Just nu i M3-nätverket
Jump to content

Hijacklo


hawkiii123

Recommended Posts

Hejsan, jag har lite virus/trojanproblem på min laptop och skulle vara tacksam om någon här kunde ta en titt på min hijackthislogg:

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 20:44:42, on 2010-08-12

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program\AVG\AVG9\avgchsvx.exe

C:\Program\AVG\AVG9\avgrsx.exe

C:\Program\AVG\AVG9\avgcsrvx.exe

C:\WINDOWS\system32\ZoneLabs\vsmon.exe

C:\Program\CheckPoint\ZAForceField\IswSvc.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe

C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program\AVG\AVG9\avgwdsvc.exe

C:\Program\Bonjour\mDNSResponder.exe

C:\Program\Java\jre6\bin\jqs.exe

C:\Program\Telenor\Connection Manager\Sesam\BIN\SecMIPService.exe

C:\WINDOWS\system32\svchost.exe

C:\Program\AVG\AVG9\avgnsx.exe

C:\Program\Sony Ericsson\Sony Ericsson MD400 Wireless Modem\wwanSvc.exe

C:\Program\AVG\AVG9\avgemc.exe

C:\WINDOWS\Explorer.EXE

C:\Program\AVG\AVG9\avgcsrvx.exe

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

C:\WINDOWS\system32\igfxsrvc.exe

C:\Program\Telenor\Connection Manager\Connection Manager.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Program\Synaptics\SynTP\SynTPEnh.exe

C:\Program\LAUNCH~1\LManager.exe

C:\Program\Java\jre6\bin\jusched.exe

C:\Program\iTunes\iTunesHelper.exe

C:\Program\AVG\AVG9\avgtray.exe

C:\Program\Zone Labs\ZoneAlarm\zlclient.exe

C:\WINDOWS\system32\igfxext.exe

C:\Documents and Settings\Mag\Lokala inställningar\Application Data\gvkdwsula\ouvwubitssd.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program\Windows Live\Messenger\msnmsgr.exe

C:\Program\Messenger\msmsgs.exe

C:\Program\iPod\bin\iPodService.exe

C:\DOCUME~1\Mag\LOKALA~1\Temp\RtkBtMnt.exe

C:\Program\CheckPoint\ZAForceField\ForceField.exe

C:\WINDOWS\System32\svchost.exe

C:\Program\Mozilla Firefox\firefox.exe

C:\Program\Mozilla Firefox\plugin-container.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\msiexec.exe

C:\Program\Trend Micro\HiJackThis\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.packardbell.com/rdr.aspx?b=ACPW&l=041d&s=0&o=xph&d=0409&m=doa150'>http://homepage.packardbell.com/rdr.aspx?b=ACPW&l=041d&s=0&o=xph&d=0409&m=doa150

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.packardbell.com/rdr.aspx?b=ACPW&l=041d&s=0&o=xph&d=0409&m=doa150

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157'>http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896'>http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar

R3 - URLSearchHook: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program\ZoneAlarm\tbZone.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program\Delade filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program\AVG\AVG9\avgssie.dll

O2 - BHO: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program\ZoneAlarm\tbZone.dll

O2 - BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll

O2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program\Delade filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program\google\googletoolbar1.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program\Google\GoogleToolbarNotifier\3.1.415.1646\swg.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program\google\googletoolbar1.dll

O3 - Toolbar: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program\ZoneAlarm\tbZone.dll

O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [AzMixerSel] C:\Program\Realtek\Audio\Drivers\AzMixerSel.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Program\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [LManager] C:\Program\LAUNCH~1\LManager.exe

O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program\Google\Google Desktop Search\GoogleDesktop.exe" /startup

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC

O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe

O4 - HKLM\..\Run: [snp2uvc] rundll32.exe C:\WINDOWS\system32\csnp2uvc.dll,ResetCIDS

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [AVG9_TRAY] C:\Program\AVG\AVG9\avgtray.exe

O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program\Zone Labs\ZoneAlarm\zlclient.exe"

O4 - HKLM\..\Run: [iSW] "C:\Program\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"

O4 - HKLM\..\Run: [sjyxmoiq] C:\Documents and Settings\Mag\Lokala inställningar\Application Data\gvkdwsula\ouvwubitssd.exe

O4 - HKLM\..\Run: [lijyxvnd] C:\Documents and Settings\Mag\Lokala inställningar\Application Data\pjccwlifr\odqaawytssd.exe

O4 - HKLM\..\Run: [sta] rundll32 "husap.dll",,Run

O4 - HKLM\..\Run: [MChk] C:\WINDOWS\system32\uusap.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Program\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [MSMSGS] "C:\Program\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [skype] "C:\Program\Skype\\Phone\Skype.exe" /nosplash /minimized

O4 - HKCU\..\Run: [sjyxmoiq] C:\Documents and Settings\Mag\Lokala inställningar\Application Data\gvkdwsula\ouvwubitssd.exe

O4 - HKCU\..\Run: [lijyxvnd] C:\Documents and Settings\Mag\Lokala inställningar\Application Data\pjccwlifr\odqaawytssd.exe

O4 - HKCU\..\Run: [12CFG214-K641-12SF-N85P] C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Blogga detta - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Blogga detta i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Skicka till OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: Ski&cka till OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program\AVG\AVG9\avgpp.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program\DELADE~1\Skype\SKYPE4~1.DLL

O20 - AppInit_DLLs: C:\Program\Google\GOOGLE~1\GOEC62~1.DLL

O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)

O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program\AVG\AVG9\avgemc.exe

O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program\AVG\AVG9\avgwdsvc.exe

O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program\Bonjour\mDNSResponder.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program\Delade filer\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Google Desktop-hanteraren 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program\Google\Google Desktop Search\GoogleDesktop.exe

O23 - Service: GTMM Device Service - Option nv - C:\Program\Telenor\Connection Manager\GtmmDeviceService.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program\iPod\bin\iPodService.exe

O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program\CheckPoint\ZAForceField\IswSvc.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program\Java\jre6\bin\jqs.exe

O23 - Service: Sesam Control Service (SesamService) - Swisscom - C:\Program\Telenor\Connection Manager\Sesam\BIN\SecMIPService.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

O23 - Service: wwanSvc - Unknown owner - C:\Program\Sony Ericsson\Sony Ericsson MD400 Wireless Modem\wwanSvc.exe

 

--

End of file - 11835 bytes

 

 

Tackar!

Link to comment
Share on other sites

Hej,

en DDS logg ger betydligt mer information än HiJack This.

Läs igenom och ge oss så mycket info du kan.

För att du ska få så bra hjälp som möjligt så är det bra om nedanstående information finns i ditt inlägg.

 

Beskriv noga vad du har för problem med datorn, varför du tror eller vet att det finns skadliga program i datorn.

 

Om något antivirus- eller antispionprogram har hittat något skadligt så klistra in en logg där det framgår vad som har hittats och vilka filer och mappar som är inblandade.

 

Klistra in loggen/resultatet från programmet DDS. Spara DDS på Skrivbordet.

http://download.blee...om/sUBs/dds.scr

Starta programmet genom att dubbelklicka på det.

Tryck Yes/Ja om frågan om Optional Scan dyker upp.

I ditt svar klistrar du in loggen DSS.txt. Medan du bifogar Attach.txt som en fil.

 

DDS är ett program som listar processer som kör, program och tjänster som startas automatiskt samt filer i sådana mappar som är vanliga att skadliga program och som är nya eller ändrade under senaste 1-3 månader. DDS är ett mycket vanligt program bland oss som hjälper till att rensa datorer. Resultatet ger oss en grundläggande kunskap om vad som händer och har hänt nyligen i datorn, och från det kan vi dra slutsatser om vad som är nästa lämpliga steg i rensningen av datorn.

 

Obs! När du klistrar in en logg eller ett resultat i ditt inlägg använd inga knappar eller taggar utan kopiera det i programmet (oftast Anteckningar) och klistra in det direkt i rutan du skriver i.

Mvh

Mats H

Link to comment
Share on other sites

Hej, tack för ditt svar!

 

Problem jag upplever är felmeddelanden när jag startar upp, en .dll som tydligen saknas. Dessutom så börjar mitt AVG antivirus och zone alarm brandvägg varna för trojaner och okända program.

 

 

AVG har följande i sitt "vault"

 

"Infection";"Trojan horse Dropper.Generic2.AHER";"c:\Documents and Settings\Mag\Lokala inställningar\Temp\753410.exe";"";"2010-08-10, 21:14:21"

"Infection";"Trojan horse BackDoor.Generic12.CEEJ";"c:\Documents and Settings\Mag\Lokala inställningar\Temp\8556799.exe";"";"2010-08-10, 21:14:22"

"Infection";"Trojan horse Generic18.BJMB";"c:\Documents and Settings\Mag\Lokala inställningar\Temporary Internet Files\Content.IE5\1IC9GD1T\secureapp70700[1].exe";"";"2010-08-10, 21:14:23"

"Infection";"Trojan horse Generic18.BFEE";"c:\Documents and Settings\Mag\Lokala inställningar\Temp\9218.exe";"";"2010-08-10, 21:14:24"

"Infection";"Trojan horse Downloader.Generic9.CFQM";"c:\Documents and Settings\Mag\Lokala inställningar\Temp\532.exe";"";"2010-08-10, 21:14:25"

"Infection";"Trojan horse Generic18.AQRH";"c:\WINDOWS\system32\dusap.dll";"";"2010-08-10, 21:14:30"

"PUP";"Adware Generic4.AKPT";"c:\WINDOWS\system32\husap.dll";"";"2010-08-10, 21:14:31"

"Infection";"Trojan horse Generic18.BJMB";"c:\Documents and Settings\Mag\Lokala inställningar\Temporary Internet Files\Content.IE5\1IC9GD1T\secureapp70700[2].exe";"";"2010-08-10, 21:14:32"

"Infection";"Trojan horse Generic18.BJMB";"c:\Documents and Settings\Mag\Application Data\FCD4057AB9E5D43C034BD3A2FDF29011\secureapp70700.exe";"";"2010-08-10, 21:20:21"

"Infection";"Trojan horse Generic18.BJMB";"c:\Documents and Settings\Mag\Lokala inställningar\Temporary Internet Files\Content.IE5\1IC9GD1T\secureapp70700[1].exe";"";"2010-08-10, 21:24:46"

"Infection";"Trojan horse Downloader.Generic_c.BOC";"c:\WINDOWS\system32\uusap.exe";"";"2010-08-10, 21:45:49"

"Infection";"Trojan horse SHeur3.ARPA";"C:\DOCUME~1\Mag\LOKALA~1\Temp\xmeaonwcrs.tmp";"";"2010-08-10, 21:51:26"

"Warning";"Found registry key with reference to infected file C:\DOCUME~1\Mag\LOKALA~1\Temp\xmeaonwcrs.tmp";"HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\lsdefrag";"";"2010-08-10, 21:51:26"

"Infection";"Trojan horse Generic18.BJMB";"C:\Documents and Settings\Mag\Application Data\FCD4057AB9E5D43C034BD3A2FDF29011\secureapp70700.exe";"";"2010-08-10, 21:58:09"

"Infection";"Trojan horse BackDoor.Generic12.CEEJ";"C:\Documents and Settings\Mag\Lokala inställningar\Temporary Internet Files\Content.IE5\9EKAQOPQ\backbot[1].exe";"";"2010-08-10, 22:00:42"

"Infection";"Trojan horse Generic18.BFEE";"C:\Documents and Settings\Mag\Lokala inställningar\Temporary Internet Files\Content.IE5\9EKAQOPQ\new[1].exe";"";"2010-08-10, 22:00:54"

"Infection";"Trojan horse Dropper.Generic2.AHER";"C:\Documents and Settings\Mag\Lokala inställningar\Temporary Internet Files\Content.IE5\9EKAQOPQ\pr[1].exe";"";"2010-08-10, 22:00:55"

"Infection";"Trojan horse Downloader.Generic9.CFQM";"C:\Documents and Settings\Mag\Lokala inställningar\Temporary Internet Files\Content.IE5\L67PTF10\rp020832[1].exe";"";"2010-08-10, 22:01:43"

"Infection";"Trojan horse BackDoor.Generic12.CEEJ";"c:\Documents and Settings\Mag\Lokala inställningar\Temporary Internet Files\Content.IE5\1IC9GD1T\backbot[1].exe";"";"2010-08-12, 20:32:49"

"Infection";"Trojan horse Downloader.Agent2.AAMI";"c:\Documents and Settings\Mag\Lokala inställningar\Temporary Internet Files\Content.IE5\1IC9GD1T\loaderadv600[1].exe";"";"2010-08-12, 20:32:57"

"Infection";"Trojan horse Downloader.Generic9.CFQM";"c:\Documents and Settings\Mag\Lokala inställningar\Temporary Internet Files\Content.IE5\1IC9GD1T\rp020832[1].exe";"";"2010-08-12, 20:33:07"

"Infection";"Trojan horse Downloader.Agent2.AAMI";"c:\Documents and Settings\Mag\Lokala inställningar\Temporary Internet Files\Content.IE5\9EKAQOPQ\loaderadv600[1].exe";"";"2010-08-12, 20:34:01"

"Infection";"Trojan horse Generic18.BLTW";"c:\Documents and Settings\Mag\Lokala inställningar\Temporary Internet Files\Content.IE5\9EKAQOPQ\kofmhoahpk[1].htm";"";"2010-08-12, 20:34:01"

"Infection";"Trojan horse Generic18.BMMR";"c:\Documents and Settings\Mag\Lokala inställningar\Temporary Internet Files\Content.IE5\9EKAQOPQ\sjnvpnidk[1].htm";"";"2010-08-12, 20:34:02"

"Infection";"Trojan horse Generic18.BMGP";"c:\Documents and Settings\Mag\Lokala inställningar\Temporary Internet Files\Content.IE5\FE0PJA1N\imhbjepxrz[3].htm";"";"2010-08-12, 20:34:34"

"Infection";"Trojan horse Downloader.Generic9.CFQM";"c:\Documents and Settings\Mag\Lokala inställningar\Temp\75181.exe";"";"2010-08-12, 20:35:40"

"Infection";"Trojan horse BackDoor.Generic12.CEEJ";"c:\Documents and Settings\Mag\Lokala inställningar\Temp\559288.exe";"";"2010-08-12, 20:35:40"

"Infection";"Trojan horse Generic18.BLTW";"c:\Documents and Settings\Mag\Lokala inställningar\Temp\llipk.exe";"";"2010-08-12, 20:35:40"

"Infection";"Trojan horse Generic18.BMHL";"c:\Documents and Settings\Mag\Lokala inställningar\Application Data\gvkdwsula\ouvwubitssd.exe";"";"2010-08-12, 21:45:52"

 

 

 

DDS-logg:

 

 

DDS (Ver_10-03-17.01) - NTFSx86

Run by Mag at 21:48:30,23 on 2010-08-12

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15

Microsoft Windows XP Home Edition 5.1.2600.3.1252.46.1053.18.1012.221 [GMT 3:00]

 

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

 

 

 

 

============== Running Processes ===============

 

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

C:\Program\AVG\AVG9\avgchsvx.exe

svchost.exe

C:\Program\AVG\AVG9\avgrsx.exe

C:\Program\AVG\AVG9\avgcsrvx.exe

svchost.exe

C:\WINDOWS\system32\ZoneLabs\vsmon.exe

C:\Program\CheckPoint\ZAForceField\IswSvc.exe

C:\WINDOWS\system32\spoolsv.exe

svchost.exe

C:\Program\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe

C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program\AVG\AVG9\avgwdsvc.exe

C:\Program\Bonjour\mDNSResponder.exe

C:\Program\Java\jre6\bin\jqs.exe

C:\Program\Telenor\Connection Manager\Sesam\BIN\SecMIPService.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\Program\AVG\AVG9\avgnsx.exe

C:\Program\Sony Ericsson\Sony Ericsson MD400 Wireless Modem\wwanSvc.exe

C:\Program\AVG\AVG9\avgemc.exe

C:\WINDOWS\Explorer.EXE

C:\Program\AVG\AVG9\avgcsrvx.exe

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\igfxpers.exe

C:\WINDOWS\system32\igfxsrvc.exe

C:\Program\Telenor\Connection Manager\Connection Manager.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Program\Synaptics\SynTP\SynTPEnh.exe

C:\Program\LAUNCH~1\LManager.exe

C:\Program\Java\jre6\bin\jusched.exe

C:\Program\iTunes\iTunesHelper.exe

C:\Program\AVG\AVG9\avgtray.exe

C:\Program\Zone Labs\ZoneAlarm\zlclient.exe

C:\WINDOWS\system32\igfxext.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program\Windows Live\Messenger\msnmsgr.exe

C:\Program\Messenger\msmsgs.exe

C:\Program\iPod\bin\iPodService.exe

C:\DOCUME~1\Mag\LOKALA~1\Temp\RtkBtMnt.exe

C:\Program\CheckPoint\ZAForceField\ForceField.exe

C:\WINDOWS\System32\svchost.exe -k HTTPFilter

C:\Program\Mozilla Firefox\firefox.exe

C:\Program\Mozilla Firefox\plugin-container.exe

C:\WINDOWS\system32\wuauclt.exe

C:\DOCUME~1\Mag\LOKALA~1\Temp\12620.exe

C:\Documents and Settings\Mag\Mina dokument\Hämtade filer\dds.scr

 

============== Pseudo HJT Report ===============

 

uStart Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=041d&s=0&o=xph&d=0409&m=doa150

uDefault_Page_URL = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=041d&s=0&o=xph&d=0409&m=doa150

uInternet Settings,ProxyOverride = *.local

uURLSearchHooks: ZoneAlarm Toolbar: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - c:\program\zonealarm\tbZone.dll

mWinlogon: Taskman=c:\documents and settings\mag\application data\ohydy.exe

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program\delade filer\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program\avg\avg9\avgssie.dll

BHO: ZoneAlarm Toolbar: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - c:\program\zonealarm\tbZone.dll

BHO: ZoneAlarm Security Engine Registrar: {8a4a36c2-0535-4d2c-bd3d-496cb7eed6e3} - c:\program\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll

BHO: Windows Live inloggningshjälpen: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program\delade filer\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program\google\googletoolbar1.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program\google\googletoolbarnotifier\3.1.415.1646\swg.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program\google\googletoolbar1.dll

TB: ZoneAlarm Toolbar: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - c:\program\zonealarm\tbZone.dll

TB: ZoneAlarm Security Engine: {ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107} - c:\program\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll

uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe

uRun: [msnmsgr] "c:\program\windows live\messenger\msnmsgr.exe" /background

uRun: [MSMSGS] "c:\program\messenger\msmsgs.exe" /background

uRun: [<NO NAME>]

uRun: [skype] "c:\program\skype\\phone\Skype.exe" /nosplash /minimized

uRun: [sjyxmoiq] c:\documents and settings\mag\lokala inställningar\application data\gvkdwsula\ouvwubitssd.exe

uRun: [lijyxvnd] c:\documents and settings\mag\lokala inställningar\application data\pjccwlifr\odqaawytssd.exe

uRun: [12CFG214-K641-12SF-N85P] c:\recycler\s-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe

mRun: [igfxTray] c:\windows\system32\igfxtray.exe

mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe

mRun: [Persistence] c:\windows\system32\igfxpers.exe

mRun: [RTHDCPL] RTHDCPL.EXE

mRun: [Alcmtr] ALCMTR.EXE

mRun: [AzMixerSel] c:\program\realtek\audio\drivers\AzMixerSel.exe

mRun: [synTPEnh] c:\program\synaptics\syntp\SynTPEnh.exe

mRun: [LManager] c:\program\launch~1\LManager.exe

mRun: [Google Desktop Search] "c:\program\google\google desktop search\GoogleDesktop.exe" /startup

mRun: [Adobe Reader Speed Launcher] "c:\program\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [iMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC

mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC

mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName

mRun: [PLFSetL] c:\windows\PLFSetL.exe

mRun: [snp2uvc] rundll32.exe c:\windows\system32\csnp2uvc.dll,ResetCIDS

mRun: [sunJavaUpdateSched] "c:\program\java\jre6\bin\jusched.exe"

mRun: [QuickTime Task] "c:\program\quicktime\QTTask.exe" -atboottime

mRun: [iTunesHelper] "c:\program\itunes\iTunesHelper.exe"

mRun: [AVG9_TRAY] c:\program\avg\avg9\avgtray.exe

mRun: [ZoneAlarm Client] "c:\program\zone labs\zonealarm\zlclient.exe"

mRun: [iSW] "c:\program\checkpoint\zaforcefield\ForceField.exe" /icon="hidden"

mRun: [sjyxmoiq] c:\documents and settings\mag\lokala inställningar\application data\gvkdwsula\ouvwubitssd.exe

mRun: [lijyxvnd] c:\documents and settings\mag\lokala inställningar\application data\pjccwlifr\odqaawytssd.exe

mRun: [sta] rundll32 "husap.dll",,Run

mRun: [MChk] c:\windows\system32\uusap.exe

mRun: [Microsoft Driver Setup] c:\windows\cfdrive32.exe

dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE

mExplorerRun: [Microsoft Driver Setup] c:\windows\cfdrive32.exe

IE: E&xportera till Microsoft Excel - c:\program\micros~2\office12\EXCEL.EXE/3000

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program\messenger\msmsgs.exe

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program\windows live\writer\WriterBrowserExtension.dll

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program\micros~2\office12\ONBttnIE.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\program\micros~2\office12\REFIEBAR.DLL

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab

Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program\avg\avg9\avgpp.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program\delade~1\skype\SKYPE4~1.DLL

Notify: avgrsstarter - avgrsstx.dll

Notify: igfxcui - igfxdev.dll

AppInit_DLLs: c:\program\google\google~1\GOEC62~1.DLL

 

================= FIREFOX ===================

 

FF - ProfilePath - c:\docume~1\mag\applic~1\mozilla\firefox\profiles\bqxpcojq.default\

FF - component: c:\program\avg\avg9\firefox\components\avgssff.dll

FF - component: c:\program\checkpoint\zaforcefield\trustchecker\components\TrustCheckerMozillaPlugin.dll

FF - component: c:\program\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll

FF - plugin: c:\documents and settings\mag\application data\mozilla\firefox\profiles\bqxpcojq.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll

FF - plugin: c:\program\checkpoint\zaforcefield\trustchecker\bin\npFFApi.dll

FF - plugin: c:\program\windows live\photo gallery\NPWLPG.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

FF - HiddenExtension: Java Console: No Registry Reference - c:\program\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

FF - HiddenExtension: Java Console: No Registry Reference - c:\program\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

 

---- FIREFOX POLICIES ----

c:\program\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.visited_color", "#551A8B");

c:\program\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);

c:\program\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);

c:\program\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);

c:\program\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);

c:\program\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);

c:\program\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);

c:\program\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);

c:\program\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);

c:\program\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);

c:\program\mozilla firefox\greprefs\all.js - pref("html5.enable", false);

c:\program\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);

c:\program\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

c:\program\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);

c:\program\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");

c:\program\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");

c:\program\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.videoFeeds.handler", "ask");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

 

============= SERVICES / DRIVERS ===============

 

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-7-28 216400]

R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-7-28 29584]

R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-7-28 243024]

R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2009-7-27 532224]

R2 avg9emc;AVG Free E-mail Scanner;c:\program\avg\avg9\avgemc.exe [2010-7-28 921952]

R2 avg9wd;AVG Free WatchDog;c:\program\avg\avg9\avgwdsvc.exe [2010-7-28 308136]

R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program\checkpoint\zaforcefield\ISWKL.sys [2010-5-26 26352]

R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program\checkpoint\zaforcefield\ISWSVC.exe [2010-5-26 493032]

R2 SesamService;Sesam Control Service;c:\program\telenor\connection manager\sesam\bin\SecMIPService.exe [2008-5-9 1216296]

R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?]

R2 wwanSvc;wwanSvc;c:\program\sony ericsson\sony ericsson md400 wireless modem\wwanSvc.exe [2008-10-14 106496]

R3 TSWLAN;TsWlan Packet Driver;c:\windows\system32\drivers\TsWlan.sys [2008-10-17 33664]

R3 wtsmpadap;Sesam Virtual Adapter;c:\windows\system32\drivers\wtsmpadap.sys [2008-4-29 39720]

R3 WtSmpFlt;Sesam Adapter;c:\windows\system32\drivers\wtsmpflt.sys [2008-4-29 272424]

S3 GoogleDesktopManager-080708-050100;Google Desktop-hanteraren 5.7.808.7150;c:\program\google\google desktop search\GoogleDesktop.exe [2009-1-20 24064]

S3 GTMM Device Service;GTMM Device Service;c:\program\telenor\connection manager\GtmmDeviceService.exe [2008-11-26 106496]

S3 seu3bus;Sony Ericsson MD400g Mobile Broadband Composite Device driver (WDM);c:\windows\system32\drivers\seu3bus.sys [2008-8-13 307200]

S3 seu3card;Sony Ericsson MD400g Device Mgmt;c:\windows\system32\drivers\seu3card.sys [2008-8-13 380800]

S3 seu3mdfl;Sony Ericsson MD400g Mobile Broadband Modem Filter;c:\windows\system32\drivers\seu3mdfl.sys [2008-8-13 14976]

S3 seu3mdfl2;Sony Ericsson MD400g Mobile Broadband Data Modem Filter;c:\windows\system32\drivers\seu3mdfl2.sys [2008-8-13 14976]

S3 seu3mdm;Sony Ericsson MD400g Mobile Broadband Modem Driver;c:\windows\system32\drivers\seu3mdm.sys [2008-8-13 389376]

S3 seu3mdm2;Sony Ericsson MD400g Mobile Broadband Data Modem Driver;c:\windows\system32\drivers\seu3mdm2.sys [2008-8-13 434176]

S3 seu3nd5;Sony Ericsson MD400g Mobile Broadband Network Adapter (NDIS);c:\windows\system32\drivers\seu3nd5.sys [2008-8-13 25984]

S3 seu3unic;Sony Ericsson MD400g Mobile Broadband Network Adapter (WDM);c:\windows\system32\drivers\seu3unic.sys [2008-8-13 405504]

S3 Sony_EricssonWWSC;Sony Ericsson PC SC Port;c:\windows\system32\drivers\seu3scard.sys [2008-8-8 24232]

 

=============== Created Last 30 ================

 

2010-08-12 17:46:47 122880 --sh--r- c:\windows\cfdrive32.exe

2010-08-12 17:43:39 0 d-----w- c:\program\Trend Micro

2010-08-12 17:31:22 0 d-----w- c:\program\CCleaner

2010-08-10 18:14:20 0 d--h--w- C:\$AVG

2010-08-10 18:13:21 111616 --sh--r- c:\docume~1\mag\applic~1\ohydy.exe

2010-08-10 18:12:18 0 d-----w- c:\docume~1\mag\applic~1\FCD4057AB9E5D43C034BD3A2FDF29011

2010-08-06 12:45:55 0 d-----w- c:\program\AviSynth 2.5

2010-08-06 12:45:38 0 d-----w- c:\program\Red Kawa

2010-07-29 09:15:42 0 d-----w- c:\docume~1\mag\applic~1\CheckPoint

2010-07-29 09:15:17 0 d-----w- c:\program\Conduit

2010-07-29 09:15:15 0 d-----w- c:\program\ZoneAlarm

2010-07-29 09:14:57 0 d-----w- c:\program\CheckPoint

2010-07-28 12:49:24 12536 ----a-w- c:\windows\system32\avgrsstx.dll

2010-07-28 12:49:19 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys

2010-07-28 12:49:06 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys

2010-07-28 12:48:58 0 d-----w- c:\windows\system32\drivers\Avg

2010-07-28 12:44:04 0 d-----w- c:\program\AVG

2010-07-28 12:43:33 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9

 

==================== Find3M ====================

 

2010-07-29 09:14:49 4212 ---ha-w- c:\windows\system32\zllictbl.dat

2010-07-22 19:18:34 84026 ----a-w- c:\windows\system32\perfc01D.dat

2010-07-22 19:18:34 444892 ----a-w- c:\windows\system32\perfh01D.dat

2010-06-23 10:51:22 1238528 ----a-w- c:\windows\system32\zpeng25.dll

2009-04-27 18:16:12 32768 --sha-w- c:\windows\system32\config\systemprofile\lokala inställningar\tidigare\history.ie5\mshist012009042720090428\index.dat

 

============= FINISH: 21:51:32,73 ===============

Link to comment
Share on other sites

Hej,

starta i FelSäkert läge med nätverk, logga in som administratör.

Installera Malwarebytes' Anti-Malware

kör en snabbskanner, följ programmets instruktioner,återkom med en logg,

hittas under fliken loggar.

Om det inte går att installera eller köra, återkom direkt.

Bifoga också filen Attach.txt från din DDS körning.

Mvh

Mats H

Link to comment
Share on other sites

Hej,

starta i FelSäkert läge med nätverk, logga in som administratör.

Installera Malwarebytes' Anti-Malware

kör en snabbskanner, följ programmets instruktioner,återkom med en logg,

hittas under fliken loggar.

Om det inte går att installera eller köra, återkom direkt.

Bifoga också filen Attach.txt från din DDS körning.

Mvh

Mats H

 

 

Beklagar att mitt svar dröjt, men här kommer iaf loggen från malware

 

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

 

Database version: 4422

 

Windows 5.1.2600 Service Pack 3 (Safe Mode)

Internet Explorer 8.0.6001.18702

 

2010-08-12 23:14:53

mbam-log-2010-08-12 (23-14-53).txt

 

Scan type: Quick scan

Objects scanned: 137120

Time elapsed: 9 minute(s), 0 second(s)

 

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 4

Registry Values Infected: 8

Registry Data Items Infected: 0

Folders Infected: 2

Files Infected: 11

 

Memory Processes Infected:

(No malicious items detected)

 

Memory Modules Infected:

(No malicious items detected)

 

Registry Keys Infected:

HKEY_CLASSES_ROOT\AppID\{84c3c236-f588-4c93-84f4-147b2abbe67b} (Adware.Adrotator) -> No action taken.

HKEY_CLASSES_ROOT\AppID\{38061edc-40bb-4618-a8da-e56353347e6d} (Adware.EZlife) -> No action taken.

HKEY_CLASSES_ROOT\AppID\{7b6a2552-e65b-4a9e-add4-c45577ffd8fd} (Adware.EZLife) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$NtUninstallMTF1011$ (Adware.Adrotator) -> No action taken.

 

Registry Values Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lijyxvnd (Trojan.FakeAlert) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Worm.Palevo) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell (Worm.Palevo) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sta (Trojan.Agent.Gen) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\microsoft driver setup (Worm.Palevo) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sjyxmoiq (Rogue.AntivirusSuite.Gen) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mchk (Trojan.Agent.Gen) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\microsoft driver setup (Worm.Palevo) -> No action taken.

 

Registry Data Items Infected:

(No malicious items detected)

 

Folders Infected:

C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811 (Trojan.Agent) -> No action taken.

C:\WINDOWS\$NtUninstallMTF1011$ (Adware.Adrotator) -> No action taken.

 

Files Infected:

C:\Documents and Settings\Mag\Lokala inställningar\Application Data\pjccwlifr\odqaawytssd.exe (Trojan.FakeAlert) -> No action taken.

C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe (Worm.Autorun.B) -> No action taken.

C:\Documents and Settings\Mag\Lokala inställningar\Temp\218.exe (Backdoor.Agent) -> No action taken.

C:\Documents and Settings\Mag\Lokala inställningar\Temp\311.exe (Malware.Packer.Gen) -> No action taken.

C:\Documents and Settings\Mag\Lokala inställningar\Temp\74566.exe (Backdoor.Agent) -> No action taken.

C:\Documents and Settings\Mag\Lokala inställningar\Temp\9393.exe (Malware.Packer.Gen) -> No action taken.

C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\Desktop.ini (Trojan.Agent) -> No action taken.

C:\WINDOWS\$NtUninstallMTF1011$\apUninstall.exe (Adware.Adrotator) -> No action taken.

C:\Documents and Settings\Administratör\Application Data\ohydy.exe (Worm.Palevo) -> No action taken.

C:\Documents and Settings\Mag\Application Data\ohydy.exe (Worm.Palevo) -> No action taken.

C:\WINDOWS\cfdrive32.exe (Worm.Palevo) -> No action taken.

 

 

Jag hade möjlighet att ta bort dessa filer, ska jag göra det eller vänta?

Link to comment
Share on other sites

Hej,

C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe (Worm.Autorun.B)

 

Se MBAM loggen, innebär att smitta förs över via USB anslutna enheter, minnen, Externa diskar, mobiler, allt som varit i kontakt med denna dator.

Om du flyttat filer till andra datorer med USB minne t.ex så måste den andra datorn också köra detta program och rensa sina USB externt anslutna enheter.

Du behöver köra detta program med: http://download.blee...Disinfector.exe

Citerar sidan, hoppas att engelska går bra, annars fråga:

  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
    Note: Some security programs will flag Flash_Disinfector as being some sort of malware, you can safely ignore these warnings
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.

Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.

 

Mvh

Mats H

Link to comment
Share on other sites

Hej,

C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe (Worm.Autorun.B)

 

Se MBAM loggen, innebär att smitta förs över via USB anslutna enheter, minnen, Externa diskar, mobiler, allt som varit i kontakt med denna dator.

Om du flyttat filer till andra datorer med USB minne t.ex så måste den andra datorn också köra detta program och rensa sina USB externt anslutna enheter.

Du behöver köra detta program med: http://download.blee...Disinfector.exe

Citerar sidan, hoppas att engelska går bra, annars fråga:

  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
    Note: Some security programs will flag Flash_Disinfector as being some sort of malware, you can safely ignore these warnings
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.

Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.

 

Mvh

Mats H

 

 

Det där lät ju mindre kul, men nödvändigt! Har ett minne och en extern hårddisk som jag flyttat filer mellan denna laptop och jobbpcn. Blir till att köra detta program på samtliga imorgon.

 

här är en ny dds-logg. Efter att jag tog bort filerna så har inte datorn visat tecken på virus längre vilket är positivt:).

 

 

DDS (Ver_10-03-17.01) - NTFSx86

Run by Mag at 23:51:27,87 on 2010-08-12

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15

Microsoft Windows XP Home Edition 5.1.2600.3.1252.46.1053.18.1012.360 [GMT 3:00]

 

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

 

============== Running Processes ===============

 

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

C:\Program\AVG\AVG9\avgchsvx.exe

C:\Program\AVG\AVG9\avgrsx.exe

svchost.exe

C:\Program\AVG\AVG9\avgcsrvx.exe

svchost.exe

C:\WINDOWS\system32\ZoneLabs\vsmon.exe

C:\WINDOWS\Explorer.EXE

C:\Program\CheckPoint\ZAForceField\IswSvc.exe

C:\WINDOWS\system32\spoolsv.exe

svchost.exe

C:\Program\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe

C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program\AVG\AVG9\avgwdsvc.exe

C:\Program\Bonjour\mDNSResponder.exe

C:\Program\Java\jre6\bin\jqs.exe

C:\Program\Telenor\Connection Manager\Sesam\BIN\SecMIPService.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\Program\AVG\AVG9\avgnsx.exe

C:\Program\Sony Ericsson\Sony Ericsson MD400 Wireless Modem\wwanSvc.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program\AVG\AVG9\avgemc.exe

C:\Program\AVG\AVG9\avgcsrvx.exe

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\igfxpers.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\igfxsrvc.exe

C:\Program\Synaptics\SynTP\SynTPEnh.exe

C:\Program\LAUNCH~1\LManager.exe

C:\Program\Adobe\Reader 9.0\Reader\Reader_sl.exe

C:\Program\Java\jre6\bin\jusched.exe

C:\Program\iTunes\iTunesHelper.exe

C:\Program\AVG\AVG9\avgtray.exe

C:\Program\Zone Labs\ZoneAlarm\zlclient.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program\Windows Live\Messenger\msnmsgr.exe

C:\Program\Messenger\msmsgs.exe

C:\Program\Skype\Phone\Skype.exe

C:\WINDOWS\system32\igfxext.exe

C:\Program\iPod\bin\iPodService.exe

C:\DOCUME~1\Mag\LOKALA~1\Temp\RtkBtMnt.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\Program\CheckPoint\ZAForceField\ForceField.exe

C:\Program\Telenor\Connection Manager\GlobeTrotter Launcher.exe

C:\Program\Telenor\Connection Manager\Connection Manager.exe

C:\Program\Skype\Plugin Manager\skypePM.exe

C:\Documents and Settings\Mag\Mina dokument\Hämtade filer\dds.scr

C:\Program\Mozilla Firefox\firefox.exe

 

============== Pseudo HJT Report ===============

 

uStart Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=041d&s=0&o=xph&d=0409&m=doa150

uDefault_Page_URL = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=041d&s=0&o=xph&d=0409&m=doa150

uInternet Settings,ProxyOverride = *.local

uURLSearchHooks: ZoneAlarm Toolbar: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - c:\program\zonealarm\tbZone.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program\delade filer\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program\avg\avg9\avgssie.dll

BHO: ZoneAlarm Toolbar: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - c:\program\zonealarm\tbZone.dll

BHO: ZoneAlarm Security Engine Registrar: {8a4a36c2-0535-4d2c-bd3d-496cb7eed6e3} - c:\program\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll

BHO: Windows Live inloggningshjälpen: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program\delade filer\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program\google\googletoolbar1.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program\google\googletoolbarnotifier\3.1.415.1646\swg.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program\google\googletoolbar1.dll

TB: ZoneAlarm Toolbar: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - c:\program\zonealarm\tbZone.dll

TB: ZoneAlarm Security Engine: {ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107} - c:\program\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll

uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe

uRun: [msnmsgr] "c:\program\windows live\messenger\msnmsgr.exe" /background

uRun: [MSMSGS] "c:\program\messenger\msmsgs.exe" /background

uRun: [<NO NAME>]

uRun: [skype] "c:\program\skype\\phone\Skype.exe" /nosplash /minimized

uRun: [sjyxmoiq] c:\documents and settings\mag\lokala inställningar\application data\gvkdwsula\ouvwubitssd.exe

uRun: [lijyxvnd] c:\documents and settings\mag\lokala inställningar\application data\pjccwlifr\odqaawytssd.exe

uRun: [12CFG214-K641-12SF-N85P] c:\recycler\s-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe

mRun: [igfxTray] c:\windows\system32\igfxtray.exe

mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe

mRun: [Persistence] c:\windows\system32\igfxpers.exe

mRun: [RTHDCPL] RTHDCPL.EXE

mRun: [Alcmtr] ALCMTR.EXE

mRun: [AzMixerSel] c:\program\realtek\audio\drivers\AzMixerSel.exe

mRun: [synTPEnh] c:\program\synaptics\syntp\SynTPEnh.exe

mRun: [LManager] c:\program\launch~1\LManager.exe

mRun: [Google Desktop Search] "c:\program\google\google desktop search\GoogleDesktop.exe" /startup

mRun: [Adobe Reader Speed Launcher] "c:\program\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [iMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC

mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC

mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName

mRun: [PLFSetL] c:\windows\PLFSetL.exe

mRun: [snp2uvc] rundll32.exe c:\windows\system32\csnp2uvc.dll,ResetCIDS

mRun: [sunJavaUpdateSched] "c:\program\java\jre6\bin\jusched.exe"

mRun: [QuickTime Task] "c:\program\quicktime\QTTask.exe" -atboottime

mRun: [iTunesHelper] "c:\program\itunes\iTunesHelper.exe"

mRun: [AVG9_TRAY] c:\program\avg\avg9\avgtray.exe

mRun: [ZoneAlarm Client] "c:\program\zone labs\zonealarm\zlclient.exe"

mRun: [iSW] "c:\program\checkpoint\zaforcefield\ForceField.exe" /icon="hidden"

dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE

IE: E&xportera till Microsoft Excel - c:\program\micros~2\office12\EXCEL.EXE/3000

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program\messenger\msmsgs.exe

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program\windows live\writer\WriterBrowserExtension.dll

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program\micros~2\office12\ONBttnIE.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\program\micros~2\office12\REFIEBAR.DLL

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab

Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program\avg\avg9\avgpp.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program\delade~1\skype\SKYPE4~1.DLL

Notify: avgrsstarter - avgrsstx.dll

Notify: igfxcui - igfxdev.dll

AppInit_DLLs: c:\program\google\google~1\GOEC62~1.DLL

 

================= FIREFOX ===================

 

FF - ProfilePath - c:\docume~1\mag\applic~1\mozilla\firefox\profiles\bqxpcojq.default\

FF - component: c:\program\avg\avg9\firefox\components\avgssff.dll

FF - component: c:\program\checkpoint\zaforcefield\trustchecker\components\TrustCheckerMozillaPlugin.dll

FF - component: c:\program\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll

FF - plugin: c:\documents and settings\mag\application data\mozilla\firefox\profiles\bqxpcojq.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll

FF - plugin: c:\program\checkpoint\zaforcefield\trustchecker\bin\npFFApi.dll

FF - plugin: c:\program\windows live\photo gallery\NPWLPG.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

FF - HiddenExtension: Java Console: No Registry Reference - c:\program\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

FF - HiddenExtension: Java Console: No Registry Reference - c:\program\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

 

---- FIREFOX POLICIES ----

c:\program\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.visited_color", "#551A8B");

c:\program\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);

c:\program\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);

c:\program\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);

c:\program\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);

c:\program\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);

c:\program\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);

c:\program\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);

c:\program\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);

c:\program\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);

c:\program\mozilla firefox\greprefs\all.js - pref("html5.enable", false);

c:\program\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);

c:\program\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

c:\program\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);

c:\program\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");

c:\program\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");

c:\program\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.videoFeeds.handler", "ask");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

 

============= SERVICES / DRIVERS ===============

 

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-7-28 216400]

R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-7-28 29584]

R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-7-28 243024]

R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2009-7-27 532224]

R2 avg9emc;AVG Free E-mail Scanner;c:\program\avg\avg9\avgemc.exe [2010-7-28 921952]

R2 avg9wd;AVG Free WatchDog;c:\program\avg\avg9\avgwdsvc.exe [2010-7-28 308136]

R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program\checkpoint\zaforcefield\ISWKL.sys [2010-5-26 26352]

R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program\checkpoint\zaforcefield\ISWSVC.exe [2010-5-26 493032]

R2 SesamService;Sesam Control Service;c:\program\telenor\connection manager\sesam\bin\SecMIPService.exe [2008-5-9 1216296]

R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?]

R2 wwanSvc;wwanSvc;c:\program\sony ericsson\sony ericsson md400 wireless modem\wwanSvc.exe [2008-10-14 106496]

R3 wtsmpadap;Sesam Virtual Adapter;c:\windows\system32\drivers\wtsmpadap.sys [2008-4-29 39720]

R3 WtSmpFlt;Sesam Adapter;c:\windows\system32\drivers\wtsmpflt.sys [2008-4-29 272424]

S3 GoogleDesktopManager-080708-050100;Google Desktop-hanteraren 5.7.808.7150;c:\program\google\google desktop search\GoogleDesktop.exe [2009-1-20 24064]

S3 GTMM Device Service;GTMM Device Service;c:\program\telenor\connection manager\GtmmDeviceService.exe [2008-11-26 106496]

S3 seu3bus;Sony Ericsson MD400g Mobile Broadband Composite Device driver (WDM);c:\windows\system32\drivers\seu3bus.sys [2008-8-13 307200]

S3 seu3card;Sony Ericsson MD400g Device Mgmt;c:\windows\system32\drivers\seu3card.sys [2008-8-13 380800]

S3 seu3mdfl;Sony Ericsson MD400g Mobile Broadband Modem Filter;c:\windows\system32\drivers\seu3mdfl.sys [2008-8-13 14976]

S3 seu3mdfl2;Sony Ericsson MD400g Mobile Broadband Data Modem Filter;c:\windows\system32\drivers\seu3mdfl2.sys [2008-8-13 14976]

S3 seu3mdm;Sony Ericsson MD400g Mobile Broadband Modem Driver;c:\windows\system32\drivers\seu3mdm.sys [2008-8-13 389376]

S3 seu3mdm2;Sony Ericsson MD400g Mobile Broadband Data Modem Driver;c:\windows\system32\drivers\seu3mdm2.sys [2008-8-13 434176]

S3 seu3nd5;Sony Ericsson MD400g Mobile Broadband Network Adapter (NDIS);c:\windows\system32\drivers\seu3nd5.sys [2008-8-13 25984]

S3 seu3unic;Sony Ericsson MD400g Mobile Broadband Network Adapter (WDM);c:\windows\system32\drivers\seu3unic.sys [2008-8-13 405504]

S3 Sony_EricssonWWSC;Sony Ericsson PC SC Port;c:\windows\system32\drivers\seu3scard.sys [2008-8-8 24232]

S3 TSWLAN;TsWlan Packet Driver;c:\windows\system32\drivers\TsWlan.sys [2008-10-17 33664]

 

=============== Created Last 30 ================

 

2010-08-12 19:59:59 0 d-----w- c:\docume~1\mag\applic~1\Malwarebytes

2010-08-12 19:59:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-08-12 19:59:44 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-08-12 19:59:44 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes

2010-08-12 19:59:43 0 d-----w- c:\program\Malwarebytes' Anti-Malware

2010-08-12 17:43:39 0 d-----w- c:\program\Trend Micro

2010-08-12 17:31:22 0 d-----w- c:\program\CCleaner

2010-08-10 18:14:20 0 d--h--w- C:\$AVG

2010-08-10 18:12:18 0 d-----w- c:\docume~1\mag\applic~1\FCD4057AB9E5D43C034BD3A2FDF29011

2010-08-06 12:45:55 0 d-----w- c:\program\AviSynth 2.5

2010-08-06 12:45:38 0 d-----w- c:\program\Red Kawa

2010-07-29 09:15:42 0 d-----w- c:\docume~1\mag\applic~1\CheckPoint

2010-07-29 09:15:17 0 d-----w- c:\program\Conduit

2010-07-29 09:15:15 0 d-----w- c:\program\ZoneAlarm

2010-07-29 09:14:57 0 d-----w- c:\program\CheckPoint

2010-07-28 12:49:24 12536 ----a-w- c:\windows\system32\avgrsstx.dll

2010-07-28 12:49:19 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys

2010-07-28 12:49:06 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys

2010-07-28 12:48:58 0 d-----w- c:\windows\system32\drivers\Avg

2010-07-28 12:44:04 0 d-----w- c:\program\AVG

2010-07-28 12:43:33 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9

 

==================== Find3M ====================

 

2010-07-29 09:14:49 4212 ---ha-w- c:\windows\system32\zllictbl.dat

2010-07-22 19:18:34 84026 ----a-w- c:\windows\system32\perfc01D.dat

2010-07-22 19:18:34 444892 ----a-w- c:\windows\system32\perfh01D.dat

2010-06-23 10:51:22 1238528 ----a-w- c:\windows\system32\zpeng25.dll

2009-04-27 18:16:12 32768 --sha-w- c:\windows\system32\config\systemprofile\lokala inställningar\tidigare\history.ie5\mshist012009042720090428\index.dat

 

============= FINISH: 23:55:01,79 ===============

Link to comment
Share on other sites

Hej,

vi fortsätter med detta!

Håll ut! :)

Spara ComboFix på Skrivbordet:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

 

Stäng av alla program du ser inklusive antivirusprogram och antispionprogram men lämna brandväggen på.

Hur? Se http://www.bleepingcomputer.com/forums/topic114351.html

Kör ComboFix och följ anvisningarna som visas.

Om det kommer upp en fråga om du vill installera återställningskonsolen så svara ja.

 

VIKTIGT! Klicka inte på ComboFix-fönstret med musen när den körs annars kan den hänga upp sig.

 

När den är färdig så ska en logg komma upp, klistra in den i ditt svar. Kontrollera att antivirusprogram mm är igång innan du ansluter till internet.

 

Om du får problem med att komma ut på internet:

Kontrollpanelen - Nätverksanslutningar

högerklicka på din internetanslutning och välj Reparera och/eller starta om datorn.

 

Varning! ComboFix förhindrar automatisk körning av CD, disketter och USB-enheter för att göra det lättare att rensa datorn och skydda datorn mot infektioner i framtiden. Det kan bli problem t ex om datorn har internet via ett USB-modem eller USB-nätverkskort. Säg då till i stället för att köra ComboFix.

 

Mvh

Mats H

Link to comment
Share on other sites

Hej,

angående din jobb-PC, så bör du lämna in den för kontroll och rensning på er IT avdelning. Hänvisa till denna tråd.

Mvh

Mats H

Link to comment
Share on other sites

Hej,

vi fortsätter med detta!

Håll ut! :)

Spara ComboFix på Skrivbordet:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

 

Stäng av alla program du ser inklusive antivirusprogram och antispionprogram men lämna brandväggen på.

Hur? Se http://www.bleepingcomputer.com/forums/topic114351.html

Kör ComboFix och följ anvisningarna som visas.

Om det kommer upp en fråga om du vill installera återställningskonsolen så svara ja.

 

VIKTIGT! Klicka inte på ComboFix-fönstret med musen när den körs annars kan den hänga upp sig.

 

När den är färdig så ska en logg komma upp, klistra in den i ditt svar. Kontrollera att antivirusprogram mm är igång innan du ansluter till internet.

 

Om du får problem med att komma ut på internet:

Kontrollpanelen - Nätverksanslutningar

högerklicka på din internetanslutning och välj Reparera och/eller starta om datorn.

 

Varning! ComboFix förhindrar automatisk körning av CD, disketter och USB-enheter för att göra det lättare att rensa datorn och skydda datorn mot infektioner i framtiden. Det kan bli problem t ex om datorn har internet via ett USB-modem eller USB-nätverkskort. Säg då till i stället för att köra ComboFix.

 

Mvh

Mats H

 

 

Här kommer en Combofix-logg:

 

ComboFix 10-08-12.03 - Mag 2010-08-13 11:37:52.1.2 - x86

Microsoft Windows XP Home Edition 5.1.2600.3.1252.46.1053.18.1012.422 [GMT 3:00]

Körs från: c:\documents and settings\Mag\Skrivbord\ComboFix.exe

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

.

 

((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\documents and settings\All Users\Dokument\Settings

c:\documents and settings\All Users\Dokument\Settings\cbss.dll

c:\windows\system32\Install.cmd

 

Infekterad kopia av c:\windows\system32\drivers\i2omp.sys hittades och desinficerades.

Återställd kopia från - Kitty had a snack :P

.

((((((((((((((((((((((((((((((((((((((( Drivrutiner/Tjänster )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Service_npf

 

 

(((((((((((((((((((((((( Filer Skapade från 2010-07-13 till 2010-08-13 ))))))))))))))))))))))))))))))

.

 

2010-08-12 20:04 . 2010-08-12 20:04 -------- d-----w- c:\documents and settings\Administratör

2010-08-12 19:59 . 2010-08-12 19:59 -------- d-----w- c:\documents and settings\Mag\Application Data\Malwarebytes

2010-08-12 19:59 . 2010-04-29 12:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-08-12 19:59 . 2010-08-12 19:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-08-12 19:59 . 2010-04-29 12:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-08-12 19:59 . 2010-08-12 19:59 -------- d-----w- c:\program\Malwarebytes' Anti-Malware

2010-08-12 17:43 . 2010-08-12 17:43 388096 ----a-r- c:\documents and settings\Mag\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2010-08-12 17:43 . 2010-08-12 17:43 -------- d-----w- c:\program\Trend Micro

2010-08-12 17:31 . 2010-08-12 17:31 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache

2010-08-12 17:31 . 2010-08-12 17:31 -------- d-----w- c:\program\CCleaner

2010-08-10 18:14 . 2010-08-10 18:14 -------- d-----w- C:\$AVG

2010-08-10 18:12 . 2010-08-10 18:58 -------- d-----w- c:\documents and settings\Mag\Application Data\FCD4057AB9E5D43C034BD3A2FDF29011

2010-08-06 14:46 . 2010-08-06 14:46 -------- d-----w- c:\program\Delade filer\Skype

2010-08-06 12:45 . 2010-08-06 12:46 -------- d-----w- c:\program\AviSynth 2.5

2010-08-06 12:45 . 2010-08-06 12:45 -------- d-----w- c:\program\Red Kawa

2010-07-29 09:15 . 2010-07-29 09:15 -------- d-----w- c:\documents and settings\Mag\Application Data\CheckPoint

2010-07-29 09:15 . 2010-07-29 09:15 -------- d-----w- c:\program\Conduit

2010-07-29 09:15 . 2010-07-29 09:15 -------- d-----w- c:\program\ZoneAlarm

2010-07-29 09:14 . 2010-07-29 09:14 -------- d-----w- c:\program\CheckPoint

2010-07-29 09:14 . 2010-06-23 10:51 69120 ----a-w- c:\windows\system32\zlcomm.dll

2010-07-29 09:14 . 2010-06-23 10:51 103936 ----a-w- c:\windows\system32\zlcommdb.dll

2010-07-28 12:49 . 2010-07-28 12:49 12536 ----a-w- c:\windows\system32\avgrsstx.dll

2010-07-28 12:49 . 2010-07-28 12:49 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys

2010-07-28 12:49 . 2010-07-28 12:49 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys

2010-07-28 12:49 . 2010-07-28 12:49 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys

2010-07-28 12:48 . 2010-08-12 17:26 -------- d-----w- c:\windows\system32\drivers\Avg

2010-07-28 12:44 . 2010-07-28 12:44 -------- d-----w- c:\program\AVG

2010-07-28 12:43 . 2010-07-28 12:44 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-08-13 08:51 . 2009-04-27 17:05 -------- d-----w- c:\documents and settings\Mag\Application Data\Skype

2010-08-13 06:14 . 2009-04-27 17:07 -------- d-----w- c:\documents and settings\Mag\Application Data\skypePM

2010-08-12 20:34 . 2009-07-23 10:00 -------- d-----w- c:\documents and settings\Mag\Application Data\vlc

2010-08-12 19:58 . 2009-04-27 17:17 -------- d-----w- c:\documents and settings\Mag\Application Data\uTorrent

2010-08-11 20:37 . 2010-08-12 16:17 2694656 ----a-w- c:\windows\Internet Logs\xDBC.tmp

2010-08-11 20:37 . 2010-08-12 16:17 1718784 ----a-w- c:\windows\Internet Logs\xDBD.tmp

2010-08-11 20:08 . 2009-01-20 09:34 -------- d--h--w- c:\program\InstallShield Installation Information

2010-08-10 18:35 . 2010-08-10 18:44 274944 ----a-w- c:\windows\Internet Logs\xDB9.tmp

2010-08-10 18:32 . 2010-08-10 18:44 2345984 ----a-w- c:\windows\Internet Logs\xDBB.tmp

2010-08-10 18:32 . 2010-08-10 18:44 2345984 ----a-w- c:\windows\Internet Logs\xDBA.tmp

2010-08-06 14:47 . 2009-04-27 17:05 -------- d-----r- c:\program\Skype

2010-08-06 14:46 . 2009-04-27 17:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype

2010-08-01 13:04 . 2010-04-05 20:28 3693789 ----a-w- c:\windows\Internet Logs\tvDebug.Zip

2010-07-31 12:27 . 2010-07-31 18:50 3387392 ----a-w- c:\windows\Internet Logs\xDB8.tmp

2010-07-30 10:54 . 2009-07-27 20:24 -------- d-----w- c:\documents and settings\Mag\Application Data\Spotify

2010-07-30 09:58 . 2009-05-14 15:36 -------- d-----w- c:\documents and settings\Mag\Application Data\dvdcss

2010-07-29 09:14 . 2009-07-27 17:38 4212 ---ha-w- c:\windows\system32\zllictbl.dat

2010-07-22 19:18 . 2009-01-20 16:10 84026 ----a-w- c:\windows\system32\perfc01D.dat

2010-07-22 19:18 . 2009-01-20 16:10 444892 ----a-w- c:\windows\system32\perfh01D.dat

2010-06-23 10:51 . 2009-07-27 17:38 1238528 ----a-w- c:\windows\system32\zpeng25.dll

2010-06-14 21:12 . 2009-01-20 09:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help

2010-06-14 21:06 . 2010-06-14 21:06 -------- d-----w- c:\program\Paint.NET

2010-06-14 14:31 . 2009-01-20 08:27 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe

2010-05-23 11:03 . 2010-05-23 11:03 655360 ----a-w- c:\documents and settings\Mag\Application Data\Spotify\Gracenote\gnsdk_sdkmanager.dll

2010-05-23 11:03 . 2010-05-23 11:03 282624 ----a-w- c:\documents and settings\Mag\Application Data\Spotify\Gracenote\gnsdk_musicid_file.dll

2010-05-23 11:03 . 2010-05-23 11:03 208896 ----a-w- c:\documents and settings\Mag\Application Data\Spotify\Gracenote\gnsdk_dsp.dll

.

 

(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Not* Tomma poster & legitima standardposter visas inte.

REGEDIT4

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

 

[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

2010-05-09 08:50 2517088 ----a-w- c:\program\ZoneAlarm\tbZone.dll

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

 

[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD}"= "c:\program\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

 

[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\program\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883840]

"Skype"="c:\program\Skype\\Phone\Skype.exe" [2010-05-13 26192168]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-15 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]

"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]

"RTHDCPL"="RTHDCPL.EXE" [2008-12-30 18082304]

"AzMixerSel"="c:\program\Realtek\Audio\Drivers\AzMixerSel.exe" [2006-07-17 53248]

"SynTPEnh"="c:\program\Synaptics\SynTP\SynTPEnh.exe" [2008-07-31 1343488]

"LManager"="c:\program\LAUNCH~1\LManager.exe" [2008-08-18 817672]

"Google Desktop Search"="c:\program\Google\Google Desktop Search\GoogleDesktop.exe" [2009-01-20 24064]

"Adobe Reader Speed Launcher"="c:\program\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]

"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-15 208952]

"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-15 59392]

"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-15 455168]

"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-15 455168]

"PLFSetL"="c:\windows\PLFSetL.exe" [2008-07-03 94208]

"snp2uvc"="c:\windows\system32\csnp2uvc.dll" [2008-11-03 196608]

"SunJavaUpdateSched"="c:\program\Java\jre6\bin\jusched.exe" [2009-07-25 149280]

"QuickTime Task"="c:\program\QuickTime\QTTask.exe" [2009-05-26 413696]

"iTunesHelper"="c:\program\iTunes\iTunesHelper.exe" [2009-07-13 292128]

"AVG9_TRAY"="c:\program\AVG\AVG9\avgtray.exe" [2010-07-28 2065760]

"ZoneAlarm Client"="c:\program\Zone Labs\ZoneAlarm\zlclient.exe" [2010-06-23 1043968]

"ISW"="c:\program\CheckPoint\ZAForceField\ForceField.exe" [2010-05-26 730600]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]

2010-07-28 12:49 12536 ----a-w- c:\windows\system32\avgrsstx.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=c:\program\Google\GOOGLE~1\GoogleDesktopNetwork3.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

 

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-07-28 216400]

R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-07-28 243024]

R2 avg9emc;AVG Free E-mail Scanner;c:\program\AVG\AVG9\avgemc.exe [2010-07-28 921952]

R2 avg9wd;AVG Free WatchDog;c:\program\AVG\AVG9\avgwdsvc.exe [2010-07-28 308136]

R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program\CheckPoint\ZAForceField\ISWKL.sys [2010-05-26 26352]

R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program\CheckPoint\ZAForceField\ISWSVC.exe [2010-05-26 493032]

R2 SesamService;Sesam Control Service;c:\program\Telenor\Connection Manager\Sesam\BIN\SecMIPService.exe [2008-05-09 1216296]

R2 wwanSvc;wwanSvc;c:\program\Sony Ericsson\Sony Ericsson MD400 Wireless Modem\wwanSvc.exe [2008-10-14 106496]

R3 wtsmpadap;Sesam Virtual Adapter;c:\windows\system32\drivers\wtsmpadap.sys [2008-04-29 39720]

R3 WtSmpFlt;Sesam Adapter;c:\windows\system32\drivers\wtsmpflt.sys [2008-04-29 272424]

S3 GoogleDesktopManager-080708-050100;Google Desktop-hanteraren 5.7.808.7150;c:\program\Google\Google Desktop Search\GoogleDesktop.exe [2009-01-20 24064]

S3 GTMM Device Service;GTMM Device Service;c:\program\Telenor\Connection Manager\GtmmDeviceService.exe [2008-11-26 106496]

S3 seu3bus;Sony Ericsson MD400g Mobile Broadband Composite Device driver (WDM);c:\windows\system32\drivers\seu3bus.sys [2008-08-13 307200]

S3 seu3card;Sony Ericsson MD400g Device Mgmt;c:\windows\system32\drivers\seu3card.sys [2008-08-13 380800]

S3 seu3mdfl;Sony Ericsson MD400g Mobile Broadband Modem Filter;c:\windows\system32\drivers\seu3mdfl.sys [2008-08-13 14976]

S3 seu3mdfl2;Sony Ericsson MD400g Mobile Broadband Data Modem Filter;c:\windows\system32\drivers\seu3mdfl2.sys [2008-08-13 14976]

S3 seu3mdm;Sony Ericsson MD400g Mobile Broadband Modem Driver;c:\windows\system32\drivers\seu3mdm.sys [2008-08-13 389376]

S3 seu3mdm2;Sony Ericsson MD400g Mobile Broadband Data Modem Driver;c:\windows\system32\drivers\seu3mdm2.sys [2008-08-13 434176]

S3 seu3nd5;Sony Ericsson MD400g Mobile Broadband Network Adapter (NDIS);c:\windows\system32\drivers\seu3nd5.sys [2008-08-13 25984]

S3 seu3unic;Sony Ericsson MD400g Mobile Broadband Network Adapter (WDM);c:\windows\system32\drivers\seu3unic.sys [2008-08-13 405504]

S3 Sony_EricssonWWSC;Sony Ericsson PC SC Port;c:\windows\system32\drivers\seu3scard.sys [2008-08-08 24232]

S3 TSWLAN;TsWlan Packet Driver;c:\windows\system32\drivers\TsWlan.sys [2008-10-17 33664]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

getPlusHelper REG_MULTI_SZ getPlusHelper

.

.

------- Extra genomsökning -------

.

uStart Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=041d&s=0&o=xph&d=0409&m=doa150

uInternet Settings,ProxyOverride = *.local

IE: E&xportera till Microsoft Excel - c:\program\MICROS~2\Office12\EXCEL.EXE/3000

FF - ProfilePath - c:\documents and settings\Mag\Application Data\Mozilla\Firefox\Profiles\bqxpcojq.default\

FF - component: c:\program\AVG\AVG9\Firefox\components\avgssff.dll

FF - component: c:\program\CheckPoint\ZAForceField\TrustChecker\components\TrustCheckerMozillaPlugin.dll

FF - component: c:\program\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll

FF - plugin: c:\documents and settings\Mag\Application Data\Mozilla\Firefox\Profiles\bqxpcojq.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll

FF - plugin: c:\program\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll

FF - plugin: c:\program\Windows Live\Photo Gallery\NPWLPG.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

 

---- FIREFOX POLICY ----

c:\program\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);

c:\program\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);

c:\program\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);

c:\program\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);

c:\program\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);

c:\program\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);

c:\program\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);

.

- - - - FÖRÄLDRALÖSA POSTER SOM TAGITS BORT - - - -

 

HKCU-Run-sjyxmoiq - c:\documents and settings\Mag\Lokala inställningar\Application Data\gvkdwsula\ouvwubitssd.exe

HKCU-Run-lijyxvnd - c:\documents and settings\Mag\Lokala inställningar\Application Data\pjccwlifr\odqaawytssd.exe

AddRemove-NIS2009 - c:\program\Norton Internet Security\Engine\16.0.0.125\RunCmd.exe

AddRemove-Office2007 - c:\program files\Microsoft Office\RunCmd.exe

AddRemove-Works9 - c:\program files\Microsoft Office\RunCmd.exe

 

 

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-08-13 11:51

Windows 5.1.2600 Service Pack 3 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

--------------------- DLLer som "laddats" under processer som körs ---------------------

 

- - - - - - - > 'winlogon.exe'(1408)

c:\program\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll

 

- - - - - - - > 'lsass.exe'(1464)

c:\program\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll

 

- - - - - - - > 'explorer.exe'(1620)

c:\program\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll

c:\windows\system32\webcheck.dll

.

------------------------ Andra processer som körs ------------------------

.

c:\program\AVG\AVG9\avgchsvx.exe

c:\program\AVG\AVG9\avgrsx.exe

c:\program\AVG\AVG9\avgcsrvx.exe

c:\windows\System32\SCardSvr.exe

c:\program\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe

c:\program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

c:\program\Bonjour\mDNSResponder.exe

c:\program\Java\jre6\bin\jqs.exe

c:\windows\system32\wdfmgr.exe

c:\program\AVG\AVG9\avgnsx.exe

c:\program\AVG\AVG9\avgcsrvx.exe

c:\windows\system32\igfxsrvc.exe

c:\windows\RTHDCPL.EXE

c:\windows\system32\igfxext.exe

c:\docume~1\Mag\LOKALA~1\Temp\RtkBtMnt.exe

c:\program\iPod\bin\iPodService.exe

c:\windows\system32\wbem\wmiapsrv.exe

c:\windows\system32\wscntfy.exe

.

**************************************************************************

.

Sluttid: 2010-08-13 11:55:47 - datorn startades om.

ComboFix-quarantined-files.txt 2010-08-13 08:55

 

Före genomsökningen: 6 669 291 520 byte ledigt

Efter genomsökningen: 6 705 737 728 byte ledigt

 

- - End Of File - - F36F9AFB060B38EAFB60B7229A626A14

Link to comment
Share on other sites

Vad finns i mappen?

2010-08-10 18:12 . 2010-08-10 18:58 -------- d-----w- c:\documents and settings\Mag\Application Data\FCD4057AB9E5D43C034BD3A2FDF29011

 

Jag ser att du har haft Norton förut. Det kan vara bra att köra deras städprogram om du inte redan har gjort det:

http://www.symantec.com/norton/support/kb/web_view.jsp?wv_type=public_web&docurl=20090910004050EN Step 3

 

Det är en gammal Java-version med säkerhetshål i datorn. Jag rekommenderar dig att installera en ny från http://www.java.com/sv/ och kontrollera sedan att den gamla "Java™ 6 Update 15" avinstallerades. Om inte får du göra det (inga webbläsare igång). Likaså är det en VLC och Adobe Reader med säkerhetshål i datorn. Uppdatera dem.

 

Om dessa fortfarande finns kvar avinstallera dem:

Street-Ads Browser Enhancer

ZoneAlarm Toolbar

 

När ovanstående är gjort starta om datorn och kör DDS. Klistra in loggen DDS.txt.

 

Hittar AVG något nu om du söker igenom datorn med det?

Något klagomål från ZoneAlarm?

Link to comment
Share on other sites

Hej,

 

Jag har uppdaterat programmen samt tagit bort zonealarm toolbar. En scan med AVG visade på 0 hot.

 

Ny DDS-logg:

 

 

DDS (Ver_10-03-17.01) - NTFSx86

Run by Mag at 16:03:23,37 on 2010-08-13

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21

Microsoft Windows XP Home Edition 5.1.2600.3.1252.46.1053.18.1012.326 [GMT 3:00]

 

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

 

============== Running Processes ===============

 

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\system32\ZoneLabs\vsmon.exe

C:\Program\AVG\AVG9\avgchsvx.exe

C:\Program\AVG\AVG9\avgrsx.exe

C:\Program\AVG\AVG9\avgcsrvx.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

svchost.exe

C:\Program\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe

C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program\AVG\AVG9\avgwdsvc.exe

C:\Program\Bonjour\mDNSResponder.exe

C:\Program\Java\jre6\bin\jqs.exe

C:\Program\Telenor\Connection Manager\Sesam\BIN\SecMIPService.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\Program\AVG\AVG9\avgnsx.exe

C:\Program\Sony Ericsson\Sony Ericsson MD400 Wireless Modem\wwanSvc.exe

C:\Program\AVG\AVG9\avgemc.exe

C:\Program\AVG\AVG9\avgcsrvx.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\igfxpers.exe

C:\WINDOWS\system32\igfxsrvc.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Program\Synaptics\SynTP\SynTPEnh.exe

C:\Program\LAUNCH~1\LManager.exe

C:\Program\Delade filer\Java\Java Update\jusched.exe

C:\Program\iTunes\iTunesHelper.exe

C:\Program\AVG\AVG9\avgtray.exe

C:\Program\Zone Labs\ZoneAlarm\zlclient.exe

C:\Program\Adobe\Reader 9.0\Reader\Reader_sl.exe

C:\WINDOWS\system32\igfxext.exe

C:\Program\Windows Live\Messenger\msnmsgr.exe

C:\Program\Skype\Phone\Skype.exe

C:\Program\iPod\bin\iPodService.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\Program\Telenor\Connection Manager\GlobeTrotter Launcher.exe

C:\Program\Skype\Plugin Manager\skypePM.exe

C:\Program\Telenor\Connection Manager\Connection Manager.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Documents and Settings\Mag\Mina dokument\Hämtade filer\dds.scr

 

============== Pseudo HJT Report ===============

 

uStart Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=041d&s=0&o=xph&d=0409&m=doa150

uInternet Settings,ProxyOverride = *.local

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program\delade filer\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program\avg\avg9\avgssie.dll

BHO: Windows Live inloggningshjälpen: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program\delade filer\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program\google\googletoolbar1.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program\google\googletoolbarnotifier\3.1.415.1646\swg.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program\google\googletoolbar1.dll

TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File

uRun: [msnmsgr] "c:\program\windows live\messenger\msnmsgr.exe" /background

uRun: [skype] "c:\program\skype\\phone\Skype.exe" /nosplash /minimized

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

mRun: [igfxTray] c:\windows\system32\igfxtray.exe

mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe

mRun: [Persistence] c:\windows\system32\igfxpers.exe

mRun: [RTHDCPL] RTHDCPL.EXE

mRun: [AzMixerSel] c:\program\realtek\audio\drivers\AzMixerSel.exe

mRun: [synTPEnh] c:\program\synaptics\syntp\SynTPEnh.exe

mRun: [LManager] c:\program\launch~1\LManager.exe

mRun: [Google Desktop Search] "c:\program\google\google desktop search\GoogleDesktop.exe" /startup

mRun: [iMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC

mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC

mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName

mRun: [PLFSetL] c:\windows\PLFSetL.exe

mRun: [snp2uvc] rundll32.exe c:\windows\system32\csnp2uvc.dll,ResetCIDS

mRun: [sunJavaUpdateSched] "c:\program\delade filer\java\java update\jusched.exe"

mRun: [QuickTime Task] "c:\program\quicktime\QTTask.exe" -atboottime

mRun: [iTunesHelper] "c:\program\itunes\iTunesHelper.exe"

mRun: [AVG9_TRAY] c:\program\avg\avg9\avgtray.exe

mRun: [ZoneAlarm Client] "c:\program\zone labs\zonealarm\zlclient.exe"

mRun: [Adobe Reader Speed Launcher] "c:\program\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [Adobe ARM] "c:\program\delade filer\adobe\arm\1.0\AdobeARM.exe"

dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE

IE: E&xportera till Microsoft Excel - c:\program\micros~2\office12\EXCEL.EXE/3000

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program\messenger\msmsgs.exe

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program\windows live\writer\WriterBrowserExtension.dll

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program\micros~2\office12\ONBttnIE.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\program\micros~2\office12\REFIEBAR.DLL

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab

Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program\avg\avg9\avgpp.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program\delade~1\skype\SKYPE4~1.DLL

Notify: avgrsstarter - avgrsstx.dll

Notify: igfxcui - igfxdev.dll

AppInit_DLLs: c:\program\google\google~1\GoogleDesktopNetwork3.dll

 

================= FIREFOX ===================

 

FF - ProfilePath - c:\docume~1\mag\applic~1\mozilla\firefox\profiles\bqxpcojq.default\

FF - component: c:\program\avg\avg9\firefox\components\avgssff.dll

FF - component: c:\program\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll

FF - plugin: c:\documents and settings\mag\application data\mozilla\firefox\profiles\bqxpcojq.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll

FF - plugin: c:\program\java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program\windows live\photo gallery\NPWLPG.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

FF - HiddenExtension: Java Console: No Registry Reference - c:\program\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

FF - HiddenExtension: Java Console: No Registry Reference - c:\program\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

FF - HiddenExtension: Java Console: No Registry Reference - c:\program\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

 

---- FIREFOX POLICIES ----

c:\program\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.visited_color", "#551A8B");

c:\program\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);

c:\program\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);

c:\program\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);

c:\program\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);

c:\program\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);

c:\program\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);

c:\program\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);

c:\program\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);

c:\program\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);

c:\program\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);

c:\program\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);

c:\program\mozilla firefox\greprefs\all.js - pref("html5.enable", false);

c:\program\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);

c:\program\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

c:\program\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);

c:\program\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");

c:\program\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");

c:\program\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.videoFeeds.handler", "ask");

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);

c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

 

============= SERVICES / DRIVERS ===============

 

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-7-28 216400]

R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-7-28 29584]

R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-7-28 243024]

R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2009-7-27 532224]

R2 avg9emc;AVG Free E-mail Scanner;c:\program\avg\avg9\avgemc.exe [2010-7-28 921952]

R2 avg9wd;AVG Free WatchDog;c:\program\avg\avg9\avgwdsvc.exe [2010-7-28 308136]

R2 SesamService;Sesam Control Service;c:\program\telenor\connection manager\sesam\bin\SecMIPService.exe [2008-5-9 1216296]

R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?]

R2 wwanSvc;wwanSvc;c:\program\sony ericsson\sony ericsson md400 wireless modem\wwanSvc.exe [2008-10-14 106496]

R3 wtsmpadap;Sesam Virtual Adapter;c:\windows\system32\drivers\wtsmpadap.sys [2008-4-29 39720]

R3 WtSmpFlt;Sesam Adapter;c:\windows\system32\drivers\wtsmpflt.sys [2008-4-29 272424]

S3 GoogleDesktopManager-080708-050100;Google Desktop-hanteraren 5.7.808.7150;c:\program\google\google desktop search\GoogleDesktop.exe [2009-1-20 24064]

S3 GTMM Device Service;GTMM Device Service;c:\program\telenor\connection manager\GtmmDeviceService.exe [2008-11-26 106496]

S3 seu3bus;Sony Ericsson MD400g Mobile Broadband Composite Device driver (WDM);c:\windows\system32\drivers\seu3bus.sys [2008-8-13 307200]

S3 seu3card;Sony Ericsson MD400g Device Mgmt;c:\windows\system32\drivers\seu3card.sys [2008-8-13 380800]

S3 seu3mdfl;Sony Ericsson MD400g Mobile Broadband Modem Filter;c:\windows\system32\drivers\seu3mdfl.sys [2008-8-13 14976]

S3 seu3mdfl2;Sony Ericsson MD400g Mobile Broadband Data Modem Filter;c:\windows\system32\drivers\seu3mdfl2.sys [2008-8-13 14976]

S3 seu3mdm;Sony Ericsson MD400g Mobile Broadband Modem Driver;c:\windows\system32\drivers\seu3mdm.sys [2008-8-13 389376]

S3 seu3mdm2;Sony Ericsson MD400g Mobile Broadband Data Modem Driver;c:\windows\system32\drivers\seu3mdm2.sys [2008-8-13 434176]

S3 seu3nd5;Sony Ericsson MD400g Mobile Broadband Network Adapter (NDIS);c:\windows\system32\drivers\seu3nd5.sys [2008-8-13 25984]

S3 seu3unic;Sony Ericsson MD400g Mobile Broadband Network Adapter (WDM);c:\windows\system32\drivers\seu3unic.sys [2008-8-13 405504]

S3 Sony_EricssonWWSC;Sony Ericsson PC SC Port;c:\windows\system32\drivers\seu3scard.sys [2008-8-8 24232]

S3 TSWLAN;TsWlan Packet Driver;c:\windows\system32\drivers\TsWlan.sys [2008-10-17 33664]

 

=============== Created Last 30 ================

 

2010-08-13 12:30:22 423656 ----a-w- c:\windows\system32\deployJava1.dll

2010-08-13 06:48:19 0 d-sha-r- C:\cmdcons

2010-08-13 06:43:42 98816 ----a-w- c:\windows\sed.exe

2010-08-13 06:43:42 77312 ----a-w- c:\windows\MBR.exe

2010-08-13 06:43:42 256512 ----a-w- c:\windows\PEV.exe

2010-08-13 06:43:42 161792 ----a-w- c:\windows\SWREG.exe

2010-08-13 06:25:47 0 d---a-r- C:\autorun.inf

2010-08-12 19:59:59 0 d-----w- c:\docume~1\mag\applic~1\Malwarebytes

2010-08-12 19:59:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-08-12 19:59:44 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-08-12 19:59:44 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes

2010-08-12 19:59:43 0 d-----w- c:\program\Malwarebytes' Anti-Malware

2010-08-12 17:43:39 0 d-----w- c:\program\Trend Micro

2010-08-12 17:31:22 0 d-----w- c:\program\CCleaner

2010-08-10 18:14:20 0 d-----w- C:\$AVG

2010-08-10 18:12:18 0 d-----w- c:\docume~1\mag\applic~1\FCD4057AB9E5D43C034BD3A2FDF29011

2010-08-06 12:45:55 0 d-----w- c:\program\AviSynth 2.5

2010-08-06 12:45:38 0 d-----w- c:\program\Red Kawa

2010-07-29 09:15:42 0 d-----w- c:\docume~1\mag\applic~1\CheckPoint

2010-07-29 09:14:57 0 d-----w- c:\program\CheckPoint

2010-07-28 12:49:24 12536 ----a-w- c:\windows\system32\avgrsstx.dll

2010-07-28 12:49:19 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys

2010-07-28 12:49:06 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys

2010-07-28 12:48:58 0 d-----w- c:\windows\system32\drivers\Avg

2010-07-28 12:44:04 0 d-----w- c:\program\AVG

2010-07-28 12:43:33 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9

 

==================== Find3M ====================

 

2010-07-29 09:14:49 4212 ---ha-w- c:\windows\system32\zllictbl.dat

2010-07-22 19:18:34 84026 ----a-w- c:\windows\system32\perfc01D.dat

2010-07-22 19:18:34 444892 ----a-w- c:\windows\system32\perfh01D.dat

2010-06-23 10:51:22 1238528 ----a-w- c:\windows\system32\zpeng25.dll

2009-04-27 18:16:12 32768 --sha-w- c:\windows\system32\config\systemprofile\lokala inställningar\tidigare\history.ie5\mshist012009042720090428\index.dat

 

============= FINISH: 16:05:37,93 ===============

Link to comment
Share on other sites

Vad finns i mappen?

2010-08-10 18:12 . 2010-08-10 18:58 -------- d-----w- c:\documents and settings\Mag\Application Data\FCD4057AB9E5D43C034BD3A2FDF29011

 

De gamla Java-versionerna finns fortfarande kvar i Firefox. Ser du till dem i Firefox - Verktyg - Tillägg - Insticksmoduler? I så fall ta bort eller inaktivera dem.

Link to comment
Share on other sites

Vad finns i mappen?

2010-08-10 18:12 . 2010-08-10 18:58 -------- d-----w- c:\documents and settings\Mag\Application Data\FCD4057AB9E5D43C034BD3A2FDF29011

 

De gamla Java-versionerna finns fortfarande kvar i Firefox. Ser du till dem i Firefox - Verktyg - Tillägg - Insticksmoduler? I så fall ta bort eller inaktivera dem.

.

 

Hej,

 

Enligt firefox har jag java 6.0.210.7 Vilket borde vara den senaste? Denna är också den enda jag kan hitta i läggtill/ta bort program.

 

c:\documents and settings\Mag\Application Data\FCD4057AB9E5D43C034BD3A2FDF29011 är en tom mapp av nån anledning.

 

Tack för all hjälp!

Link to comment
Share on other sites

c:\documents and settings\Mag\Application Data\FCD4057AB9E5D43C034BD3A2FDF29011 är en tom mapp av nån anledning.
Bra, då kan det tas bort.

 

Det där är senaste versionen av Java, men i loggen ser det ut som att det dessutom finns två äldre version 6.0.13... och 6.0.15...

 

Det här CFScript fixar båda ovanstående saker. Kopiera alla rader i rutan:

DDS::
TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
FF - HiddenExtension: Java Console: No Registry Reference - c:\program\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
2010-08-10 18:12:18 0 d-----w- c:\docume~1\mag\applic~1\FCD4057AB9E5D43C034BD3A2FDF29011

och klistra in i Anteckningar. Kontrollera att det ser ut precis som i rutan.

Spara filen på Skrivbordet med namnet CFScript.

 

Förbered datorn på samma sätt som tidigare för ComboFix.

Dra CFScript med musen och släpp den ovanpå ComboFix-ikonen på Skrivbordet så startar programmet på ett särskilt sätt.

Klistra in loggen som kommer ut.

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.



×
×
  • Create New...