Gå til innhold

Msn virus fra "photobucket"-link


Anbefalte innlegg

Har fått et virus fra en youtube fil, jeg sletta den ntmngr.exe fila.

 

Jeg tror det er bra men hver gang jeg starter opp maskinen så kommer vil du kjøre ntmngr.exe filen?

 

hva skal jeg gjøre? er 11 år og er på gråten her (drit redd) :(

 

Edit:

 

Kjører avast på grundig skanning nå!

 

Ikke noe å begynne å gråte for. I første omgang kan du kjøre en scan med Combofix. Den lager en logg som du poster. Du kan godt opprette en egen tråd (klikk Nytt emne-knappen) der du legger loggen.

 

Hent Combofix, og legg det på skrivebordet

 

Kjør combofix.exe, og følg veiledningen.

Du må ikke klikke på vinduet mens programmet kjører.

 

Post loggfilen fra combofix (c:\combofix.txt)

Lenke til kommentar
Videoannonse
Annonse
Jeg lurer på om det er noe standardmåte/smørbrødsliste for hvordan å identifisere at en har fått viruset, og deretter for fjerning. Eventuellt om det er noen av anti-virus-programmene som tar dette?

 

Dette fordi det ser ut til at en god del har fått dette, og hadde vært fint å sende til evt de som har fått dette viruset pga av meg. Disse har gjerne ikke noe særlig datakunnskaper, så hadde vært best med et program som gjorde hele greien.

 

Ser ut som om du har peil norbat, noen innspill?

Jeg henger meg på den. Begynner å bli faretruende mange venner som hyler etter hjelp. :ph34r:

Lenke til kommentar
Jeg lurer på om det er noe standardmåte/smørbrødsliste for hvordan å identifisere at en har fått viruset, og deretter for fjerning. Eventuellt om det er noen av anti-virus-programmene som tar dette?

 

Dette fordi det ser ut til at en god del har fått dette, og hadde vært fint å sende til evt de som har fått dette viruset pga av meg. Disse har gjerne ikke noe særlig datakunnskaper, så hadde vært best med et program som gjorde hele greien.

 

Ser ut som om du har peil norbat, noen innspill?

 

Vil tro man merker at man har dette da msn begynner å sende dette ut til kontaktene.

 

Fordi dette er en 'ny' infeksjon, tar det litt tid før av-programmene har fått laget en fix for dette. Problemfilene er i all hovedsak knyttet til følgende to filer:

 

C:\Windows\ntmngr.exe: Dette er en Backdoor.Win32.IRCBot-fil (Kaspersky) eller IRC/BackDoor.SdBot3.XAT (AVG) som gjør at andre kan få tilgang til PC-en

 

C:\Windows:\Issas.exe. Prevx kaller den for SystemPoser:Trojan. Få av-prog tar denne foreløpig. I forbindelse med denne fila så dukker også fila 62916400BB40211E"]445930.exe[/b] opp (gjør bla. til at Issas.exe fila starter opp sammen med windows)

 

 

Hvordan løse dette:

 

MSNFix fjerner bla. noen images.zip filer som opprettes.

 

ComboFix klarer å fjerne 445930.exe og images.zip fila og vil avsløre om Issas.exe og ntmngr.exe ligger på PC-en.

 

Issas.exe og ntmngr.exe kan man da fjerne manuelt (de vil mest sannsynlig være skjulte filer og man må da sette mappealt. til å vise skjulte filer samt vise beskyttede operativsystemfiler). Ofte så er det best å slette filene fra sikker modus da det kan være vanskelig å slette dem om de er i bruk. Alt. er å stoppe prosessene vha. oppgavebehandlingen.

 

Alt. er å spørre om hjelp på forumet. Kjør Combofix og legg loggen i en egen tråd som du oppretter ved å klikke Nytt emne-knappen.

Endret av norbat
Lenke til kommentar
Har fått et virus fra en youtube fil, jeg sletta den ntmngr.exe fila.

 

Jeg tror det er bra men hver gang jeg starter opp maskinen så kommer vil du kjøre ntmngr.exe filen?

 

hva skal jeg gjøre? er 11 år og er på gråten her (drit redd) :(

 

Edit:

 

Kjører avast på grundig skanning nå!

 

Ikke noe å begynne å gråte for. I første omgang kan du kjøre en scan med Combofix. Den lager en logg som du poster. Du kan godt opprette en egen tråd (klikk Nytt emne-knappen) der du legger loggen.

 

Hent Combofix, og legg det på skrivebordet

 

Kjør combofix.exe, og følg veiledningen.

Du må ikke klikke på vinduet mens programmet kjører.

 

Post loggfilen fra combofix (c:\combofix.txt)

 

har gjort det, vær så snill se på den

Lenke til kommentar

Takk for god oppsummering norbat, men nå har tingene viklet seg enda mere sammen for min del:

 

Jeg får ikke combofix til å fungere. Når det starter ser det fint ut, det står at den skal søke og det kan ta opptil 10 min, men så forsvinner vinduet av seg selv (har ikke trykket på det el.) og nå har nettverkstilkoblingen min sluttet å fungere (kommer ikke på internett)...

Lenke til kommentar

Se om du får kjørt en systemgjenoppretting til da nettverkstilkoblingen fungerte ok

(I XP så finner man gjenopprettingen på Tilbehør->systemverktøy->systemgjenoppretting).

 

Evt. det kan være at winsock har blitt korrupt. Fra kjør/søk-feltet i vista kan du skrive følgende (en restart er antakelig nødvendig):

netsh winsock reset catalog

Lenke til kommentar
Pjunin:

 

Gå til nettstedet http://virusscan.jotti.org/ og last opp følgende fil for sjekk: C:\WINDOWS\system32\drivers\qbqydcex.sys

(Du må antakelig slå på "Vis skjulte filer og mapper" og slå av "Skjul beskyttede operativsystemfiler" for å se den). Gi tilbakemelding på om de ble funnet noe.

 

Fann ingenting :hmm:

 

Kjørte combofix en gang til og fekk denna følgende rapport;

 

ComboFix 08-01-11.3 - Eldar Godø 2008-01-12 17:38:50.2 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.681 [GMT 1:00]

Running from: C:\Documents and Settings\Eldar Godø\Desktop\ComboFix.exe

Command switches used :: C:\Documents and Settings\Eldar Godø\Desktop\CFScript.txt

* Created a new restore point

 

FILE

C:\ojbehyqa.bat

.

 

((((((((((((((((((((((((( Files Created from 2007-12-12 to 2008-01-12 )))))))))))))))))))))))))))))))

.

 

2008-01-12 03:19 . 2008-01-12 03:19 1,159 --a------ C:\zia02540

2008-01-12 03:12 . 2008-01-12 03:12 60,416 --a------ C:\WINDOWS\system32\drivers\vcannlmg.sys

2008-01-12 02:38 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe

2008-01-12 02:34 . 2008-01-12 03:12 <DIR> d-------- C:\Program Files\Avenger

2008-01-12 01:52 . 2008-01-12 01:52 <DIR> d-------- C:\Program Files\Opera

2008-01-11 22:45 . 2008-01-11 22:46 <DIR> d-------- C:\Program Files\Crimson Editor

2008-01-07 15:57 . 2008-01-12 17:24 54,156 --ah----- C:\WINDOWS\QTFont.qfn

2008-01-07 15:57 . 2008-01-07 15:57 1,409 --a------ C:\WINDOWS\QTFont.for

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-01-12 05:42 --------- d-----w C:\Program Files\Trillian

2008-01-12 02:15 202 ----a-w C:\Program Files\lmktpuyv.txt

2008-01-11 20:58 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys

2008-01-11 20:58 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys

2008-01-11 20:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft

2008-01-11 20:57 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe

2007-11-30 15:25 --------- d-----w C:\Documents and Settings\Eldar Godø\Application Data\Ventrilo

2007-11-14 16:43 --------- d-----w C:\Program Files\Ventrilo

2007-11-14 16:43 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard

2007-03-02 00:25 21,822,168 ----a-w C:\Program Files\AdbeRdr80_en_US.exe

2007-03-02 00:19 7,050,552 ----a-w C:\Program Files\psa30se_en_us.exe

.

 

((((((((((((((((((((((((((((( snapshot@2008-01-12_ 2.43.15.10 )))))))))))))))))))))))))))))))))))))))))

.

- 2008-01-12 01:42:05 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT

+ 2008-01-12 16:38:45 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT

- 2008-01-12 01:42:05 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat

+ 2008-01-12 16:38:45 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat

- 2008-01-12 01:42:05 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT

+ 2008-01-12 16:38:45 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT

- 2008-01-12 01:42:05 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat

+ 2008-01-12 16:38:45 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat

- 2008-01-12 01:42:05 6,238,208 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT

+ 2008-01-12 16:38:46 6,238,208 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT

- 2008-01-12 01:42:05 102,400 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat

+ 2008-01-12 16:38:46 102,400 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-05-30 12:52 868352]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SoundMan"="SOUNDMAN.EXE" [2004-01-08 19:54 65536 C:\WINDOWS\SOUNDMAN.EXE]

"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-12-12 10:31 335872]

"EM_EXEC"="C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [2001-09-19 08:41 35328]

"MULTIMEDIA KEYBOARD"="C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe" [2002-06-12 22:50 167936]

"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 12:03 36975]

"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2006-09-22 17:59 921600]

"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [ ]

"Launch LGDCore"="C:\Program Files\Logitech\G-series Software\LGDCore.exe" [2006-03-06 16:31 1122304]

"Launch LCDMon"="C:\Program Files\Logitech\G-series Software\LCDMon.exe" [2006-03-06 16:14 497152]

"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24 286720]

"dieayepa"="C:\gexfsth^.bat" [ ]

"jlxmaswg"="C:\bqeixjyd.bat" [ ]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 02:07 15360]

 

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\

Wireless Config.lnk - C:\Program Files\Wireless Technology Corporation\Wireless LAN 802.11b USB\ZDConfig.exe [2006-09-22 17:51:37]

 

R1 ewido security suite driver;ewido security suite driver;C:\Program Files\ewido anti-malware\guard.sys [2005-12-30 12:12]

R1 msikbd2k;Multimedia Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys [2001-12-20 08:02]

R2 nhksrv;Netropa NHK Server;C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe [2001-08-06 05:41]

R3 ZD1201U(ZyDAS);ZyDAS ZD1201 IEEE 802.11b Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1201u.sys [2003-07-31 16:41]

R3 ZDNDIS5;ZDNDIS5 Protocol Driver;C:\WINDOWS\system32\ZDNDIS5.SYS [2002-10-30 10:43]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]

\Shell\AutoRun\command - G:\LaunchU3.exe -a

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{92bb3f4d-c08e-11dc-82a9-000e8e000fc2}]

\Shell\AutoRun\command - G:\LaunchU3.exe -a

 

.

Contents of the 'Scheduled Tasks' folder

"2008-01-12 04:02:50 C:\WINDOWS\Tasks\Se etter oppdateringer for Windows Live Toolbar.job"

- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE

.

**************************************************************************

 

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-01-12 17:39:42

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2008-01-12 17:40:03

ComboFix2.txt 2008-01-12 01:43:30

.

2007-07-11 15:48:16 --- E O F ---

 

 

EDIT:

Scannet følgende filer på virusscan.jotti

C:\WINDOWS\system32\drivers\vcannlmg.sys

Panda Antivirus Found Rootkit/Booto.C

 

C:\WINDOWS\NirCmd.exe

AntiVir Found APPL/NirCmd.3

Panda Antivirus Found Application/NirCmd.A

Endret av Pjunin
Lenke til kommentar

Last ned SDFix til skrivebordet.

 

Dobbeltklikk på SDFix.exe og det vil pakke seg ut til ei mappe i C:\SDFix

 

Restart PC-en i sikker modus (tapp F8 under oppstart, velg sikker modus)

 

Åpne SDFix-mappa og dobbeltklikk på 'RunThis.bat' for å starte programmet

Velg Y for å starte rensingen

PC-en vil restarte, og SDFix vil fortsette.

Post loggen den lager.

 

Edit: C:\WINDOWS\NirCmd.exe er en del av Combofix.

Endret av norbat
Lenke til kommentar
du sier hele tida "post loggen", men hva er det godt for? Jeg har enda ikke sett et innlegg som sier: "Sånn blir du kvitt det" her :(

 

Så lenge det er ulike filer der noen filer må fjernes manuelt, så er jeg (vet ikke hva andre trenger) avhengig av å se disse loggene som kan fortelle hvilke filer som ligger der. Dette for å være sikker på at man fjerner de filene man skal, at ikke noe annet ligger og ulmer på PC-en etc. Jeg lover at jeg ikke ber dem post loggene for moro skyld. :)

 

Det ligger noen poster som forteller hvilke filer som er mest sentrale i denne epidemien (bla. lssas.exe og ntmngr.exe). Disse kan man selvfølgelig spore opp og slette, men om det ligger noen andre filer der som også bør vekk, ja det kan en logg fortelle.

Lenke til kommentar

SDFix rapporten:

 

 

SDFix: Version 1.126

 

Run by Eldar Godø on 12.01.2008 at 18:44

 

Microsoft Windows XP [Version 5.1.2600]

 

Running From: C:\SDFix

 

Safe Mode:

Checking Services:

 

 

Restoring Windows Registry Values

Restoring Windows Default Hosts File

 

Rebooting...

 

 

Normal Mode:

Checking Files:

 

No Trojan Files Found

 

 

 

 

 

Removing Temp Files...

 

ADS Check:

 

C:\WINDOWS

No streams found.

 

C:\WINDOWS\system32

No streams found.

 

C:\WINDOWS\system32\svchost.exe

No streams found.

 

C:\WINDOWS\system32\ntoskrnl.exe

No streams found.

 

 

 

Final Check:

 

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-01-12 18:49:02

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden services & system hive ...

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]

"s0"=dword:3a0df84a

"s1"=dword:dd1b4d47

"s2"=dword:2906352f

"h0"=dword:00000001

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]

"p0"="C:\Program Files\DAEMON Tools\"

"h0"=dword:00000000

"khjeh"=hex:dc,ee,47,03,e4,78,ce,19,a6,6a,27,63,2d,b1,a1,e4,06,a1,2d,37,70,..

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA40000001]

"a0"=hex:20,01,00,00,b8,52,77,80,29,f9,6c,43,a0,1e,93,51,fc,a3,5b,8c,9e,..

"khjeh"=hex:91,ff,e6,b7,4e,cc,10,49,a1,5b,0b,7f,4a,6e,e4,b0,99,12,01,d8,17,..

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA40000001Jf40]

"khjeh"=hex:d3,13,5a,fb,98,3c,5c,5b,56,d0,6c,6d,e8,f4,4f,5c,46,69,c9,97,fb,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]

"p0"="C:\Program Files\DAEMON Tools\"

"h0"=dword:00000000

"khjeh"=hex:dc,ee,47,03,e4,78,ce,19,a6,6a,27,63,2d,b1,a1,e4,06,a1,2d,37,70,..

 

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA40000001]

"a0"=hex:20,01,00,00,b8,52,77,80,29,f9,6c,43,a0,1e,93,51,fc,a3,5b,8c,9e,..

"khjeh"=hex:91,ff,e6,b7,4e,cc,10,49,a1,5b,0b,7f,4a,6e,e4,b0,99,12,01,d8,17,..

 

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA40000001Jf40]

"khjeh"=hex:d3,13,5a,fb,98,3c,5c,5b,56,d0,6c,6d,e8,f4,4f,5c,46,69,c9,97,fb,..

 

scanning hidden registry entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 0

 

 

Remaining Services:

------------------

 

 

 

Authorized Application Key Export:

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

 

Remaining Files:

---------------

 

 

Files with Hidden Attributes:

 

Wed 31 May 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"

 

Finished!

 

 

 

Syns jeg har spammet nokk med rapporter no :blush:

Men du skal ha stor takk for all hjelpen du har gitt meg mr.Norbat :!:

Endret av Pjunin
Lenke til kommentar
Er dere sikre på at denne greia er ufarlig, utenom å bare spre seg selv? Søstra mi fikk dette viruset i går (selv klarte jeg heldigvis å unngå det), og i dag har alt gått på dunken. Hun klarer ikke å starte Windows lenger, selv ikke i sikkerhetsmodus! :ohmy:

 

Denne trojaneren er nok mer farlig enn at den bare sprer seg til andre. Den har en bakdørfunksjon, som gjør at andre kan få tilgang til pc og at den åpner for å hente inn andre filer av tvilsom karakter.

Lenke til kommentar
SDFix rapporten:

 

 

 

SDFix: Version 1.126

 

Run by Eldar Godø on 12.01.2008 at 18:44

 

Microsoft Windows XP [Version 5.1.2600]

 

Running From: C:\SDFix

 

Safe Mode:

Checking Services:

 

 

Restoring Windows Registry Values

Restoring Windows Default Hosts File

 

Rebooting...

 

 

Normal Mode:

Checking Files:

 

No Trojan Files Found

 

 

 

 

 

Removing Temp Files...

 

ADS Check:

 

C:\WINDOWS

No streams found.

 

C:\WINDOWS\system32

No streams found.

 

C:\WINDOWS\system32\svchost.exe

No streams found.

 

C:\WINDOWS\system32\ntoskrnl.exe

No streams found.

 

 

 

Final Check:

 

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-01-12 18:49:02

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden services & system hive ...

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]

"s0"=dword:3a0df84a

"s1"=dword:dd1b4d47

"s2"=dword:2906352f

"h0"=dword:00000001

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]

"p0"="C:\Program Files\DAEMON Tools\"

"h0"=dword:00000000

"khjeh"=hex:dc,ee,47,03,e4,78,ce,19,a6,6a,27,63,2d,b1,a1,e4,06,a1,2d,37,70,..

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA40000001]

"a0"=hex:20,01,00,00,b8,52,77,80,29,f9,6c,43,a0,1e,93,51,fc,a3,5b,8c,9e,..

"khjeh"=hex:91,ff,e6,b7,4e,cc,10,49,a1,5b,0b,7f,4a,6e,e4,b0,99,12,01,d8,17,..

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA40000001Jf40]

"khjeh"=hex:d3,13,5a,fb,98,3c,5c,5b,56,d0,6c,6d,e8,f4,4f,5c,46,69,c9,97,fb,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]

"p0"="C:\Program Files\DAEMON Tools\"

"h0"=dword:00000000

"khjeh"=hex:dc,ee,47,03,e4,78,ce,19,a6,6a,27,63,2d,b1,a1,e4,06,a1,2d,37,70,..

 

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA40000001]

"a0"=hex:20,01,00,00,b8,52,77,80,29,f9,6c,43,a0,1e,93,51,fc,a3,5b,8c,9e,..

"khjeh"=hex:91,ff,e6,b7,4e,cc,10,49,a1,5b,0b,7f,4a,6e,e4,b0,99,12,01,d8,17,..

 

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA40000001Jf40]

"khjeh"=hex:d3,13,5a,fb,98,3c,5c,5b,56,d0,6c,6d,e8,f4,4f,5c,46,69,c9,97,fb,..

 

scanning hidden registry entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 0

 

 

Remaining Services:

------------------

 

 

 

Authorized Application Key Export:

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

 

Remaining Files:

---------------

 

 

Files with Hidden Attributes:

 

Wed 31 May 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"

 

Finished!

 

 

 

 

Syns jeg har spammet nokk med rapporter no :blush:

Men du skal ha stor takk for all hjelpen du har gitt meg mr.Norbat :!:

 

Hvis du legger loggene dine mellom spoiler-tagger, så får du dem slik jeg har gjort med din logg over (i skjul). Ingen kommer til å beskylde deg for spamming av rapporter.

 

Vil anta problemet ditt med 'MSN-viruset' er borte.

Problemet du evt. har nå er at det kan ligge en rootkit på PC-en din. Verken combofix eller sdfix sier noe klart fra om dette, men loggen viser en fil som virker suspekt.

 

Isteden for å slette fila vcannlmg.sys, kan du forandre filnavnet til f.eks. vcannlmg.sys.vir

Mulig du må gjøre dette fra sikker modus.

Jeg ønsker å se en ny combofix-logg etter at du har gjort dette, men skal ikke tvinge deg. :)

Lenke til kommentar

Ny combofix Rapport:

 

 

ComboFix 08-01-11.3 - Eldar Godø 2008-01-12 20:28:47.3 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.779 [GMT 1:00]

Running from: C:\Documents and Settings\Eldar Godø\Desktop\ComboFix.exe

.

 

((((((((((((((((((((((((( Files Created from 2007-12-12 to 2008-01-12 )))))))))))))))))))))))))))))))

.

 

2008-01-12 18:43 . 2008-01-12 18:43 <DIR> d-------- C:\WINDOWS\ERUNT

2008-01-12 03:19 . 2008-01-12 03:19 1,159 --a------ C:\zia02540

2008-01-12 03:12 . 2008-01-12 03:12 60,416 --a------ C:\WINDOWS\system32\drivers\vcannlmg.sys.vir

2008-01-12 02:38 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe

2008-01-12 02:34 . 2008-01-12 03:12 <DIR> d-------- C:\Program Files\Avenger

2008-01-12 01:52 . 2008-01-12 01:52 <DIR> d-------- C:\Program Files\Opera

2008-01-11 22:45 . 2008-01-11 22:46 <DIR> d-------- C:\Program Files\Crimson Editor

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-01-12 19:28 --------- d-----w C:\Program Files\Trillian

2008-01-12 02:15 202 ----a-w C:\Program Files\lmktpuyv.txt

2008-01-11 20:58 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys

2008-01-11 20:58 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys

2008-01-11 20:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft

2008-01-11 20:57 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe

2007-11-30 15:25 --------- d-----w C:\Documents and Settings\Eldar Godø\Application Data\Ventrilo

2007-11-14 16:43 --------- d-----w C:\Program Files\Ventrilo

2007-11-14 16:43 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard

2007-03-02 00:25 21,822,168 ----a-w C:\Program Files\AdbeRdr80_en_US.exe

2007-03-02 00:19 7,050,552 ----a-w C:\Program Files\psa30se_en_us.exe

.

 

((((((((((((((((((((((((((((( snapshot@2008-01-12_ 2.43.15.10 )))))))))))))))))))))))))))))))))))))))))

.

- 2008-01-12 01:42:05 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT

+ 2008-01-12 16:38:45 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT

- 2008-01-12 01:42:05 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat

+ 2008-01-12 16:38:45 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat

- 2008-01-12 01:42:05 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT

+ 2008-01-12 16:38:45 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT

- 2008-01-12 01:42:05 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat

+ 2008-01-12 16:38:45 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat

- 2008-01-12 01:42:05 6,238,208 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT

+ 2008-01-12 16:38:46 6,238,208 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT

- 2008-01-12 01:42:05 102,400 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat

+ 2008-01-12 16:38:46 102,400 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat

+ 2008-01-12 08:21:54 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE

+ 2008-01-12 17:43:44 6,238,208 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT

+ 2008-01-12 17:43:44 102,400 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat

+ 2008-01-12 08:21:54 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE

+ 2008-01-12 17:43:33 6,238,208 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT

+ 2008-01-12 17:43:33 102,400 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-05-30 12:52 868352]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SoundMan"="SOUNDMAN.EXE" [2004-01-08 19:54 65536 C:\WINDOWS\SOUNDMAN.EXE]

"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-12-12 10:31 335872]

"EM_EXEC"="C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [2001-09-19 08:41 35328]

"MULTIMEDIA KEYBOARD"="C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe" [2002-06-12 22:50 167936]

"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 12:03 36975]

"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2006-09-22 17:59 921600]

"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [ ]

"Launch LGDCore"="C:\Program Files\Logitech\G-series Software\LGDCore.exe" [2006-03-06 16:31 1122304]

"Launch LCDMon"="C:\Program Files\Logitech\G-series Software\LCDMon.exe" [2006-03-06 16:14 497152]

"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24 286720]

"dieayepa"="C:\gexfsth^.bat" [ ]

"jlxmaswg"="C:\bqeixjyd.bat" [ ]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 02:07 15360]

 

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\

Wireless Config.lnk - C:\Program Files\Wireless Technology Corporation\Wireless LAN 802.11b USB\ZDConfig.exe [2006-09-22 17:51:37]

 

R1 ewido security suite driver;ewido security suite driver;C:\Program Files\ewido anti-malware\guard.sys [2005-12-30 12:12]

R1 msikbd2k;Multimedia Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys [2001-12-20 08:02]

R2 nhksrv;Netropa NHK Server;C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe [2001-08-06 05:41]

R3 ZD1201U(ZyDAS);ZyDAS ZD1201 IEEE 802.11b Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1201u.sys [2003-07-31 16:41]

R3 ZDNDIS5;ZDNDIS5 Protocol Driver;C:\WINDOWS\system32\ZDNDIS5.SYS [2002-10-30 10:43]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]

\Shell\AutoRun\command - G:\LaunchU3.exe -a

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{92bb3f4d-c08e-11dc-82a9-000e8e000fc2}]

\Shell\AutoRun\command - G:\LaunchU3.exe -a

 

.

Contents of the 'Scheduled Tasks' folder

"2008-01-12 04:02:50 C:\WINDOWS\Tasks\Se etter oppdateringer for Windows Live Toolbar.job"

- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE

.

**************************************************************************

 

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-01-12 20:30:03

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2008-01-12 20:30:23

ComboFix2.txt 2008-01-12 16:40:03

ComboFix3.txt 2008-01-12 01:43:30

.

2007-07-11 15:48:16 --- E O F ---

 

 

Lenke til kommentar
Ny combofix Rapport:

 

 

ComboFix 08-01-11.3 - Eldar Godø 2008-01-12 20:28:47.3 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.779 [GMT 1:00]

Running from: C:\Documents and Settings\Eldar Godø\Desktop\ComboFix.exe

.

 

((((((((((((((((((((((((( Files Created from 2007-12-12 to 2008-01-12 )))))))))))))))))))))))))))))))

.

 

2008-01-12 18:43 . 2008-01-12 18:43 <DIR> d-------- C:\WINDOWS\ERUNT

2008-01-12 03:19 . 2008-01-12 03:19 1,159 --a------ C:\zia02540

2008-01-12 03:12 . 2008-01-12 03:12 60,416 --a------ C:\WINDOWS\system32\drivers\vcannlmg.sys.vir

2008-01-12 02:38 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe

2008-01-12 02:34 . 2008-01-12 03:12 <DIR> d-------- C:\Program Files\Avenger

2008-01-12 01:52 . 2008-01-12 01:52 <DIR> d-------- C:\Program Files\Opera

2008-01-11 22:45 . 2008-01-11 22:46 <DIR> d-------- C:\Program Files\Crimson Editor

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-01-12 19:28 --------- d-----w C:\Program Files\Trillian

2008-01-12 02:15 202 ----a-w C:\Program Files\lmktpuyv.txt

2008-01-11 20:58 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys

2008-01-11 20:58 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys

2008-01-11 20:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft

2008-01-11 20:57 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe

2007-11-30 15:25 --------- d-----w C:\Documents and Settings\Eldar Godø\Application Data\Ventrilo

2007-11-14 16:43 --------- d-----w C:\Program Files\Ventrilo

2007-11-14 16:43 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard

2007-03-02 00:25 21,822,168 ----a-w C:\Program Files\AdbeRdr80_en_US.exe

2007-03-02 00:19 7,050,552 ----a-w C:\Program Files\psa30se_en_us.exe

.

 

((((((((((((((((((((((((((((( snapshot@2008-01-12_ 2.43.15.10 )))))))))))))))))))))))))))))))))))))))))

.

- 2008-01-12 01:42:05 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT

+ 2008-01-12 16:38:45 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT

- 2008-01-12 01:42:05 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat

+ 2008-01-12 16:38:45 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat

- 2008-01-12 01:42:05 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT

+ 2008-01-12 16:38:45 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT

- 2008-01-12 01:42:05 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat

+ 2008-01-12 16:38:45 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat

- 2008-01-12 01:42:05 6,238,208 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT

+ 2008-01-12 16:38:46 6,238,208 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT

- 2008-01-12 01:42:05 102,400 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat

+ 2008-01-12 16:38:46 102,400 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat

+ 2008-01-12 08:21:54 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE

+ 2008-01-12 17:43:44 6,238,208 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT

+ 2008-01-12 17:43:44 102,400 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat

+ 2008-01-12 08:21:54 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE

+ 2008-01-12 17:43:33 6,238,208 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT

+ 2008-01-12 17:43:33 102,400 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-05-30 12:52 868352]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SoundMan"="SOUNDMAN.EXE" [2004-01-08 19:54 65536 C:\WINDOWS\SOUNDMAN.EXE]

"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-12-12 10:31 335872]

"EM_EXEC"="C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [2001-09-19 08:41 35328]

"MULTIMEDIA KEYBOARD"="C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe" [2002-06-12 22:50 167936]

"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 12:03 36975]

"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2006-09-22 17:59 921600]

"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [ ]

"Launch LGDCore"="C:\Program Files\Logitech\G-series Software\LGDCore.exe" [2006-03-06 16:31 1122304]

"Launch LCDMon"="C:\Program Files\Logitech\G-series Software\LCDMon.exe" [2006-03-06 16:14 497152]

"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24 286720]

"dieayepa"="C:\gexfsth^.bat" [ ]

"jlxmaswg"="C:\bqeixjyd.bat" [ ]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 02:07 15360]

 

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\

Wireless Config.lnk - C:\Program Files\Wireless Technology Corporation\Wireless LAN 802.11b USB\ZDConfig.exe [2006-09-22 17:51:37]

 

R1 ewido security suite driver;ewido security suite driver;C:\Program Files\ewido anti-malware\guard.sys [2005-12-30 12:12]

R1 msikbd2k;Multimedia Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys [2001-12-20 08:02]

R2 nhksrv;Netropa NHK Server;C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe [2001-08-06 05:41]

R3 ZD1201U(ZyDAS);ZyDAS ZD1201 IEEE 802.11b Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1201u.sys [2003-07-31 16:41]

R3 ZDNDIS5;ZDNDIS5 Protocol Driver;C:\WINDOWS\system32\ZDNDIS5.SYS [2002-10-30 10:43]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]

\Shell\AutoRun\command - G:\LaunchU3.exe -a

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{92bb3f4d-c08e-11dc-82a9-000e8e000fc2}]

\Shell\AutoRun\command - G:\LaunchU3.exe -a

 

.

Contents of the 'Scheduled Tasks' folder

"2008-01-12 04:02:50 C:\WINDOWS\Tasks\Se etter oppdateringer for Windows Live Toolbar.job"

- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE

.

**************************************************************************

 

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-01-12 20:30:03

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2008-01-12 20:30:23

ComboFix2.txt 2008-01-12 16:40:03

ComboFix3.txt 2008-01-12 01:43:30

.

2007-07-11 15:48:16 --- E O F ---

 

 

Åpne notisblokk og kopier inn det som står i fet skrift under, lagre fila på skrivebordet som CFScript.txt.

Dra deretter fila over Combofix-iconet. Combofix vil starte igjen.

Registry::

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"dieayepa"=-

"jlxmaswg"=-

 

Kunne godt ha tenkt meg og sett en hjt-logg

Last ned Hijackthis. Legg det i en egen mappe på skrivebordet.

Start programmet, velg "Do a system scan and save a logfile". Loggfilen kopierer du og poster.

 

 

eeeh..

jeg er ikke helt med :S Jeg fikk dette viruset, og jeg har kjørt Combofix.

Så .. til slutt kommer det opp en lang logg. Med masse rare greier!! (det kommer opp i "notisblokk")

men skal jeg bare krysse den ut? er viruset borte nå??

 

Du kopierer loggen og limer den inn i en ny tråd som du oppretter ved å klikk på Nytt emne-knappen.

Dette gjør at du får en egen tråd da denne begynner å bli lang og uoversiktelig :)

Lenke til kommentar

Combofix Logg:

 

ComboFix 08-01-11.3 - Eldar Godø 2008-01-12 23:22:03.4 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.736 [GMT 1:00]

Running from: C:\Documents and Settings\Eldar Godø\Desktop\ComboFix.exe

Command switches used :: C:\Documents and Settings\Eldar Godø\Desktop\CFScript.txt

* Created a new restore point

.

 

((((((((((((((((((((((((( Files Created from 2007-12-12 to 2008-01-12 )))))))))))))))))))))))))))))))

.

 

2008-01-12 18:43 . 2008-01-12 18:43 <DIR> d-------- C:\WINDOWS\ERUNT

2008-01-12 03:19 . 2008-01-12 03:19 1,159 --a------ C:\zia02540

2008-01-12 03:12 . 2008-01-12 03:12 60,416 --a------ C:\WINDOWS\system32\drivers\vcannlmg.sys.vir

2008-01-12 02:38 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe

2008-01-12 02:34 . 2008-01-12 03:12 <DIR> d-------- C:\Program Files\Avenger

2008-01-12 01:52 . 2008-01-12 01:52 <DIR> d-------- C:\Program Files\Opera

2008-01-11 22:45 . 2008-01-11 22:46 <DIR> d-------- C:\Program Files\Crimson Editor

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-01-12 19:28 --------- d-----w C:\Program Files\Trillian

2008-01-12 02:15 202 ----a-w C:\Program Files\lmktpuyv.txt

2008-01-11 20:58 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys

2008-01-11 20:58 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys

2008-01-11 20:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft

2008-01-11 20:57 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe

2007-11-30 15:25 --------- d-----w C:\Documents and Settings\Eldar Godø\Application Data\Ventrilo

2007-11-14 16:43 --------- d-----w C:\Program Files\Ventrilo

2007-11-14 16:43 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard

2007-03-02 00:25 21,822,168 ----a-w C:\Program Files\AdbeRdr80_en_US.exe

2007-03-02 00:19 7,050,552 ----a-w C:\Program Files\psa30se_en_us.exe

.

 

((((((((((((((((((((((((((((( snapshot@2008-01-12_ 2.43.15.10 )))))))))))))))))))))))))))))))))))))))))

.

- 2008-01-12 01:42:05 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT

+ 2008-01-12 22:21:58 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT

- 2008-01-12 01:42:05 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat

+ 2008-01-12 22:21:58 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat

- 2008-01-12 01:42:05 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT

+ 2008-01-12 22:21:58 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT

- 2008-01-12 01:42:05 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat

+ 2008-01-12 22:21:58 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat

- 2008-01-12 01:42:05 6,238,208 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT

+ 2008-01-12 22:21:59 6,238,208 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT

- 2008-01-12 01:42:05 102,400 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat

+ 2008-01-12 22:21:59 102,400 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat

+ 2008-01-12 08:21:54 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE

+ 2008-01-12 17:43:44 6,238,208 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT

+ 2008-01-12 17:43:44 102,400 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat

+ 2008-01-12 08:21:54 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE

+ 2008-01-12 17:43:33 6,238,208 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT

+ 2008-01-12 17:43:33 102,400 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-05-30 12:52 868352]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SoundMan"="SOUNDMAN.EXE" [2004-01-08 19:54 65536 C:\WINDOWS\SOUNDMAN.EXE]

"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-12-12 10:31 335872]

"EM_EXEC"="C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [2001-09-19 08:41 35328]

"MULTIMEDIA KEYBOARD"="C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe" [2002-06-12 22:50 167936]

"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 12:03 36975]

"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2006-09-22 17:59 921600]

"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [ ]

"Launch LGDCore"="C:\Program Files\Logitech\G-series Software\LGDCore.exe" [2006-03-06 16:31 1122304]

"Launch LCDMon"="C:\Program Files\Logitech\G-series Software\LCDMon.exe" [2006-03-06 16:14 497152]

"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24 286720]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 02:07 15360]

 

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\

Wireless Config.lnk - C:\Program Files\Wireless Technology Corporation\Wireless LAN 802.11b USB\ZDConfig.exe [2006-09-22 17:51:37]

 

R1 ewido security suite driver;ewido security suite driver;C:\Program Files\ewido anti-malware\guard.sys [2005-12-30 12:12]

R1 msikbd2k;Multimedia Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys [2001-12-20 08:02]

R2 nhksrv;Netropa NHK Server;C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe [2001-08-06 05:41]

R3 ZD1201U(ZyDAS);ZyDAS ZD1201 IEEE 802.11b Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1201u.sys [2003-07-31 16:41]

R3 ZDNDIS5;ZDNDIS5 Protocol Driver;C:\WINDOWS\system32\ZDNDIS5.SYS [2002-10-30 10:43]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]

\Shell\AutoRun\command - G:\LaunchU3.exe -a

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{92bb3f4d-c08e-11dc-82a9-000e8e000fc2}]

\Shell\AutoRun\command - G:\LaunchU3.exe -a

 

.

Contents of the 'Scheduled Tasks' folder

"2008-01-12 04:02:50 C:\WINDOWS\Tasks\Se etter oppdateringer for Windows Live Toolbar.job"

- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE

.

**************************************************************************

 

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-01-12 23:22:43

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2008-01-12 23:23:03

ComboFix2.txt 2008-01-12 19:30:24

ComboFix3.txt 2008-01-12 16:40:03

ComboFix4.txt 2008-01-12 01:43:30

.

2007-07-11 15:48:16 --- E O F ---

 

 

 

 

Hijackthis Log:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 23:25:24, on 12.01.2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe

C:\WINDOWS\system32\CTsvcCDA.exe

C:\Program Files\ewido anti-malware\ewidoctrl.exe

C:\Program Files\Eset\nod32krn.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\WgaTray.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe

C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

C:\Program Files\Eset\nod32kui.exe

C:\Program Files\Logitech\G-series Software\LGDCore.exe

C:\Program Files\Logitech\G-series Software\LCDMon.exe

C:\Program Files\Logitech\G-series Software\Applets\LCDPop3\LCDPOP3.exe

C:\Program Files\Wireless Technology Corporation\Wireless LAN 802.11b USB\ZDConfig.exe

C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe

C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe

C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe

C:\Program Files\Netropa\Onscreen Display\OSD.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\notepad.exe

C:\Program Files\Opera\Opera.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.no/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.no/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.msn.no/

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.no/

R3 - URLSearchHook: (no name) - {13B31289-804F-ACBD-3353-8F6A67DC8AC9} - C:\WINDOWS\system32\irxfqs.dll (file missing)

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE

O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"

O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE

O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Wireless Config.lnk = C:\Program Files\Wireless Technology Corporation\Wireless LAN 802.11b USB\ZDConfig.exe

O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Åpne i ny bakgrunnsflik - res://C:\Program Files\Windows Live Toolbar\Components\nb-no\msntabres.dll.mui/229?a2847d79ac724ab9ace267d3287e2053

O8 - Extra context menu item: Åpne i ny forgrunnsflik - res://C:\Program Files\Windows Live Toolbar\Components\nb-no\msntabres.dll.mui/230?a2847d79ac724ab9ace267d3287e2053

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)

O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O14 - IERESET.INF: START_PAGE_URL=http://www.online.no/

O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1162

O22 - SharedTaskScheduler: AutoDisc Ware - {e04408db-4812-4478-8d4d-e46edcffd3b6} - (no file)

O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe

O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe

O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe

O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe

O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe

O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

 

--

End of file - 7431 bytes

 

 

Lenke til kommentar
Kjører du XP, kan du prøve følgende:

 

Hent Avenger og pakk det ut.

 

Start programmet, sett prikk i "Input Script Manually" og klikk på lupen.

I vinduet som kommer opp kopierer du og limer inn det som er i fet skrift under:

 

Files to delete:

C:\WINDOWS\lssas.exe

C:\WINDOWS\ntmngr.exe

C:\445930.exe

C:\WINDOWS\images.zip

Klikk på Trafikklyset. Restart PC-en.

Etter restart vil det komme en loggfil som forteller hva som har skjedd. Post loggen.

 

Det kan hende at noen av filene ikke finnes.

 

Deretter henter du Combofix, og legg det på skrivebordet

 

Kjør combofix.exe, og følg veiledningen.

Du må ikke klikke på vinduet mens programmet kjører.

 

Post loggfilen fra combofix. (vanligvis c:\combofix.txt)

 

Tusen takk "norbat"

Denne oppskriften hjalp meg :thumbup:

Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
×
×
  • Opprett ny...