Seneste forumindlæg
Køb / Salg
 * Uofficiel Black/White liste V3
Login / opret bruger

Forum \ Software \ Sikkerhed
Denne tråd er over 6 måneder gammel

Er du sikker på, at du har noget relevant at tilføje?

HJT log - en venlig sjæl der vil hjælpe?

Af Junior Supporter kastermester | 04-10-2007 20:44 | 2127 visninger | 6 svar, hop til seneste
Hej HOL! :) Jeg har på det seneste haft nogle rimeligt irriterende problemer med min computer. Den begynder at "lagge" på nettet i 1-2 minutter ad gangen hvorefter der går 10-15 minutter og herefter begynder det igen. Jeg har tracket problemet ned til ndisuio.sys filen. Jeg kan se ved flere søgninger på nettet at det vidst må være andre filer som bruger denne der får min computer til at opføre sig på denne underlige måde. Så var det jo jeg kom i tanke om HJT og HardwareOnline igen (ja, jeg har været væk længe nu...) og tænkte at der garranteret var en her som kunne hjælpe. Uden mere omtale, her er min log Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 20:38:10, on 04-10-2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programmer\TGTSoft\StyleXP\StyleXPService.exe C:\Programmer\Sygate\SPF\smc.exe C:\WINDOWS\Explorer.EXE C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe C:\Programmer\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\brsvc01a.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\brss01a.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\AGRSMMSG.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Programmer\Synaptics\SynTP\SynTPLpr.exe C:\Programmer\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\system32\taskswitch.exe C:\Programmer\EzButton\CplBCL50.EXE C:\Programmer\iTunes\iTunesHelper.exe C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe C:\Programmer\DAEMON Tools\daemon.exe C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe C:\Programmer\TuneUp Utilities 2006\MemOptimizer.exe C:\Programmer\TGTSoft\StyleXP\StyleXP.exe C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\system32\ctfmon.exe C:\Programmer\Skype\Phone\Skype.exe C:\www\Apache2\bin\ApacheMonitor.exe C:\Programmer\WIDCOMM\Bluetooth-software\BTTray.exe C:\Programmer\Rainlendar\Rainlendar.exe C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe C:\www\Apache2\bin\Apache.exe C:\Programmer\WIDCOMM\Bluetooth-software\bin\btwdins.exe C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE C:\www\Apache2\bin\Apache.exe C:\Programmer\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe C:\Programmer\Skype\Plugin Manager\skypePM.exe C:\Programmer\Microsoft SQL Server\MSSQL.3\OLAP\bin\msmdsrv.exe C:\www\MySQL 5.0\bin\mysqld-nt.exe C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\svchost.exe C:\Programmer\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\msftesql.exe C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe C:\Programmer\Alwil Software\Avast4\ashWebSv.exe C:\Programmer\iPod\bin\iPodService.exe C:\Programmer\mIRC\mirc.exe C:\Programmer\MSN Messenger\usnsvc.exe C:\Programmer\Mozilla Firefox\firefox.exe C:\Programmer\Winamp\Winamp.exe C:\Programmer\MSN Messenger\msnmsgr.exe C:\Documents and Settings\Kaare Skovgaard\Skrivebord\HiJackThis_v2.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com[...] R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://netbank.danskebank.dk[...] R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks O1 - Hosts: 82.138.240.17 nitrous.swiftirc.net O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe O4 - HKLM\..\Run: [CplBCL50] C:\Programmer\EzButton\CplBCL50.EXE O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Programmer\TuneUp Utilities 2006\MemOptimizer.exe" autostart O4 - HKCU\..\Run: [STYLEXP] C:\Programmer\TGTSoft\StyleXP\StyleXP.exe -Hide O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized O4 - Startup: Adobe Gamma.lnk = ? O4 - Startup: Rainlendar.lnk = C:\Programmer\Rainlendar\Rainlendar.exe O4 - Global Startup: Apache Monitor.lnk = C:\www\Apache2\bin\ApacheMonitor.exe O4 - Global Startup: BTTray.lnk = ? O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Send til &Bluetooth - C:\Programmer\WIDCOMM\Bluetooth-software\btsendto_ie_ctx.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth-software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth-software\btsendto_ie.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com[...] O16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) - https://netbank.danskebank.dk[...] O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com[...] O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com[...] O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com[...] O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk[...] O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmer\Fælles filer\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apache2 - Apache Software Foundation - C:\www\Apache2\bin\Apache.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmer\WIDCOMM\Bluetooth-software\bin\btwdins.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe O23 - Service: MySQL - Unknown owner - C:\www\MySQL\bin\mysqld-nt (file missing) O23 - Service: MySQL5 - Unknown owner - C:\Programmer\MySQL\MySQL.exe (file missing) O23 - Service: MySQL501 - Unknown owner - C:\www\MySQL.exe (file missing) O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Programmer\Sygate\SPF\smc.exe O23 - Service: StyleXPService - Unknown owner - C:\Programmer\TGTSoft\StyleXP\StyleXPService.exe O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Programmer\TuneUp Utilities 2006\WinStylerThemeSvc.exe O24 - Desktop Component 1: (no name) - http://skema.randersts.dk[...] -- End of file - 10306 bytes Jeg takker på forhånd for alt den hjælp jeg kan få.
--
Kaare
#1
*Cookie
Supporter
04-10-2007 22:35

Rapporter til Admin
Hej kastermester. Ja, jeg kan godt se, din PC har crashet for dig. Det ser også ud til, at du har gratisversionen af Sygate Firewall. Det var en rigtig god FW før i tiden, men gratisversionen har givet en del problemer, siden de blev opkøbt. Jeg vil derfor anbefale, at du afinstallerer det via Kontrolpanel => Tilføj/Fjern programmer. Genstart PC og installer en anden FW i stedet for. Jeg vil anbefale dig Comodo, som er en rigtig god freeware firewall, der kan hentes her: Comodo Firewall: http://www.personalfirewall.comodo.com[...] ------------- Hent så nedenstående programmer til egne mapper (fx til Skrivebordet), men vent med at bruge dem, til jeg siger til: CCleaner http://www.filehippo.com[...] AVG AntiSpyware: http://www.grisoft.cz[...] Combofix http://download.bleepingcomputer.com[...] HijackThis (nyere version end den du har brugt) http://www.trendsecure.com[...] ------------- Genstart så PC i fejlsikret tilstand (tryk F8 gentagne gange ved opstart.). Kør så nedenstående programmer - i nævnte rækkefølge: CCleaner AVG AntiSpyware (Vælg "Complete Systemscan". Det kan godt tage noget tid. Afhænger af hvor meget, du har på din PC. Når scanningen er færdig vælg "Apply all actions".) ------------- Genstart så PC i normal tilstand. Kør nu Combofix (Følg vejledningen i vinduet. VIGTIGT! Du må ikke klikke på vinduet, mens det kører, da det kan få din PC til at fryse! Når combofix er færdig og har genstartet, åbnes en logfil, som kan findes her >>> C:\combofix.txt) Kør så en ny scanning med HJT og post loggen herind til kontrol – sammen med loggen fra Combofix. Skriv også gerne et par ord om, hvordan PC’en arter sig nu, så tager vi det derfra :o) ! //*Cookie --
--
Member of Alliance of Security Analysis Professionals http://asap.maddoktor2.com[...]
#2
kastermester
Junior Supporter
05-10-2007 00:41

Rapporter til Admin
Hej Cookie Jeg vil sige tak for hjælpen og jeg er i fuld sving med at udføre ovenstående. Jeg er desværre nødt til at hoppe i seng nu, men jeg vil vende tilbage til dette engang i morgen og poste de logs som du bad om. Mange tak for hjælpen! :) --
--
Kaare
#3
*Cookie
Supporter
05-10-2007 08:45

Rapporter til Admin
Hej kastermester. Helt OK. Håber bare, du vil prøve at følge forslaget. Tror nemlig den gamle Sygate er den primære grund til dine PC-pinsler :o) Pøj-pøj med "kuren". //*Cookie --
--
Member of Alliance of Security Analysis Professionals http://asap.maddoktor2.com[...]
#4
kastermester
Junior Supporter
05-10-2007 10:18

Rapporter til Admin
Så nu blev det færdigt... jeg afinstallerede Sygate'en i går og installerede comodoen, så jeg har fulgt det råd ;). Her er combofix loggen samt den nye HJT log. Combofix ComboFix 07-10-04.6 - Kaare Skovgaard 2007-10-05 9:55:23.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1030.18.392 [GMT 2:00] Running from: D:\Installers\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Programmer\MSN Messenger\msimg32.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) -------\LEGACY_IPRIP -------\LEGACY_NWSAPAGENT -------\Iprip -------\NwSapAgent ((((((((((((((((((((((((( Files Created from 2007-09-05 to 2007-10-05 ))))))))))))))))))))))))))))))) . 2007-10-05 09:53 51,200 --a------ C:\WINDOWS\NirCmd.exe 2007-10-05 09:47 d-------- C:\Documents and Settings\Kaare Skovgaard\Application Data\Comodo 2007-10-05 09:47 d-------- C:\Documents and Settings\All Users\Application Data\Comodo 2007-10-04 23:37 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-10-04 23:29 d-------- C:\Programmer\CCleaner 2007-10-04 23:22 d-------- C:\Programmer\Comodo 2007-10-04 14:08 d-------- C:\Programmer\Microsoft Silverlight 2007-10-02 21:28 d-------- C:\Programmer\Microsoft ASP.NET 2007-09-14 18:34 d-------- C:\Programmer\Windows Live 2007-09-14 18:34 d-------- C:\Programmer\Messenger Plus! Live . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-10-05 10:07 --------- d-------- C:\Documents and Settings\Kaare Skovgaard\Application Data\Skype 2007-10-05 10:01 --------- d-------- C:\Programmer\MSN Messenger 2007-10-04 23:34 --------- d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2007-10-04 23:12 --------- d-------- C:\Programmer\mIRC 2007-10-04 22:11 --------- d-------- C:\Programmer\SwiftSwitch 2007-10-02 01:26 --------- d-------- C:\Programmer\Winamp 2007-09-26 02:40 --------- d-------- C:\Documents and Settings\Kaare Skovgaard\Application Data\Azureus 2007-09-24 01:12 --------- d-------- C:\Programmer\Mozilla Thunderbird 2007-09-18 11:20 --------- d-------- C:\Programmer\SolidWorks 2007-09-17 13:33 152644 --a------ C:\Programmer\SolidWorksswxJRNL.BAK 2007-09-06 12:24 --------- d-a------ C:\Documents and Settings\All Users\Application Data\TEMP 2007-09-06 12:05 94416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys 2007-09-06 12:05 92848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys 2007-09-06 12:03 23152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys 2007-09-06 12:02 42912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys 2007-09-06 12:00 26624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys 2007-08-31 14:49 --------- d-------- C:\Documents and Settings\Kaare Skovgaard\Application Data\Real 2007-08-30 22:17 --------- d-------- C:\Programmer\Real 2007-08-27 11:21 --------- d-------- C:\Programmer\DIFX 2007-08-27 11:20 --------- d-------- C:\Programmer\Matrix Multimedia 2007-08-25 03:08 --------- d-------- C:\Programmer\Google 2007-08-19 02:18 --------- d-------- C:\Programmer\Lavasoft 2007-08-19 02:18 --------- d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft 2007-08-16 22:56 --------- d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help 2007-08-15 10:32 --------- d-------- C:\Programmer\MSXML 6.0 2007-08-09 13:15 --------- d-------- C:\Documents and Settings\All Users\Application Data\SwiftSwitch 2007-02-06 02:25 2193939 --a------ C:\Programmer\Ti-Emulator.rar 2005-07-25 02:32 0 --a------ C:\Documents and Settings\Kaare Skovgaard\delphi7e.exe --------- C:\Programmer\Fælles filer\Wise Installation Wizard --------- C:\Programmer\Fælles filer\Real --------- C:\Programmer\Fælles filer . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATIModeChange"="Ati2mdxx.exe" [2001-09-04 10:24 C:\WINDOWS\system32\Ati2mdxx.exe] "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-02-10 21:10] "SoundMan"="SOUNDMAN.EXE" [2003-12-19 11:53 C:\WINDOWS\SOUNDMAN.EXE] "AGRSMMSG"="AGRSMMSG.exe" [2003-07-25 05:22 C:\WINDOWS\AGRSMMSG.exe] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50] "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06] "SynTPLpr"="C:\Programmer\Synaptics\SynTP\SynTPLpr.exe" [2004-01-09 08:09] "SynTPEnh"="C:\Programmer\Synaptics\SynTP\SynTPEnh.exe" [2004-01-09 08:09] "CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [2002-03-19 17:30] "CplBCL50"="C:\Programmer\EzButton\CplBCL50.EXE" [2004-03-02 11:45] "iTunesHelper"="C:\Programmer\iTunes\iTunesHelper.exe" [2006-02-23 15:45] "GrooveMonitor"="C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 01:47] "DAEMON Tools"="C:\Programmer\DAEMON Tools\daemon.exe" [2006-11-12 12:48] "SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00] "COMODO Firewall Pro"="C:\Programmer\Comodo\Firewall\CPF.exe" [2007-10-04 23:22] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TuneUp MemOptimizer"="C:\Programmer\TuneUp Utilities 2006\MemOptimizer.exe" [2005-09-21 23:34] "STYLEXP"="C:\Programmer\TGTSoft\StyleXP\StyleXP.exe" [2005-04-22 19:25] "msnmsgr"="C:\Programmer\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55] "SpybotSD TeaTimer"="C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-26 17:53] "Skype"="C:\Programmer\Skype\Phone\Skype.exe" [2007-03-12 16:05] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce] "WIAWizardMenu"=RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\ Apache Monitor.lnk - C:\www\Apache2\bin\ApacheMonitor.exe [2005-02-10 06:12:16] BTTray.lnk - C:\Programmer\WIDCOMM\Bluetooth-software\BTTray.exe [2005-09-19 16:02:54] C:\Documents and Settings\Kaare Skovgaard\Menuen Start\Programmer\Start\ Adobe Gamma.lnk - C:\Programmer\F‘lles filer\Adobe\Calibration\Adobe Gamma Loader.exe [2005-04-24 18:57:15] Rainlendar.lnk - C:\Programmer\Rainlendar\Rainlendar.exe [2005-07-22 17:14:46] C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\ Apache Monitor.lnk - C:\www\Apache2\bin\ApacheMonitor.exe [2005-02-10 06:12:16] BTTray.lnk - C:\Programmer\WIDCOMM\Bluetooth-software\BTTray.exe [2005-09-19 16:02:54] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "MimBoot"=C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe "WinampAgent"=C:\Programmer\Winamp\winampa.exe R2 MsDtsServer;SQL Server Integration Services;"C:\Programmer\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe" R2 MySQL501;MySQL501;"C:\www\MySQL 5.0\bin\mysqld-nt" --defaults-file="C:\www\MySQL 5.0\my.ini" MySQL501 R3 DKbFltr;Dritek HotKey Keyboard Filter Driver;C:\WINDOWS\system32\Drivers\DKbFltr.sys R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver;C:\WINDOWS\system32\Drivers\WBSD.SYS S2 MySQL5;MySQL5;"C:\Programmer\MySQL\MySQL Server 5.0\bin\mysqld-nt" --defaults-file="C:\Programmer\MySQL\MySQL Server 5.0\my.ini" MySQL5 S3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\Drivers\BrScnUsb.sys S3 CHC_DRIVER_SERVICE_0;Centrino Hardware Control Driver Service 0;\??\C:\Programmer\Centrino HC\chcdrv.sys S3 mchpusb;mchpusb;C:\WINDOWS\system32\DRIVERS\mchpusb.sys S3 p2pgasvc;Gruppegodkendelse på peer-netværk;C:\WINDOWS\System32\svchost.exe -k p2psvc S3 p2pimsvc;Identitetsstyring for peer-netværk;C:\WINDOWS\System32\svchost.exe -k p2psvc S3 p2psvc;Peer-netværk;C:\WINDOWS\System32\svchost.exe -k p2psvc S3 PNRPSvc;PNRP (Peer Name Resolution Protocol);C:\WINDOWS\System32\svchost.exe -k p2psvc S3 SQLWriter;SQL Server VSS Writer;"C:\Programmer\Microsoft SQL Server\90\Shared\sqlwriter.exe" S3 VWIFIMP;VirtualWiFi Miniport Driver;C:\WINDOWS\system32\DRIVERS\vwifi.sys S4 msvsmon80;Visual Studio 2005 Remote Debugger;"C:\Programmer\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon80 [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] p2psvc p2psvc p2pimsvc p2pgasvc PNRPSvc . Contents of the 'Scheduled Tasks' folder "2007-09-28 16:24:11 C:\WINDOWS\Tasks\1-Click Maintenance.job" - C:\Programmer\TuneUp Utilities 2006\SystemOptimizer.exe . ************************************************************************** catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net[...] Rootkit scan 2007-10-05 10:06:35 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\msftesql] "ImagePath"="\"C:\Programmer\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\msftesql.exe\" -s:MSSQL.2 -f:MSSQLSERVER" [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Aavmker4] [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\aawservice] "ImagePath"="\"C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe\"" . Completion time: 2007-10-05 10:11:50 - machine was rebooted C:\ComboFix-quarantined-files.txt ... 2007-10-05 10:11 . --- E O F --- HijackThis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:14:58, on 05-10-2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programmer\TGTSoft\StyleXP\StyleXPService.exe C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe C:\Programmer\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\brss01a.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\AGRSMMSG.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Programmer\Synaptics\SynTP\SynTPLpr.exe C:\Programmer\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\system32\taskswitch.exe C:\Programmer\EzButton\CplBCL50.EXE C:\Programmer\iTunes\iTunesHelper.exe C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Programmer\DAEMON Tools\daemon.exe C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe C:\www\Apache2\bin\Apache.exe C:\Programmer\Comodo\Firewall\CPF.exe C:\Programmer\TuneUp Utilities 2006\MemOptimizer.exe C:\Programmer\TGTSoft\StyleXP\StyleXP.exe C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\system32\ctfmon.exe C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\www\Apache2\bin\ApacheMonitor.exe C:\Programmer\WIDCOMM\Bluetooth-software\BTTray.exe C:\Programmer\Rainlendar\Rainlendar.exe C:\Programmer\WIDCOMM\Bluetooth-software\bin\btwdins.exe C:\www\Apache2\bin\Apache.exe C:\Programmer\Comodo\Firewall\cmdagent.exe C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Programmer\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe C:\Programmer\Microsoft SQL Server\MSSQL.3\OLAP\bin\msmdsrv.exe C:\www\MySQL 5.0\bin\mysqld-nt.exe C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\svchost.exe C:\Programmer\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\msftesql.exe C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe C:\WINDOWS\system32\wuauclt.exe C:\Programmer\Alwil Software\Avast4\ashWebSv.exe C:\Programmer\iPod\bin\iPodService.exe D:\Installers\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://netbank.danskebank.dk[...] R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe O4 - HKLM\..\Run: [CplBCL50] C:\Programmer\EzButton\CplBCL50.EXE O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Programmer\Comodo\Firewall\CPF.exe" /background O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Programmer\TuneUp Utilities 2006\MemOptimizer.exe" autostart O4 - HKCU\..\Run: [STYLEXP] C:\Programmer\TGTSoft\StyleXP\StyleXP.exe -Hide O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized O4 - Startup: Adobe Gamma.lnk = ? O4 - Startup: Rainlendar.lnk = C:\Programmer\Rainlendar\Rainlendar.exe O4 - Global Startup: Apache Monitor.lnk = C:\www\Apache2\bin\ApacheMonitor.exe O4 - Global Startup: BTTray.lnk = ? O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Send til &Bluetooth - C:\Programmer\WIDCOMM\Bluetooth-software\btsendto_ie_ctx.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth-software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth-software\btsendto_ie.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com[...] O16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) - https://netbank.danskebank.dk[...] O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com[...] O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com[...] O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com[...] O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk[...] O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmer\Fælles filer\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apache2 - Apache Software Foundation - C:\www\Apache2\bin\Apache.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmer\WIDCOMM\Bluetooth-software\bin\btwdins.exe O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Programmer\Comodo\Firewall\cmdagent.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe O23 - Service: MySQL - Unknown owner - C:\www\MySQL\bin\mysqld-nt (file missing) O23 - Service: MySQL5 - Unknown owner - C:\Programmer\MySQL\MySQL.exe (file missing) O23 - Service: MySQL501 - Unknown owner - C:\www\MySQL.exe (file missing) O23 - Service: StyleXPService - Unknown owner - C:\Programmer\TGTSoft\StyleXP\StyleXPService.exe O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Programmer\TuneUp Utilities 2006\WinStylerThemeSvc.exe O24 - Desktop Component 1: (no name) - http://skema.randersts.dk[...] -- End of file - 9766 bytes Igen tysind tak for hjælpen! --
--
Kaare
#5
*Cookie
Supporter
05-10-2007 11:35

Rapporter til Admin
Hej igen kastermester. Godt valg ;o) ! Jeg tror, du bliver glad for Comodo. Der er egl. ikke noget alarmerende i dine logs, men du har en del programmer liggende i din opstart, der er unødvendige at have liggende der. De kan alle nemt nås via Start => Programmer, så de ligger bare og sluger ressourcer. Dem kan du med fordel fravælge, hvis du vil. I så fald gør flg.: Gå i Start=>Kør og skriv: msconfig. Klik OK og gå i fanebladet Start. Fjern vingen til venstre for flg. programmer: - [ATIModeChange] Ati2mdxx.exe - [ATIPTA] C:\Program Files\ATI Technologies\ATI Control - [SoundMan] SOUNDMAN.EXE - [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe - [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe (
--
Member of Alliance of Security Analysis Professionals http://asap.maddoktor2.com[...]
#6
*Cookie
Supporter
05-10-2007 11:46

Rapporter til Admin
Sorry, link-fix: http://www.snapfiles.com[...] //*Cookie --
--
Member of Alliance of Security Analysis Professionals http://asap.maddoktor2.com[...]

Opret svar til indlægget: HJT log - en venlig sjæl der vil hjælpe?

Grundet øget spam aktivitet fra gæstebrugere, er det desværre ikke længere muligt, at oprette svar som gæst.

Hvis du ønsker at deltage i debatten, skal du oprette en brugerprofil.

Opret bruger | Login
NYHEDSBREV
Afstemning