d ----- w C: \ Program \ DivX 2007-11-30 22:01 --------- d ----- w C: \ Program \ Microsoft Works 2007-11-30 21:45 --------- d ----- w C: \ Documents and Settings \ Dimart \ Datos de programa \ Talkback 2007-11-30 21:19 --------- d ----- w C: \ Program \ DAEMON Tools 2007-11-30 21:13 685.816 ---- aw C: \ WINDOWS \ system32 \ drivers \ sptd.sys 2007-11-30 20:28 --------- d ----- w C: \ Documents and Settings \ All Users \ Datos de programa \ Azureus 2007-11-30 13:42 --------- d ----- w C: \ Documents and Settings \ Administratör \ Datos de programa \ Talkback 2007-11-30 12:38 220.160 ---- aw C: \ WINDOWS \ system32 \ Uxtheme.dll 2007-11-30 12:38 --------- d ----- w C: \ Program \ Skype 2007-11-30 12:37 --------- d ----- w C: \ Documents and Settings \ All Users \ Datos de programa \ Apple Computer 2007-11-30 12:37 --------- d ----- w C: \ Program \ Windows Media Connect 2 2007-11-30 12:37 --------- d ----- w C: \ Program \ Real Alternative 2007-11-30 12:37 --------- d ----- w C: \ Program \ QuickTime Alternative 2007-11-30 12:37 --------- d ----- w C: \ Program \ Media Player Classic 2007-11-30 12:35 --------- d ----- w C: \ Program \ K-Lite Codec Pack 2007-11-30 12:35 --------- d ----- w C: \ Program \ Java 2007-11-30 12:35 --------- d ----- w C: \ Program \ WINDOWS comunes \ Java 2007-11-30 12:34 --------- d ----- w C: \ Program \ Webteh 2007-11-30 12:34 --------- d ----- w C: \ Program \ Lavalys 2007-11-30 12:34 --------- d ----- w C: \ Program \ WINDOWS comunes \ Adobe 2007-11-30 12:23 --------- d ----- w C: \ Program \ WINDOWS comunes \ MSSoap 2007-11-30 12:15 --------- d ----- w C: \ Program \ WINDOWS comunes \ SpeechEngines 2007-11-30 12:15 --------- d ----- w C: \ Program \ WINDOWS comunes \ ODBC 2007-11-15 22:46 23.736 ---- aw C: \ WINDOWS \ system32 \ lmimirr.dll 2007-11-15 22:46 10.040 ---- aw C: \ WINDOWS \ system32 \ lmimirr2.dll 2007-11-14 07:28 450.560 ------ w C: \ WINDOWS \ system32 \ dllcache \ jscript.dll 2007-10-30 10:17 3.079.680 ---- aw C: \ WINDOWS \ system32 \ dllcache \ mshtml.dll 2007-10-29 22:43 1.293.824 ---- aw C: \ WINDOWS \ system32 \ Quartz.dll 2007-10-29 22:43 1.293.824 ------ w C: \ WINDOWS \ system32 \ dllcache \ Quartz.dll 2007-10-25 16:56 8.496.640 ------ w C: \ WINDOWS \ system32 \ dllcache \ shell32.dll 2007-10-25 13:28 222.720 ---- aw C: \ WINDOWS \ system32 \ wmasf.dll 2007-10-25 13:28 222.720 ------ w C: \ WINDOWS \ system32 \ dllcache \ wmasf.dll 2007-10-20 00:56 200.704 ---- aw C: \ WINDOWS \ system32 \ ssldivx.dll 2007-10-20 00:56 1.044.480 ---- aw C: \ WINDOWS \ system32 \ libdivx.dll 2007-10-18 15:31 51.224 ---- aw C: \ WINDOWS \ system32 \ sirenacm.dll 2007-10-11 06:12 96.768 ------ w C: \ WINDOWS \ system32 \ dllcache \ inseng.dll 2007-10-11 06:12 662.016 ------ w C: \ WINDOWS \ system32 \ dllcache \ wininet.dll 2007-10-11 06:12 616.448 ---- aw C: \ WINDOWS \ system32 \ dllcache \ urlmon.dll 2007-10-11 06:12 55.808 ------ w C: \ WINDOWS \ system32 \ dllcache \ extmgr.dll 2007-10-11 06:12 532.480 ------ w C: \ WINDOWS \ system32 \ dllcache \ mstime.dll 2007-10-11 06:12 474.624 ---- aw C: \ WINDOWS \ system32 \ dllcache \ shlwapi.dll 2007-10-11 06:12 449.024 ------ w C: \ WINDOWS \ system32 \ dllcache \ Mshtmled.dll 2007-10-11 06:12 39.424 ------ w C: \ WINDOWS \ system32 \ dllcache \ Pngfilt.dll 2007-10-11 06:12 357.888 ------ w C: \ WINDOWS \ system32 \ dllcache \ Dxtmsft.dll 2007-10-11 06:12 251.392 ------ w C: \ WINDOWS \ system32 \ dllcache \ Iepeers.dll 2007-10-11 06:12 205.312 ------ w C: \ WINDOWS \ system32 \ dllcache \ Dxtrans.dll 2007-10-11 06:12 16.384 ------ w C: \ WINDOWS \ system32 \ dllcache \ jsproxy.dll 2007-10-11 06:12 151.552 ---- aw C: \ WINDOWS \ system32 \ dllcache \ cdfview.dll 2007-10-11 06:12 146.432 ------ w C: \ WINDOWS \ system32 \ dllcache \ msrating.dll 2007-10-11 06:12 1.495.040 ---- aw C: \ WINDOWS \ system32 \ dllcache \ shdocvw.dll 2007-10-11 06:12 1.056.256 ------ w C: \ WINDOWS \ system32 \ dllcache \ danim.dll 2007-10-11 06:12 1.023.488 ---- aw C: \ WINDOWS \ system32 \ dllcache \ browseui.dll 2007-10-10 11:16 18.432 ------ w C: \ WINDOWS \ system32 \ dllcache \ iedw.exe 2006-11-07 14:29 145.920 ---- aw C: \ WINDOWS \ inf \ Hdaudio.sys 2006-09-05 08:18 20.992 - sha-r C: \ WINDOWS \ system32 \ usbmons.exe . ((((((((((((((((((((((((((((((((( Cargando Puntos Reg )))))))))))))) )))))))))))))))))))))))))))))))))))) . . REGEDIT4 * Nota * entradas vacías & entradas legítimas predeterminadas ingen son mostradas [HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curre ntVersion \ Run] "DAEMON Tools" = "C: \ Program \ DAEMON Tools \ daemon.exe" [2007-09-18 10:16 171464] "CTFMON.EXE" = "C: \ WINDOWS \ system32 \ CTFMON.EXE" [2004-08-19 08:42 30208] "MsnMsgr" = "C: \ Program \ Windows Live \ Messenger \ MsnMsgr.Exe" [2007-10-18 11:34 5724184] "Comrade.exe" = "C: \ Program \ GameSpy \ Comrade \ Comrade.exe" [2007-12-20 13:47 36864] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Run] "LogMeIn GUI" = "C: \ Program \ LogMeIn \ x86 \ LogMeInSystray.exe" [2007-08-03 15:09 63048] [HKEY_USERS \. DEFAULT \ Software \ Microsoft \ Windows \ Cur rentVersion \ Run] "CTFMON.EXE" = "C: \ WINDOWS \ system32 \ CTFMON.EXE" [2004-08-19 08:42 30208] [HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ Curr entversion \ Policies \ System] "DisableStatusMessages" = 0 (0x0) "HideShutdownScripts" = 0 (0x0) "RunLogonScriptSync" = 0 (0x0) "RunStartupScriptSync" = 0 (0x0) "HideStartupScripts" = 0 (0x0) [HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ curre ntversion \ Policies \ System] "DisableLockWorkstation" = 0 (0x0) "DisableChangePassword" = 0 (0x0) "HideLogonScripts" = 0 (0x0) "HideLogoffScripts" = 0 (0x0) "HideLegacyLogonScripts" = 0 (0x0) [HKEY_USERS \. Default \ Software \ Microsoft \ windows \ cur rentversion \ Policies \ System] "NoDispCPL" = 0 (0x0) "NoDispAppearancePage" = 0 (0x0) "NoDispScrSavPage" = 0 (0x0) "NoDispSettingsPage" = 0 (0x0) "NoVisualStyleChoice" = 0 (0x0) "NoColorChoice" = 0 (0x0) "NoSizeChoice" = 0 (0x0) "DisableLockWorkstation" = 0 (0x0) "DisableChangePassword" = 0 (0x0) "HideLogonScripts" = 0 (0x0) "HideLogoffScripts" = 0 (0x0) "HideLegacyLogonScripts" = 0 (0x0) [HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ Curr entversion \ Policies \ Explorer] "NoDesktopCleanupWizard" = 1 (0x1) "ForceClassicControlPanel" = 1 (0x1) "NoWelcomeScreen" = 0 (0x0) [HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ curre ntversion \ Policies \ Explorer] "NoChangeKeyboardNavigationIndicators" = 0 (0x0) "NoChangeAnimation" = 0 (0x0) "NoAddPrinter" = 0 (0x0) "NoDeletePrinter" = 0 (0x0) "RestrictCpl" = 0 (0x0) "DisallowCpl" = 0 (0x0) "NoViewOnDrive" = 0 (0x0) "RestrictRun" = 0 (0x0) "DisallowRun" = 0 (0x0) "NoRecycleFiles" = 0 (0x0) "ForceRecycleBinSize" = 0 (0x0) "NoCustomizeWebView" = 0 (0x0) "NoWinKeys" = 0 (0x0) "NoFileAssociate" = 0 (0x0) "NoDFSTab" = 0 (0x0) "NoInstrumentation" = 0 (0x0) "NoCustomizeThisFolder" = 0 (0x0) "NoWebView" = 0 (0x0) "DontShowSuperHidden" = 0 (0x0) "NoOnlinePrintsWizard" = 0 (0x0) "NoPublishingWizard" = 0 (0x0) "NoSMConfigurePrograms" = 0 (0x0) "NoSMMyPictures" = 0 (0x0) "NoStartMenuMyMusic" = 0 (0x0) "NoFavoritesMenu" = 0 (0x0) "NoHelp" = 0 (0x0) "NoCommonGroups" = 0 (0x0) "NoStartMenuMFUprogramsList" = 0 (0x0) "NoStartMenuPinnedList" = 0 (0x0) "NoUserNameInStartMenu" = 0 (0x0) "NoStartMenuMorePrograms" = 0 (0x0) "NoStartMenuEjectPC" = 0 (0x0) "NoSimpleStartMenu" = 0 (0x0) "ForceStartMenuLogoff" = 0 (0x0) "NoStartMenuSubFolders" = 0 (0x0) "NoDisconnect" = 0 (0x0) "NoNtSecurity" = 0 (0x0) "NoSetFolders" = 0 (0x0) "GreyMSIAds" = 0 (0x0) "ForceMaxRecentDocs" = 0 (0x0) "NoSMBalloonTip" = 0 (0x0) "NoSMBalloonTips" = 0 (0x0) "NoTrayContextMenu" = 0 (0x0) "LockTaskbar" = 0 (0x0) "NoTaskGrouping" = 0 (0x0) "NoWebServices" = 0 (0x0) "NoFileUrl" = 0 (0x0) "NoBandCustomize" = 0 (0x0) "NoToolbarCustomize" = 0 (0x0) "NoExpandedNewMenu" = 0 (0x0) "SpecifyDefaultButtons" = 0 (0x0) "NoRecentDocsNetHood" = 0 (0x0) "EnforceShellExtensionSecurity" = 0 (0x0) "NoLogOff" = 0 (0x0) "NoRunasInstallPrompt" = 0 (0x0) "PromptRunasInstallNetPath" = 1 (0x1) "NoResolveTrack" = 0 (0x0) "NoResolveSearch" = 0 (0x0) "NoDevMgrUpdate" = 0 (0x0) "NoThumbnailCache" = 0 (0x0) "ForceCopyAclwithFile" = 0 (0x0) "StartRunNoHOMEPATH" = 0 (0x0) [HKEY_USERS \. Default \ Software \ Microsoft \ windows \ cur rentversion \ Policies \ Explorer] "NoThemesTab" = 0 (0x0) "NoChangeKeyboardNavigationIndicators" = 0 (0x0) "NoChangeAnimation" = 0 (0x0) "NoAddPrinter" = 0 (0x0) "NoDeletePrinter" = 0 (0x0) "RestrictCpl" = 0 (0x0) "DisallowCpl" = 0 (0x0) "NoViewOnDrive" = 0 (0x0) "RestrictRun" = 0 (0x0) "DisallowRun" = 0 (0x0) "NoRecycleFiles" = 0 (0x0) "ForceRecycleBinSize" = 0 (0x0) "NoCustomizeWebView" = 0 (0x0) "NoViewContextMenu" = 0 (0x0) "NoWinKeys" = 0 (0x0) "NoFileAssociate" = 0 (0x0) "NoDFSTab" = 0 (0x0) "NoInstrumentation" = 0 (0x0) "NoCustomizeThisFolder" = 0 (0x0) "NoWebView" = 0 (0x0) "DontShowSuperHidden" = 0 (0x0) "NoOnlinePrintsWizard" = 0 (0x0) "NoPublishingWizard" = 0 (0x0) "NoRun" = 0 (0x0) "NoSMConfigurePrograms" = 0 (0x0) "NoSMMyPictures" = 0 (0x0) "NoStartMenuMyMusic" = 0 (0x0) "NoFavoritesMenu" = 0 (0x0) "NoHelp" = 0 (0x0) "NoCommonGroups" = 0 (0x0) "NoFind" = 0 (0x0) "NoFolderOptions" = 0 (0x0) "NoStartMenuMFUprogramsList" = 0 (0x0) "NoStartMenuPinnedList" = 0 (0x0) "NoUserNameInStartMenu" = 0 (0x0) "NoStartMenuMorePrograms" = 0 (0x0) "NoStartMenuEjectPC" = 0 (0x0) "NoSimpleStartMenu" = 0 (0x0) "ForceStartMenuLogoff" = 0 (0x0) "StartMenuLogoff" = 0 (0x0) "NoStartMenuSubFolders" = 0 (0x0) "NoDisconnect" = 0 (0x0) "NoNtSecurity" = 0 (0x0) "NoSetFolders" = 0 (0x0) "GreyMSIAds" = 0 (0x0) "ForceMaxRecentDocs" = 0 (0x0) "NoSMBalloonTip" = 0 (0x0) "NoSMBalloonTips" = 0 (0x0) "NoTrayContextMenu" = 0 (0x0) "LockTaskbar" = 0 (0x0) "HideClock" = 0 (0x0) "NoTaskGrouping" = 0 (0x0) "NoActiveDesktopChanges" = 0 (0x0) "NoWebServices" = 0 (0x0) "NoFileUrl" = 0 (0x0) "NoBandCustomize" = 0 (0x0) "NoToolbarCustomize" = 0 (0x0) "NoExpandedNewMenu" = 0 (0x0) "SpecifyDefaultButtons" = 0 (0x0) "NoRecentDocsNetHood" = 0 (0x0) "EnforceShellExtensionSecurity" = 0 (0x0) "NoClose" = 0 (0x0) "NoLogOff" = 0 (0x0) "NoRunasInstallPrompt" = 0 (0x0) "PromptRunasInstallNetPath" = 1 (0x1) "NoResolveTrack" = 0 (0x0) "NoResolveSearch" = 0 (0x0) "NoDevMgrUpdate" = 0 (0x0) "NoThumbnailCache" = 0 (0x0) "ForceCopyAclwithFile" = 0 (0x0) "StartRunNoHOMEPATH" = 0 (0x0) [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ anmäla \ LMIinit] LMIinit.dll 2007-11-15 18:46 87352 C: \ WINDOWS \ system32 \ LMIinit.dll [HKEY_LOCAL_MACHINE \ software \ microsoft \ shared tools \ msconfig \ startupreg \ Caffe-server] - a ------ 2006-07-09 15:27 4803072 C: \ Program Files \ Caffe \ Server.exe [HKEY_LOCAL_MACHINE \ software \ microsoft \ shared tools \ msconfig \ startupreg \ SoundMan] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Shared Tools \ msconfig \ startupreg \ Ctfmon.exe] - a ------ 2004-08-19 08:42 30208 C: \ WINDOWS \ system32 \ CTFMON.EXE [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Shared Tools \ msconfig \ startupreg \ igfxhkcmd] - a ------ 2005-09-20 10:32 77824 C: \ WINDOWS \ system32 \ hkcmd.exe [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Shared Tools \ msconfig \ startupreg \ igfxpers] - a ------ 2005-09-20 10:36 114688 C: \ WINDOWS \ system32 \ igfxpers.exe [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Shared Tools \ msconfig \ startupreg \ igfxtray] - a ------ 2005-09-20 10:35 94208 C: \ WINDOWS \ system32 \ igfxtray.exe [HKEY_LOCAL_MACHINE \ software \ microsoft \ shared tools \ msconfig \ startupreg \ kis] C: \ Program \ Kaspersky Lab \ Kaspersky Internet Security 6.0 \ avp.exe [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Shared Tools \ msconfig \ startupreg \ msnmsgr] C: \ Archivos de programa \ MSN Messenger \ msnmsgr.exe [HKEY_LOCAL_MACHINE \ software \ microsoft \ shared tools \ msconfig \ startupreg \ TaskSwitchXP] C: \ Program \ TaskSwitchXP \ TaskSwitchXP.exe [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Shared Tools \ msconfig \ startupreg \ WinampAgent] C: \ Program \ Winamp \ winampa.exe R1 NtFsLdf20; NtFsLdf20 C: \ WINDOWS \ system32 \ drivers \ nt FsLdf20.sys [2002-07-04 13:52] R2 LMIInfo; LogMeIn Kernel Information Provider; C: \ Program \ LogMeIn \ x86 \ RaInfo.sys [2007-08-03 15:09] R2 LMIRfsDriver; LogMeIn Remote File System Driver; C: \ WINDOWS \ system32 \ drivers \ LMIRfsDriver.sy s [2007-08-03 15:09] R3 usbscan; controlador de escáner USB; C: \ WINDOWS \ system32 \ drivers \ usbscan.sys [2006-08-17 21:32] S2 ABBYY.Licensing.FineReader.Professional.9.0; ABBYY FineReader 9,0 Licensing Service; "C: \ Program \ ABBYY FineReader 9.0 \ NetworkLicenseServer.exe" [2007-09-25 00:11] S3 bepldr; BCL easyPDF SDK 5 Loader, "C: \ Program \ WINDOWS comunes \ BCL Technologies \ easyPDF 5 \ bepldr.exe" [2007-08-22 16:19] S3 USBSTOR; Dispositivo de almacenamiento masivo de datos USB; C: \ WINDOWS \ system32 \ drivers \ USBSTOR.SYS [2004-08-03 23:08] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Svchost] LocalService REG_MULTI_SZ Alerter WebClient Lmhosts upnphost SSDPSRV [HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ Curre ntversion \ Explorer \ mountpoints2 \ (5714de88-a427-11dc-861c-00196604d2ae)] \ Shell \ Auto \ command - H: \ Cn911.exe \ Shell \ AutoRun \ command - C: \ WINDOWS \ system32 \ rundll32.exe Shell32.dll, ShellExec_RunDLL Cn911.exe [HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ Curre ntversion \ Explorer \ mountpoints2 \ (68ae8df5-aca4-11dc-81b1-00196604d2ae)] \ Shell \ AutoRun \ command - auto.exe \ Shell \ utforska \ Command - RavMon.exe-e \ Shell \ open \ Command - RavMon.exe [HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ Curre ntversion \ Explorer \ mountpoints2 \ (805ec9a7-a004-11dc-8615-00196604d2ae)] \ Shell \ AutoRun \ command - G: \ LaunchU3.exe-en [HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ Curre ntversion \ Explorer \ mountpoints2 \ (92ef7850-a108-11dc-8619-00196604d2ae)] \ Shell \ Auto \ command - H: \ Cn911.exe \ Shell \ AutoRun \ command - C: \ WINDOWS \ system32 \ rundll32.exe Shell32.dll, ShellExec_RunDLL Cn911.exe [HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ Curre ntversion \ Explorer \ mountpoints2 \ (92ef78aa-a108-11dc-8619-00196604d2ae)] \ Shell \ Auto \ command - H: \ Cn911.exe \ Shell \ AutoRun \ command - C: \ WINDOWS \ system32 \ rundll32.exe Shell32.dll, ShellExec_RunDLL Cn911.exe [HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ Curre ntversion \ Explorer \ mountpoints2 \ (92ef78b4-a108-11dc-8619-00196604d2ae)] \ Shell \ Auto \ command - H: \ Cn911.exe \ Shell \ AutoRun \ command - C: \ WINDOWS \ system32 \ rundll32.exe Shell32.dll, ShellExec_RunDLL Cn911.exe [HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ Curre ntversion \ Explorer \ mountpoints2 \ (b05019b3-A665-11dc-a263-00196604d2ae)] \ Shell \ AutoRun \ command - ntde1ect.com \ Shell \ utforska \ Command - ntde1ect.com \ Shell \ Open \ Command - ntde1ect.com [HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ Curre ntversion \ Explorer \ mountpoints2 \ (d79ae692-9f95-11dc-8614-00196604d2ae)] \ Shell \ AutoRun \ command - G: \ ntde1ect.com \ Shell \ utforska \ Command - G: \ ntde1ect.com \ Shell \ open \ Command - G: \ ntde1ect.com * Newly Created Service * - COMSYSAPP * Newly Created Service * - PROCEXP90 . Contenido de carpeta "Tareas Programadas" "2007-12-08 20:22:33 C: \ WINDOWS \ Tasks \ McDefragTask.job" . ************************************************** ************************ CatchMe 0.3.1344 W2K/XP/Vista - rootkit / stealth malware detector av Gmer, http://www.gmer.net Rootkit scan 2008-01-06 14:51:38 Windows 5.1.2600 Service Pack 2 NTFS escaneando procesos ocultos ... escaneando entradas ocultas de autostart ... escaneando Archivos ocultos ... disk error: C: \ WINDOWS \ ************************************************** ************************ [HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Services \ c atchme] "ImagePath" = "\?? \ C: \ Windows \ Temp \ catchme.sys" . --------------------- DLLs Cargados bajo los procesos en ejecución --------------------- PROCESS: C: \ WINDOWS \ system32 \ Winlogon.exe -> C: \ WINDOWS \ system32 \ usbmons.dll . Tiempo completado: 2008-01-06 14:52:51 ComboFix-quarantined-files.txt 2008-01-06 18:51:58 . 2007-12-18 03:51:13 --- EOF --- Loggfil av Trend Micro HijackThis v2.0.2 Scan saved at 03:32:28, den 06/01/2008 Plattform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Kör processer: C: \ WINDOWS \ System32 \ Smss.exe C: \ WINDOWS \ system32 \ Winlogon.exe C: \ WINDOWS \ system32 \ services.exe C: \ WINDOWS \ system32 \ Lsass.exe C: \ WINDOWS \ system32 \ Svchost.exe C: \ WINDOWS \ System32 \ Svchost.exe C: \ WINDOWS \ system32 \ Svchost.exe C: \ WINDOWS \ system32 \ Spoolsv.exe C: \ Program \ LogMeIn \ x86 \ RaMaint.exe C: \ Program \ LogMeIn \ x86 \ LogMeIn.exe C: \ Archivos de programa \ Archivos comunes \ Microsoft Shared \ VS7DEBUG \ MDM.EXE C: \ WINDOWS \ system32 \ HPZipm12.exe C: \ WINDOWS \ system32 \ Svchost.exe C: \ WINDOWS \ System32 \ Svchost.exe C: \ Program \ LogMeIn \ x86 \ LogMeInSystray.exe C: \ Program \ DAEMON Tools \ daemon.exe C: \ WINDOWS \ system32 \ Ctfmon.exe C: \ WINDOWS \ system32 \ dllhost.exe C: \ WINDOWS \ explorer.exe C: \ Archivos de programa \ Mozilla Firefox \ firefox.exe C: \ Program \ Microsoft Office \ Office11 \ Winword.exe C: \ Program \ Trend Micro \ HijackThis \ asdf.exe R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = cirka: blank R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Toolbar, LinksFolderName = O2 - BHO: Adobe PDF Reader Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program \ Adobe \ Acrobat 7.0 \ ActiveX \ AcroIEHelper.dll O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program \ Java \ jre1.5.0_09 \ bin \ ssv.dll O4 - HKLM \ .. \ Run: [LogMeIn GUI] "C: \ Program \ LogMeIn \ x86 \ LogMeInSystray.exe" O4 - HKLM \ .. \ Run: [DAEMON Tools] "C: \ Program \ DAEMON Tools \ daemon.exe"-lang 1033 O4 - HKCU \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe O4 - HKLM \ .. \ Run: [MsnMsgr] "C: \ Program \ Windows Live \ Messenger \ msmsgs.exe" / background O4 - HKLM \ .. \ Run: [Comrade.exe] C: \ Program \ GameSpy \ Comrade \ Comrade.exe O4 - HKUS \ S-1-5-19 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe (User "Servicio LOCAL) O4 - HKUS \ S-1-5-20 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe (User "Servicio de röda") O4 - HKUS \ S-1-5-18 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe (User "SYSTEM") O4 - HKUS \. DEFAULT \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe (User 'Default user') O6 - HKCU \ Software \ Policies \ Microsoft \ Internet Explorer \ Toolbars \ Restrictions nuvarande O8 - Extra sammanhang menyobjektet: E & xportar en Microsoft Excel - res: / / C: \ Archiv ~ 1 \ mikro ~ 1 \ Office11 \ EXCEL.EXE/3000 O9 - Extra button: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program \ Java \ jre1.5.0_09 \ bin \ ssv.dll O9 - Extra 'Tools' menuitem: Consola de Sun Java - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program \ Java \ jre1.5.0_09 \ bin \ ssv.dll Ø9 - Extra button: Referencia - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ Archiv ~ 1 \ mikro ~ 1 \ Office11 \ REFIEBAR.DLL O16 - DPF: (05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8) (Office Genuine Advantage Validation Tool) -- http://go.microsoft.com/fwlink/?linkid=58813 O16 - DPF: (5D6F45B3-9043-443D-a792-115447494D24) (UnoCtrl Class) -- http://messenger.zone.msn.com/ES-LA/.../GAME_UNO1.cab O16 - DPF: (B8BE5E93-A60C-4D26-A2DC-220313175592) (MSN Games - Installer) -- http://messenger.zone.msn.com/binary...o.cab56649.cab O16 - DPF: (C3F79A2B-B9B4-4A66-B012-3EE46475B072) (MessengerStatsClient Class) -- http://messenger.zone.msn.com/binary...t.cab56907.cab O17 - HKLM \ System \ CCS \ Services \ Tcpip \ .. \ (BAA62A6B-DD15-4E55-a719-401AF676E3A9): NameServer = 10.0.0.1,10.0.0.2 O23 - Service: ABBYY FineReader 9,0 Licensing Service (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - C: \ Program \ ABBYY FineReader 9.0 \ NetworkLicenseServer.exe O23 - Service: Ares Chattrum server (AresChatServer) - Ares Development Group - C: \ Archivos de programa \ Ares \ chatServer.exe O23 - Service: BCL easyPDF SDK 5 Loader (bepldr) - Unknown owner - C: \ Program \ WINDOWS comunes \ BCL Technologies \ easyPDF 5 \ bepldr.exe O23 - Service: indexeringstjänsten (CiSvc) - Unknown ägaren - C: \ WINDOWS \ system32 \ cisvc.exe (fil saknas) O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C: \ Program \ LogMeIn \ x86 \ RaMaint.exe O23 - Service: LogMeIn - LogMeIn, Inc. - C: \ Program \ LogMeIn \ x86 \ LogMeIn.exe O23 - Service: PML Driver HPZ12 - HP - C: \ WINDOWS \ system32 \ HPZipm12.exe O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C: \ Program \ Spyware Doctor \ svcntaux.exe O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C: \ Program \ Spyware Doctor \ swdsvc.exe -- End of file - 4754 bytes |
|
#6
| |||
| |||
| Det fick ett par av dem men det finns ännu mer. Hämta SDFix.exe och spara den på skrivbordet. Dubbelklicka SDFix.exe och det kommer att extrahera filerna till% SystemDrive% (Enhet som innehåller Windows-katalogen, normalt C: \ SDFix) Var vänlig och starta om datorn i Felsäkert läge genom att göra följande:
Nästa post SDFix log Ny HijackThis log |
|
#7
| |||
| |||
| Problemet löst. :) Thnx |
|
#8
| |||
| |||
| |
|
#9
| |||
| |||
| no prob. |
![]() |
|
| Komihåglista |
Liknande Trådar | ||||
| Tråd | Thread Starter | Forum | Svar | Senaste Inlägg |
| Firefox Omdirigering till falskt Site när du använder Google Search | UncleSlam | Virus, spionprogram och säkerhet | 27 | 12 mars 2009 14:45 |
| Outlook sökning och avancerad sökning inte fungerar (försökt återuppbygga index) | Psychotron | Office Suites & Applications | 1 | 16 juli 2008 19:22 |
| XP SP3 cripples vissa datorer med oändliga omstarter | SocialWarfare | Windows-operativsystem | 5 | 9 maj 2008 09:56 |
| Visste Something Stupid | FunkyJuice | Processorer, moderkort & RAM | 10 | 5 februari 2008 17:09 |
| Endless Problem, Windows wont Börja nu | Polkigtry | General Hardware Chat | 2 | 13 januari 2008 02:06 |
| Thread Tools | |
| |