Jeg kan ikke hente Avenger her fra tråden. Jeg bliver smidt helt af og må åbne forum igen.
Den alternative udgave jeg har fået pr. mail kan jeg godt gemme, men jeg kan ikke køre den. Jeg får lige et hurtigt glimt af næste vindue med Avenger, men ikke nok til at jeg kan nå at aktivere vinduet, før så er det væk igen.
Jeg kan stadig ikke køre Hijackthis. Her er det det samme problem som tidligere. Lige et hurtigt glimt og så er vinduet væk igen.
Hvorimod Silentrunners virker, og her er loggen/noten derfra :
“Silent Runners.vbs”, revision 49, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by “{++}”
Startup items buried in registry:
————————————————-
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
“MSMSGS” = ““C:\Programmer\Messenger\msmsgs.exe” /background” [MS]
“JewelQuestSetup.exe” = “C:\DOWNLO~1\JEWELQ~1.EXE /r” [file not found]
“ctfmon.exe” = “C:\WINDOWS\system32\ctfmon.exe” [MS]
“ErrorSafe” = ““C:\Programmer\Error Safe Free\ers.exe” /scan” [file not found]
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
“SunJavaUpdateSched” = “C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe” [“Sun Microsystems, Inc.”]
“hpsysdrv” = “c:\windows\system\hpsysdrv.exe” [“Hewlett-Packard Company”]
“Genvej til egenskabsside for High Definition Audio” = “HDAudPropShortcut.exe” [“Windows (R) Server 2003 DDK provider”]
“HPHUPD06” = “c:\Programmer\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe” [“Hewlett-Packard”]
“HPHmon06” = “C:\WINDOWS\system32\hphmon06.exe” [“Hewlett-Packard”]
“KBD” = “C:\HP\KBD\KBD.EXE” [“Hewlett-Packard Company”]
“Home Theater SchSvr” = ““C:\Programmer\Fælles filer\InterVideo\SchSvr\SchSvr.exe”” [“InterVideo Inc.”]
“WINREMOTE” = “C:\Programmer\InterVideo\Common\Bin\WinRemote.exe” [“InterVideo Inc.”]
“Recguard” = “C:\WINDOWS\SMINST\RECGUARD.EXE” [empty string]
“PS2” = “C:\WINDOWS\system32\ps2.exe” [“Hewlett-Packard Company”]
“ATIPTA” = “C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe” [“ATI Technologies, Inc.”]
“SoundMan” = “SOUNDMAN.EXE” [“Realtek Semiconductor Corp.”]
“AlcWzrd” = “ALCWZRD.EXE” [“RealTek Semicoductor Corp.”]
“Alcmtr” = “ALCMTR.EXE” [“Realtek Semiconductor Corp.”]
“LSBWatcher” = “c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe” [“Hewlett-Packard Company”]
“EPSON Stylus CX3200” = “C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 “EPSON Stylus CX3200” /O6 “USB001” /M “Stylus CX3200”” [“SEIKO EPSON CORPORATION”]
“BluetoothAuthenticationAgent” = “rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent” [MS]
“Notification Utility” = ““C:\Programmer\Notify\notify.exe ” /silent” [file not found]
“SweetIM” = “C:\Programmer\Macrogaming\SweetIM\SweetIM.exe” [“MacroGaming LTD.”]
“iTunesHelper” = ““C:\Programmer\iTunes\iTunesHelper.exe”” [“Apple Computer, Inc.”]
“QuickTime Task” = ““C:\Programmer\QuickTime\qttask.exe” -atboottime” [“Apple Computer, Inc.”]
“!AVG Anti-Spyware” = ““C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” /minimized” [“Anti-Malware Development a.s.”]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
-> {HKLM…CLSID} = “AcroIEHlprObj Class”
\InProcServer32\(Default) = “C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll” [“Adobe Systems Incorporated”]
{2D68F875-ADCC-F2BC-A67A-75F6948BD923}\(Default) = (no title provided)
-> {HKLM…CLSID} = “Class”
\InProcServer32\(Default) = “C:\WINDOWS\fitia1.dll” [file not found]
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
“{42071714-76d4-11d1-8b24-00a0c9068ff3}” = “Kontrolpanel-udvidelse til skærmpanorering”
-> {HKLM…CLSID} = “Kontrolpanel-udvidelse til skærmpanorering”
\InProcServer32\(Default) = “deskpan.dll” [file not found]
“{88895560-9AA2-1069-930E-00AA0030EBC8}” = “HyperTerminal-ikon”
-> {HKLM…CLSID} = “HyperTerminal Icon Ext”
\InProcServer32\(Default) = “C:\WINDOWS\system32\hticons.dll” [“Hilgraeve, Inc.”]
“{cc86590a-b60a-48e6-996b-41d25ed39a1e}” = “Portable Media Devices Menu”
-> {HKLM…CLSID} = “Portable Media Devices Menu”
\InProcServer32\(Default) = “C:\WINDOWS\system32\Audiodev.dll” [MS]
“{7F67036B-66F1-411A-AD85-759FB9C5B0DB}” = “SampleView”
-> {HKLM…CLSID} = “SampleView”
\InProcServer32\(Default) = “C:\WINDOWS\system32\ShellvRTF.dll” [“XSS”]
“{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}” = “iTunes”
-> {HKLM…CLSID} = “iTunes”
\InProcServer32\(Default) = “C:\Programmer\iTunes\iTunesMiniPlayer.dll” [“Apple Computer, Inc.”]
“{00020D75-0000-0000-C000-000000000046}” = “Microsoft Office Outlook Desktop Icon Handler”
-> {HKLM…CLSID} = “Microsoft Office Outlook”
\InProcServer32\(Default) = “C:\PROGRA~1\MICROS~3\OFFICE11\MLSHEXT.DLL” [MS]
“{0006F045-0000-0000-C000-000000000046}” = “Microsoft Office Outlook Custom Icon Handler”
-> {HKLM…CLSID} = “Filtypenavn for Outlook-filikon”
\InProcServer32\(Default) = “C:\PROGRA~1\MICROS~3\OFFICE11\OLKFSTUB.DLL” [MS]
“{42042206-2D85-11D3-8CFF-005004838597}” = “Microsoft Office HTML Icon Handler”
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = “C:\Programmer\Microsoft Office\OFFICE11\msohev.dll” [MS]
“{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}” = “Messenger Sharing Folders”
-> {HKLM…CLSID} = “Mine delemapper”
\InProcServer32\(Default) = “C:\Programmer\MSN Messenger\fsshext.8.0.0812.00.dll” [MS]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
<<!>> “{57B86673-276A-48B2-BAE7-C6DBB3020EB8}” = “AVG Anti-Spyware 7.5”
-> {HKLM…CLSID} = “CShellExecuteHookImpl Object”
\InProcServer32\(Default) = “C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll” [“Anti-Malware Development a.s.”]
<<!>> “{54D9498B-CF93-414F-8984-8CE7FDE0D391}” = “ewido shell guard”
-> {HKLM…CLSID} = “CShellExecuteHookImpl Object”
\InProcServer32\(Default) = “C:\Documents and Settings\HP_Ejer\Skrivebord\Spywarefri\security suite\shellhook.dll” [“TODO: <Firmenname>”]
<<!>> “{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}” = (no title provided)
-> {HKLM…CLSID} = “SABShellExecuteHook Class”
\InProcServer32\(Default) = “C:\Programmer\SUPERAntiSpyware\SASSEH.DLL” [“SuperAdBlocker.com”]
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\
<<!>> “AppInit_DLLs” = “\\?\C:\WINDOWS\system32\com5.sit” [file not found]
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\
<<!>> “Userinit” = “c:\windows\system32\userinit.exe,“c:\windows\compaqsensor.exe”,” [MS], [null data]
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
<<!>> AtiExtEvent\DLLName = “Ati2evxx.dll” [“ATI Technologies Inc.”]
<<!>> SASWinLogon\DLLName = “C:\Programmer\SUPERAntiSpyware\SASWINLO.dll” [“SUPERAntiSpyware.com”]
HKLM\Software\Classes\PROTOCOLS\Filter\
<<!>> text/xml\CLSID = “{807553E5-5146-11D5-A672-00B0D022E945}”
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = “C:\Programmer\Fælles filer\Microsoft Shared\OFFICE11\MSOXMLMF.DLL” [MS]
HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = “PDF Column Info”
-> {HKLM…CLSID} = “PDF Shell Extension”
\InProcServer32\(Default) = “C:\Programmer\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll” [“Adobe Systems, Inc.”]
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
AVG Anti-Spyware\(Default) = “{8934FCEF-F5B8-468f-951F-78A921CD3920}”
-> {HKLM…CLSID} = “CContextScan Object”
\InProcServer32\(Default) = “C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\context.dll” [“Anti-Malware Development a.s.”]
ewido\(Default) = “{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}”
-> {HKLM…CLSID} = “Ctest Object”
\InProcServer32\(Default) = “C:\Documents and Settings\HP_Ejer\Skrivebord\Spywarefri\security suite\context.dll” [“ewido networks”]
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
AVG Anti-Spyware\(Default) = “{8934FCEF-F5B8-468f-951F-78A921CD3920}”
-> {HKLM…CLSID} = “CContextScan Object”
\InProcServer32\(Default) = “C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\context.dll” [“Anti-Malware Development a.s.”]
ewido\(Default) = “{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}”
-> {HKLM…CLSID} = “Ctest Object”
\InProcServer32\(Default) = “C:\Documents and Settings\HP_Ejer\Skrivebord\Spywarefri\security suite\context.dll” [“ewido networks”]
Default executables:
——————————
HKCU\Software\Classes\.bat\(Default) = (value not set)
HKCU\Software\Classes\.cmd\(Default) = (value not set)
HKCU\Software\Classes\.com\(Default) = (value not set)
HKCU\Software\Classes\.exe\(Default) = (value not set)
HKCU\Software\Classes\.hta\(Default) = (value not set)
Group Policies {policy setting}:
————————————————
Note: detected settings may not have any effect.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
“NoCDBurning” = (REG_DWORD) hex:0x00000000
{unrecognized setting}
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\
“DisableRegistryTools” = (REG_DWORD) hex:0x00000000
{Prevent access to registry editing tools}
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\
“shutdownwithoutlogon” = (REG_DWORD) hex:0x00000001
{Shutdown: Allow system to be shut down without having to log on}
“undockwithoutlogon” = (REG_DWORD) hex:0x00000001
{Devices: Allow undock without having to log on}
Active Desktop and Wallpaper:
——————————————-
Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
“Wallpaper” = “C:\WINDOWS\system32\config\systemprofile\Lokale indstillinger\Application Data\Microsoft\Wallpaper1.bmp”
Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
“Wallpaper” = “C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Wallpaper1.bmp”
Enabled Screen Saver:
——————————-
HKCU\Control Panel\Desktop\
“SCRNSAVE.EXE” = “C:\WINDOWS\system32\logon.scr” [MS]
Startup items in “HP_Ejer” & “All Users” startup folders:
————————————————————————————-
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start
“Adobe Reader Hurtigstart” -> shortcut to: “C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe” [“Adobe Systems Incorporated”]
“HP Digital Imaging Monitor” -> shortcut to: “C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe” [“Hewlett-Packard Co.”]
Enabled Scheduled Tasks:
————————————
“Symantec NetDetect” -> launches: “C:\Programmer\Symantec\LiveUpdate\NDETECT.EXE” [“Symantec Corporation”]
Winsock2 Service Provider DLLs:
———————————————-
Namespace Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS]
000000000002\LibraryPath = “%SystemRoot%\System32\winrnr.dll” [MS]
000000000003\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS]
000000000004\LibraryPath = “%SystemRoot%\system32\wshbth.dll” [MS]
Transport Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 20
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05
Toolbars, Explorer Bars, Extensions:
——————————————————
Toolbars
HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
“{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}”
-> {HKLM…CLSID} = “HP-visning”
\InProcServer32\(Default) = “c:\Programmer\HP\Digital Imaging\bin\HPDTLK02.dll” [“Hewlett-Packard Company”]
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
“{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}”
-> {HKLM…CLSID} = “HP-visning”
\InProcServer32\(Default) = “c:\Programmer\HP\Digital Imaging\bin\HPDTLK02.dll” [“Hewlett-Packard Company”]
HKLM\Software\Microsoft\Internet Explorer\Toolbar\
“{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}” = (no title provided)
-> {HKLM…CLSID} = “HP-visning”
\InProcServer32\(Default) = “c:\Programmer\HP\Digital Imaging\bin\HPDTLK02.dll” [“Hewlett-Packard Company”]
Explorer Bars
HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\
HKLM\Software\Classes\CLSID\{1E0DE227-5CE4-4EA3-AB0C-8B03E1AA76BC}\(Default) = “My Web Search Quick View”
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = “C:\WINDOWS\system32\shdocvw.dll” [MS]
HKLM\Software\Classes\CLSID\{22B8FE23-7824-FEC2-590C-B31BDC5DE9A0}\(Default) = “JavaScript console”
Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
InProcServer32\(Default) = “C:\WINDOWS\fitia1.dll” [file not found]
HKLM\Software\Classes\CLSID\{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}\(Default) = “HP-visning”
Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
InProcServer32\(Default) = “c:\Programmer\HP\Digital Imaging\bin\HPDTLK02.dll” [“Hewlett-Packard Company”]
HKLM\Software\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = “&Opslag;”
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = “C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL” [MS]
Extensions (Tools menu items, main toolbar menu buttons)
HKCU\Software\Microsoft\Internet Explorer\Extensions\
{E2D4D26B-0180-43A4-B05F-462D6D54C789}\
“ButtonText” = “Tilslutningshjælp”
“MenuText” = “Tilslutningshjælp”
“Script” = “C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm” [null data]
HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
“MenuText” = “Sun Java Console”
“CLSIDExtension” = “{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}”
-> {HKCU…CLSID} = “Java Plug-in”
\InProcServer32\(Default) = “C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll” [null data]
-> {HKLM…CLSID} = “Java Plug-in 1.5.0_06”
\InProcServer32\(Default) = “C:\Programmer\Java\jre1.5.0_06\bin\npjpi150_06.dll” [“Sun Microsystems, Inc.”]
{92780B25-18CC-41C8-B9BE-3C9C571A8263}\
“ButtonText” = “Opslag”
{E2D4D26B-0180-43A4-B05F-462D6D54C789}\
“ButtonText” = “Tilslutningshjælp”
“MenuText” = “Tilslutningshjælp”
“Script” = “C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm” [null data]
{FB5F1910-F110-11D2-BB9E-00C04F795683}\
“ButtonText” = “Messenger”
“MenuText” = “Windows Messenger”
“Exec” = “C:\Programmer\Messenger\msmsgs.exe” [MS]
Miscellaneous IE Hijack Points
———————————————
C:\WINDOWS\INF\IERESET.INF (used to “Reset Web Settings”)
Added lines (compared with English-language version):
[Strings]: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Missing lines (compared with English-language version):
[Strings]: 1 line
Running Services (Display Name, Service Name, Path {Service DLL}):
—————————————————————————————————
Ati HotKey Poller, Ati HotKey Poller, “C:\WINDOWS\system32\Ati2evxx.exe” [“ATI Technologies Inc.”]
AVG Anti-Spyware Guard, AVG Anti-Spyware Guard, “C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe” [“Anti-Malware Development a.s.”]
Bluetooth Support Service, BthServ, “C:\WINDOWS\system32\svchost.exe -k bthsvcs” {“C:\WINDOWS\System32\bthserv.dll” [MS]}
EPSON Printer Status Agent2, EPSONStatusAgent2, “C:\Programmer\Fælles filer\EPSON\EBAPI\SAgent2.exe” [“SEIKO EPSON CORPORATION”]
EpsonBidirectionalService, EpsonBidirectionalService, “C:\Programmer\Fælles filer\EPSON\EBAPI\eEBSVC.exe” [null data]
ewido security suite control, ewido security suite control, “C:\Documents and Settings\HP_Ejer\Skrivebord\Spywarefri\security suite\ewidoctrl.exe” [“ewido networks”]
iPodService, iPodService, “C:\Programmer\iPod\bin\iPodService.exe” [“Apple Computer, Inc.”]
LightScribeService Direct Disc Labeling Service, LightScribeService, ““c:\Programmer\Fælles filer\LightScribe\LSSrvc.exe”” [“Hewlett-Packard Company”]
Pml Driver HPZ12, Pml Driver HPZ12, “C:\WINDOWS\system32\HPZipm12.exe” [“HP”]
Windows User Mode Driver Framework, UMWdf, “C:\WINDOWS\system32\wdfmgr.exe” [MS]
Print Monitors:
———————-
HKLM\System\CurrentControlSet\Control\Print\Monitors\
EPSON V5 2KMonitor\Driver = “EBPMON2.DLL” [“SEIKO EPSON CORPORATION”]
Microsoft Document Imaging Writer Monitor\Driver = “mdimon.dll” [MS]
Microsoft Shared Fax Monitor\Driver = “FXSMON.DLL” [MS]
—————
<<!>>: Suspicious data at a malware launch point.
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
DLL launch points, use the -supp parameter or answer “No” at the
first message box and “Yes” at the second message box.
—————(total run time: 27 seconds, including 2 seconds for message boxes)