Gå til innhold

[Løst]Platinumsoft2010 virus - ettervirkning


Anbefalte innlegg

Jeg fikk plutselig platinumsoft2010-viruset og etter mye om og men, klarte jeg omsider å bli kvitt det.

 

Først med sikkerhetsmodus og så kjøre Malwarebytes. Så puttet jeg harddisken min i damas pc og fikk fjernet resten med oppdatert malwarebytes.

 

Det ser ut til at viruset er borte men problemet er at jeg kommer ikke inn på internett.

 

Jeg har nettverksoppkobling og kan snakke med folk på skype og jeg kan laste ned fra uTorrent.

 

Men hverken IE eller Opera fungerer.

 

Hva kan være galt?

Lenke til kommentar
Videoannonse
Annonse

Da avinstallerer jeg combofix ;)

 

 

ComboFix 10-01-04.01 - Administrator 05.01.2010  20:11:21.1.2 - x86
Microsoft Windows XP Professional  5.1.2600.2.1252.47.1033.18.3071.2589 [GMT 1:00]
Kjører fra: c:\users\Administrator\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 100105-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

ADVARSEL -DENNE MASKINEN HAR IKKE GJENOPPRETTINGSKONSOLLEN INSTALLERT !!
.

(((((((((((((((((((((((((((((((((((((((   Andre slettinger   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\tmp83.tmp
c:\windows\system32\tmp84.tmp

.
(((((((((((((((((((((((((((   Filer Opprettet Fra 2009-12-05 til 2010-01-05  )))))))))))))))))))))))))))))))))
.

2010-01-04 22:41 . 2010-01-04 23:55	--------	d-----w-	c:\users\Administrator\Local Settings\Application Data\acnrwx
2009-12-31 01:55 . 2009-12-31 01:55	--------	d-----w-	C:\bridge1
2009-12-27 19:35 . 2009-12-31 13:48	--------	d-----w-	c:\program files\VTTrader 2
2009-12-22 23:59 . 2009-12-22 23:59	41872	----a-w-	c:\windows\system32\xfcodec.dll
2009-12-17 06:02 . 2009-12-17 06:02	--------	d-----w-	c:\users\Administrator\Local Settings\Application Data\Saxo Bank
2009-12-17 06:02 . 2009-12-31 13:48	--------	d-----w-	c:\program files\Saxo Bank
2009-12-17 05:04 . 2009-12-17 05:04	--------	d-----w-	c:\users\Administrator\Application Data\Canon
2009-12-15 06:12 . 2009-12-15 06:12	--------	d-----w-	c:\users\Administrator\Application Data\Malwarebytes
2009-12-15 06:12 . 2009-12-30 13:55	38224	----a-w-	c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-15 06:12 . 2010-01-05 07:14	--------	d-----w-	c:\program files\Malwarebytes' Anti-Malware
2009-12-15 06:12 . 2009-12-30 13:54	19160	----a-w-	c:\windows\system32\drivers\mbam.sys
2009-12-15 06:12 . 2009-12-15 06:12	--------	d-----w-	c:\users\All Users\Application Data\Malwarebytes
2009-12-14 01:11 . 2009-12-14 01:11	--------	d--h--w-	c:\windows\PIF
2009-12-13 20:10 . 1999-12-17 09:13	86016	----a-w-	c:\windows\unvise32.exe
2009-12-13 20:10 . 2009-12-13 23:48	--------	d-----w-	c:\program files\CashFlowatHome
2009-12-13 20:06 . 2009-12-30 09:00	--------	d-----w-	c:\program files\CASHFLOW
2009-12-08 22:33 . 2009-10-21 05:50	75776	------w-	c:\windows\system32\dllcache\strmfilt.dll
2009-12-08 22:33 . 2009-10-21 05:50	25088	------w-	c:\windows\system32\dllcache\httpapi.dll
2009-12-08 22:33 . 2009-10-20 14:41	265728	------w-	c:\windows\system32\dllcache\http.sys
2009-12-08 22:33 . 2009-10-12 13:54	69632	------w-	c:\windows\system32\dllcache\raschap.dll
2009-12-08 22:33 . 2009-10-12 13:54	112128	------w-	c:\windows\system32\dllcache\rastls.dll
2009-12-08 22:32 . 2009-10-13 10:45	270336	------w-	c:\windows\system32\dllcache\oakley.dll

.
((((((((((((((((((((((((((((((((((((((((   Find3M Rapport   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-05 19:08 . 2009-02-02 01:25	--------	d-----w-	c:\users\Administrator\Application Data\DNA
2010-01-05 19:08 . 2008-05-13 00:27	--------	d-----w-	c:\users\Administrator\Application Data\uTorrent
2010-01-05 18:54 . 2009-03-06 02:15	--------	d-----w-	c:\users\Administrator\Application Data\Skype
2010-01-05 15:01 . 2009-03-06 02:16	--------	d-----w-	c:\users\Administrator\Application Data\skypePM
2010-01-05 08:40 . 2009-02-02 01:25	--------	d-----w-	c:\program files\DNA
2010-01-05 07:10 . 2008-05-13 00:32	147320	----a-w-	c:\users\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-05 03:02 . 2008-05-13 00:16	--------	d-----w-	c:\program files\TaskSwitchXP
2010-01-05 03:01 . 2008-07-04 05:29	--------	d-----w-	c:\users\Administrator\Application Data\Sony
2010-01-05 01:15 . 2008-08-03 23:33	--------	d-----w-	c:\users\All Users\Application Data\Google Updater
2010-01-05 00:27 . 2009-12-02 00:17	--------	d-----w-	c:\users\Administrator\Application Data\X-Chat 2
2010-01-05 00:08 . 2008-05-12 19:01	--------	d-----w-	c:\program files\Spybot - Search & Destroy
2010-01-04 23:59 . 2008-05-13 15:58	--------	d-----w-	c:\program files\Xfire
2010-01-04 23:57 . 2008-05-13 15:58	--------	d-----w-	c:\users\Administrator\Application Data\Xfire
2010-01-04 01:47 . 2009-10-12 18:26	1	----a-w-	c:\users\Administrator\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-01-03 22:04 . 2008-05-13 01:54	--------	d-----w-	c:\program files\PowerArchiver
2009-12-27 14:05 . 2009-11-16 08:51	59	----a-w-	c:\windows\wpd99.drv
2009-12-27 14:05 . 2009-11-16 08:51	--------	d-----w-	c:\users\All Users\Application Data\pdf995
2009-12-26 01:03 . 2008-08-03 23:33	--------	d-----w-	c:\program files\Google
2009-12-02 00:16 . 2009-12-02 00:16	--------	d-----w-	c:\program files\X-Chat 2
2009-11-30 13:57 . 2009-11-30 13:57	1924440	----a-w-	c:\users\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-11-28 11:36 . 2008-07-28 13:44	--------	d-----w-	c:\program files\Winamp
2009-11-24 16:22 . 2009-11-24 16:22	--------	d-----w-	c:\program files\Bonjour
2009-11-24 16:22 . 2008-07-01 01:15	--------	d-----w-	c:\program files\Common Files\Adobe
2009-11-24 16:06 . 2008-07-18 14:16	--------	d-----w-	c:\program files\PowerISO
2009-11-24 16:03 . 2009-05-30 11:59	--------	d-----w-	c:\program files\u-he
2009-11-23 09:04 . 2009-03-06 02:16	56	---ha-w-	c:\windows\system32\ezsidmv.dat
2009-11-23 02:15 . 2009-11-23 02:15	289832	----a-w-	c:\users\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-11-22 15:55 . 2008-07-08 20:04	--------	d--h--w-	c:\program files\InstallShield Installation Information
2009-11-22 15:54 . 2009-01-13 12:47	--------	d-----w-	c:\program files\Electronic Arts
2009-11-19 20:54 . 2009-11-19 20:54	--------	d-----w-	c:\users\All Users\Application Data\FLEXnet
2009-11-19 20:41 . 2009-11-19 20:41	--------	d-----w-	c:\program files\Common Files\Adobe AIR
2009-11-19 20:37 . 2009-11-19 20:37	--------	d-----w-	c:\program files\Common Files\Macrovision Shared
2009-11-16 08:57 . 2009-11-16 08:57	--------	d-----w-	c:\users\Administrator\Application Data\pdf995
2009-11-16 08:54 . 2009-10-12 18:24	--------	d-----w-	c:\program files\OpenOffice.org 3
2009-11-16 08:53 . 2009-11-16 08:51	--------	d-----w-	c:\program files\pdf995
2009-11-16 08:51 . 2009-11-16 08:51	51716	----a-w-	c:\windows\system32\pdf995mon.dll
2009-11-16 08:51 . 2009-11-16 08:51	249856	----a-w-	c:\windows\system32\pdfmona.dll
2009-11-09 03:21 . 2009-11-09 03:21	59388	----a-w-	c:\windows\system32\drivers\scdemu.sys
2009-11-07 00:27 . 2009-11-07 00:27	--------	d-----w-	c:\program files\Ubisoft
2009-10-29 07:46 . 2007-11-07 09:00	832512	----a-w-	c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2007-11-07 09:00	78336	----a-w-	c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2007-11-07 09:00	17408	----a-w-	c:\windows\system32\corpol.dll
2009-10-21 05:50 . 2007-11-07 09:00	75776	----a-w-	c:\windows\system32\strmfilt.dll
2009-10-21 05:50 . 2007-11-07 09:00	25088	----a-w-	c:\windows\system32\httpapi.dll
2009-10-20 14:41 . 2007-11-07 09:00	265728	----a-w-	c:\windows\system32\drivers\http.sys
2009-10-13 10:45 . 2007-11-07 09:00	270336	----a-w-	c:\windows\system32\oakley.dll
2009-10-12 13:54 . 2007-11-07 09:00	69632	----a-w-	c:\windows\system32\raschap.dll
2009-10-12 13:54 . 2007-11-07 09:00	112128	----a-w-	c:\windows\system32\rastls.dll
.

------- Sigcheck -------

[-] 2008-04-14 . BD38D1EBE24A46BD3EDA059560AFBA12 . 1054208 . . [6.0] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\asms\60\msft\windows\common\controls\comctl32.dll
[-] 2008-04-14 . 06F247492BC786CE5C24A23E178C711A . 617472 . . [5.82] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\comctl32.dll
[-] 2007-11-07 . 43A336FC1C015417D981B2D32B27B8FF . 643072 . . [5.82] . . c:\windows\system32\comctl32.dll

[-] 2008-04-14 . B26B135FF1B9F60C9388B4A7D16F600B . 578560 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\user32.dll
[-] 2007-11-07 . 0F551F3FB9C1B1884AA6FC6B13D9118D . 636928 . . [5.1.2600.3099] . . c:\windows\system32\user32.dll

[-] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\explorer.exe
[-] 2007-11-07 . A5BDD7E1FEEAFBE9F975C734FF6B98DB . 1587712 . . [6.00.2900.2894] . . c:\windows\explorer.exe

[-] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\ctfmon.exe
[-] 2007-11-07 . E00DFA816FA5521EB44C5D63109DE2A9 . 40448 . . [5.1.2600.2180] . . c:\windows\system32\ctfmon.exe

[-] 2008-04-14 . 5B19B557B0C188210A56A6B699D90B8F . 59904 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\regsvc.dll

c:\windows\System32\regsvc.dll ... mangler !!
.
((((((((((((((((((((((((((((((((   Oppstartspunkter I Registeret   )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Merk* tomme oppføringer & gyldige standardoppføringer vises ikke  
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-12-10 289584]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-08-29 171464]
"PowerArchiver Tray"="c:\program files\PowerArchiver\PASTARTER.EXE" [2007-05-21 140328]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2008-07-21 2752512]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-13 323392]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-02-04 23975720]
"CurseClient"="c:\program files\Curse\CurseClient.exe" [2009-06-08 1934336]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-13 8466432]
"nwiz"="nwiz.exe" [2007-07-13 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-07-13 81920]
"RTHDCPL"="RTHDCPL.EXE" [2007-10-16 16855552]
"PowerTweak Menu"="c:\windows\system32\mmm.exe" [2005-07-05 828416]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-10-20 286720]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-11-09 180224]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2007-05-14 35328]
"H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-10-22 385024]
"WTClient"="WTClient.exe" [2007-04-11 40960]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2007-11-30 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2007-11-30 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2007-11-30 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2007-11-30 455168]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2007-11-07 110592]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" [2009-10-29 124928]
"NewUser"="c:\windows\System32\NewUser.cmd" [2007-11-07 2475]

c:\users\Administrator\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-17 113664]
Visual Task Tips.lnk - c:\ppapps\VisualTaskTips\VisualTaskTips.exe [2008-5-13 36352]
Xfire.lnk - c:\program files\Xfire\xfire.exe [2009-12-23 3192720]

c:\users\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Ralink Wireless Utility.lnk - c:\program files\RALINK\Common\RaUI.exe [2008-11-22 606208]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"d:\\Spill\\World of Warcraft\\WoW-2.4.3-to-3.0.2-enGB-Win-Final-downloader.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"d:\\Spill\\World of Warcraft\\BackgroundDownloader.exe"=
"d:\\Spill\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enGB-downloader.exe"=
"d:\\Spill\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enGB-downloader.exe"=
"d:\\Spill\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"6112:TCP"= 6112:TCP:Blizzard Downloader
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [23.09.2009 21:31 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [23.09.2009 21:31 20560]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [23.12.2008 20:29 33792]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [13.05.2008 01:15 685816]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [17.11.2009 11:56 135664]

--- Andre tjenester/drivere lastet i minnet ---

*NewlyCreated* - ASPI32
.
Innholdet i mappen 'Scheduled Tasks' (planlagte oppgaver)

2010-01-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-08-03 10:48]

2010-01-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-17 10:56]

2010-01-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-17 10:56]

2010-01-05 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-09-17 20:18]
.
.
------- Tilleggsskanning -------
.
uStart Page = hxxp://www.google.no/
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
.
.
------- Filassosiasjoner -------
.
inifile=c:\windows\system32\Notepad2.exe %1
txtfile=c:\windows\system32\Notepad2.exe %1
.
- - - - TOMME PEKERE FJERNET - - - -

HKCU-Run-MsnMsgr - c:\program files\Windows Live\Messenger\msnmsgr.exe
HKCU-Run-AdobeBridge - (no file)
HKLM-Run-SunJavaUpdateSched - (no file)
HKLM-Run-AAWTray - c:\program files\Lavasoft\Ad-Aware 2007\AAWTray.exe
HKLM-Run-AdVantage Setup - c:\program files\DAEMON Tools\AdVantageSetup.exe
HKU-Default-Run-TaskSwitchXP - c:\program files\TaskSwitchXP\TaskSwitchXP.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [url="http://www.gmer.net"]http://www.gmer.net[/url]
Rootkit scan 2010-01-05 20:15
Windows 5.1.2600 Service Pack 2 NTFS

skanner skjulte prosesser ...  

skanner skjulte autostart-oppføringer ... 

skanner skjulte filer ...  

skanning vellykket
skjulte filer: 0

**************************************************************************
.
--------------------- LÅSTE REGISTERNØKLER ---------------------

[HKEY_USERS\S-1-5-21-1343024091-1417001333-839522115-500\Software\SecuROM\License information*]
"datasecu"=hex:b9,ea,42,c9,f7,e9,ec,aa,d4,77,ad,3b,46,fd,89,bd,7d,86,e0,67,81,
  a7,c1,a9,62,9b,db,eb,60,71,82,10,ff,0b,e2,5d,7a,5b,db,85,86,95,ce,6a,d9,10,\
"rkeysecu"=hex:3e,80,9e,c4,40,b4,90,83,87,8e,33,49,64,ac,f8,d9
.
--------------------- DLL'er Lastet Av Kjørende Prosesser ---------------------

- - - - - - - > 'winlogon.exe'(1228)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\cscui.dll

- - - - - - - > 'lsass.exe'(1284)
c:\windows\system32\setupapi.dll
.
Tidspunkt ferdig: 2010-01-05  20:16:31
ComboFix-quarantined-files.txt  2010-01-05 19:16

Pre-Run: 15 036 612 608 bytes free
Post-Run: 15 031 943 168 bytes free

- - End Of File - - 6363F2FAA63A83AB3FA49EEDC80FE1F2

 

 

edit: ummm... hvordan avinstallerer jeg combofix?

Endret av Bayne
Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
×
×
  • Opprett ny...