AVG Anti-spyware 7.5
  d124mic
Antal indlæg: 62

Her er resultatet af Gromozon Rootkit Removal scanningen. (Men PC var ikke unormalt længe om at genstarte.)

Removal tool loaded into memory
Gromozon rootkit component not detected - searching for other components
Scanning: C:\WINDOWS
Scanning: C:\Programmer\Fælles filer


Trojan.Gromozon does not exist - your system is clean.

  Ejvindh
Redaktør
Avatar
Antal indlæg: 6158

Prøv lige at følge punkt (2) og (3) også.

  d124mic
Antal indlæg: 62

Punkt nr. 2 virker ikke. jeg bliver smidt helt ud af forum/tråden og må åbne påny.

men punkt 3 giver følgende resultat :

regf                                                                                                                                                                                                                                                                                                                                           Pugf                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     hbin                   ¨ÿÿÿnk, üýçÆ  ÿÿÿÿ      ÿÿÿÿÿÿÿÿ  ø  x   ÿÿÿÿ      0   B       Windows ÿÿÿsk x   x     Ô  €¸  È        ¤            !    €      !  ?                      ?                                        Øÿÿÿvk B       fùAppInit_DLLsÖæG¸ÿÿÿ\ \ ? \ C : \ WINDOW S \ s y s t e m 3 2 \ c o m 5 . s i t   m   h Ðÿÿÿvk       ÀUDeviceNotSelectedTimeoutðÿÿÿ1 5   ±#”£ðÿÿÿ9 0   |. Ðÿÿÿvk   €’    zGDIProcessHandleQuota”þàÿÿÿvk   €    °ºSpooler2ðÿÿÿy e s   ¨I   h à  0 `  ¨  àÿÿÿvk   €      swapdiskÐÿÿÿvk       ÏTransmissionRetryTimeoutàÿÿÿh à  0 `  ¨  È  Ðÿÿÿvk   €’      USERProcessHandleQuota ¸

  d124mic
Antal indlæg: 62

Nå - så lykkedes punkt 2 alligevel, jeg må have gjort noget fejl.

catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

  Ejvindh
Redaktør
Avatar
Antal indlæg: 6158

Det ser godt nok ud til at rootkittet er væk. Men prøv lige følgende:

—Hent Avenger her:
http://swandog46.geekstogo.com/avenger.zip

I tilfælde af at du ikke kan få lov at hente dette program, eller ikke kan få lov til at køre det, sender jeg dig en email med en alternativ udgave, på en alternativ adresse. Vi vil helst ikke have denne udgave ud i offentligheden, da Gromozon-folkene holder øje med dette værktøj. Du må gerne skrive i tråden hvilken version du bruger.

—Pak Avenger-programmet ud og dobbeltklik på avenger.exe

—Sæt en prik i “Input Script Manually” og klik på Luppen - nu dukker der et lille vindue op, hvor du skal kopiere indholdet mellem de stiplede linier ind:

——————————————-
Files to delete:
C:\WINDOWS\system32\com5.sit

Registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs
——————————————-

—Klik på Trafiklyset i Avenger. Programmet vil opfordre dig til at genstarte computeren straks, hvilket du skal gøre. Programmet vil lukke din computer, slette filerne og starte computeren igen.

—Efter genstarten vil der dukke et notepad-vindue op, med en log for Avengers handlinger. Den må du gerne lægge ind i dit næste svar.

—Prøv også om du kan lave en log med Hijackthis nu.

—Hvis ikke du kan bruge Hijackthis, så prøv SilentRunners:
Hent Silentrunners her:
http://www.silentrunners.org/Silent Runners.vbs

Kør programmet, klik på Ja. Klik på OK. Vent så indtil der kommer en besked om at logfilen er færdig. Find log-filen, og læg den herind (den lægger sig i samme mappe som silentrunner programmet ligger i).

  d124mic
Antal indlæg: 62

Jeg kan ikke hente Avenger her fra tråden. Jeg bliver smidt helt af og må åbne forum igen.
Den alternative udgave jeg har fået pr. mail kan jeg godt gemme, men jeg kan ikke køre den. Jeg får lige et hurtigt glimt af næste vindue med Avenger, men ikke nok til at jeg kan nå at aktivere vinduet, før så er det væk igen.
Jeg kan stadig ikke køre Hijackthis. Her er det det samme problem som tidligere. Lige et hurtigt glimt og så er vinduet væk igen.
Hvorimod Silentrunners virker, og her er loggen/noten derfra :

“Silent Runners.vbs”, revision 49, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by “{++}”


Startup items buried in registry:
————————————————-

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
“MSMSGS” = ““C:\Programmer\Messenger\msmsgs.exe” /background” [MS]
“JewelQuestSetup.exe” = “C:\DOWNLO~1\JEWELQ~1.EXE /r” [file not found]
“ctfmon.exe” = “C:\WINDOWS\system32\ctfmon.exe” [MS]
“ErrorSafe” = ““C:\Programmer\Error Safe Free\ers.exe” /scan” [file not found]

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
“SunJavaUpdateSched” = “C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe” [“Sun Microsystems, Inc.”]
“hpsysdrv” = “c:\windows\system\hpsysdrv.exe” [“Hewlett-Packard Company”]
“Genvej til egenskabsside for High Definition Audio” = “HDAudPropShortcut.exe” [“Windows (R) Server 2003 DDK provider”]
“HPHUPD06” = “c:\Programmer\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe” [“Hewlett-Packard”]
“HPHmon06” = “C:\WINDOWS\system32\hphmon06.exe” [“Hewlett-Packard”]
“KBD” = “C:\HP\KBD\KBD.EXE” [“Hewlett-Packard Company”]
“Home Theater SchSvr” = ““C:\Programmer\Fælles filer\InterVideo\SchSvr\SchSvr.exe”” [“InterVideo Inc.”]
“WINREMOTE” = “C:\Programmer\InterVideo\Common\Bin\WinRemote.exe” [“InterVideo Inc.”]
“Recguard” = “C:\WINDOWS\SMINST\RECGUARD.EXE” [empty string]
“PS2” = “C:\WINDOWS\system32\ps2.exe” [“Hewlett-Packard Company”]
“ATIPTA” = “C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe” [“ATI Technologies, Inc.”]
“SoundMan” = “SOUNDMAN.EXE” [“Realtek Semiconductor Corp.”]
“AlcWzrd” = “ALCWZRD.EXE” [“RealTek Semicoductor Corp.”]
“Alcmtr” = “ALCMTR.EXE” [“Realtek Semiconductor Corp.”]
“LSBWatcher” = “c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe” [“Hewlett-Packard Company”]
“EPSON Stylus CX3200” = “C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 “EPSON Stylus CX3200” /O6 “USB001” /M “Stylus CX3200”” [“SEIKO EPSON CORPORATION”]
“BluetoothAuthenticationAgent” = “rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent” [MS]
“Notification Utility” = ““C:\Programmer\Notify\notify.exe ” /silent” [file not found]
“SweetIM” = “C:\Programmer\Macrogaming\SweetIM\SweetIM.exe” [“MacroGaming LTD.”]
“iTunesHelper” = ““C:\Programmer\iTunes\iTunesHelper.exe”” [“Apple Computer, Inc.”]
“QuickTime Task” = ““C:\Programmer\QuickTime\qttask.exe” -atboottime” [“Apple Computer, Inc.”]
“!AVG Anti-Spyware” = ““C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” /minimized” [“Anti-Malware Development a.s.”]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
  -> {HKLM…CLSID} = “AcroIEHlprObj Class”
            \InProcServer32\(Default) = “C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll” [“Adobe Systems Incorporated”]
{2D68F875-ADCC-F2BC-A67A-75F6948BD923}\(Default) = (no title provided)
  -> {HKLM…CLSID} = “Class”
            \InProcServer32\(Default) = “C:\WINDOWS\fitia1.dll” [file not found]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
“{42071714-76d4-11d1-8b24-00a0c9068ff3}” = “Kontrolpanel-udvidelse til skærmpanorering”
  -> {HKLM…CLSID} = “Kontrolpanel-udvidelse til skærmpanorering”
            \InProcServer32\(Default) = “deskpan.dll” [file not found]
“{88895560-9AA2-1069-930E-00AA0030EBC8}” = “HyperTerminal-ikon”
  -> {HKLM…CLSID} = “HyperTerminal Icon Ext”
            \InProcServer32\(Default) = “C:\WINDOWS\system32\hticons.dll” [“Hilgraeve, Inc.”]
“{cc86590a-b60a-48e6-996b-41d25ed39a1e}” = “Portable Media Devices Menu”
  -> {HKLM…CLSID} = “Portable Media Devices Menu”
            \InProcServer32\(Default) = “C:\WINDOWS\system32\Audiodev.dll” [MS]
“{7F67036B-66F1-411A-AD85-759FB9C5B0DB}” = “SampleView”
  -> {HKLM…CLSID} = “SampleView”
            \InProcServer32\(Default) = “C:\WINDOWS\system32\ShellvRTF.dll” [“XSS”]
“{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}” = “iTunes”
  -> {HKLM…CLSID} = “iTunes”
            \InProcServer32\(Default) = “C:\Programmer\iTunes\iTunesMiniPlayer.dll” [“Apple Computer, Inc.”]
“{00020D75-0000-0000-C000-000000000046}” = “Microsoft Office Outlook Desktop Icon Handler”
  -> {HKLM…CLSID} = “Microsoft Office Outlook”
            \InProcServer32\(Default) = “C:\PROGRA~1\MICROS~3\OFFICE11\MLSHEXT.DLL” [MS]
“{0006F045-0000-0000-C000-000000000046}” = “Microsoft Office Outlook Custom Icon Handler”
  -> {HKLM…CLSID} = “Filtypenavn for Outlook-filikon”
            \InProcServer32\(Default) = “C:\PROGRA~1\MICROS~3\OFFICE11\OLKFSTUB.DLL” [MS]
“{42042206-2D85-11D3-8CFF-005004838597}” = “Microsoft Office HTML Icon Handler”
  -> {HKLM…CLSID} = (no title provided)
            \InProcServer32\(Default) = “C:\Programmer\Microsoft Office\OFFICE11\msohev.dll” [MS]
“{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}” = “Messenger Sharing Folders”
  -> {HKLM…CLSID} = “Mine delemapper”
            \InProcServer32\(Default) = “C:\Programmer\MSN Messenger\fsshext.8.0.0812.00.dll” [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
<<!>> “{57B86673-276A-48B2-BAE7-C6DBB3020EB8}” = “AVG Anti-Spyware 7.5”
  -> {HKLM…CLSID} = “CShellExecuteHookImpl Object”
            \InProcServer32\(Default) = “C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll” [“Anti-Malware Development a.s.”]
<<!>> “{54D9498B-CF93-414F-8984-8CE7FDE0D391}” = “ewido shell guard”
  -> {HKLM…CLSID} = “CShellExecuteHookImpl Object”
            \InProcServer32\(Default) = “C:\Documents and Settings\HP_Ejer\Skrivebord\Spywarefri\security suite\shellhook.dll” [“TODO: <Firmenname>”]
<<!>> “{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}” = (no title provided)
  -> {HKLM…CLSID} = “SABShellExecuteHook Class”
            \InProcServer32\(Default) = “C:\Programmer\SUPERAntiSpyware\SASSEH.DLL” [“SuperAdBlocker.com”]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\
<<!>> “AppInit_DLLs” = “\\?\C:\WINDOWS\system32\com5.sit” [file not found]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\
<<!>> “Userinit” = “c:\windows\system32\userinit.exe,“c:\windows\compaqsensor.exe”,” [MS], [null data]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
<<!>> AtiExtEvent\DLLName = “Ati2evxx.dll” [“ATI Technologies Inc.”]
<<!>> SASWinLogon\DLLName = “C:\Programmer\SUPERAntiSpyware\SASWINLO.dll” [“SUPERAntiSpyware.com”]

HKLM\Software\Classes\PROTOCOLS\Filter\
<<!>> text/xml\CLSID = “{807553E5-5146-11D5-A672-00B0D022E945}”
  -> {HKLM…CLSID} = (no title provided)
            \InProcServer32\(Default) = “C:\Programmer\Fælles filer\Microsoft Shared\OFFICE11\MSOXMLMF.DLL” [MS]

HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = “PDF Column Info”
  -> {HKLM…CLSID} = “PDF Shell Extension”
            \InProcServer32\(Default) = “C:\Programmer\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll” [“Adobe Systems, Inc.”]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
AVG Anti-Spyware\(Default) = “{8934FCEF-F5B8-468f-951F-78A921CD3920}”
  -> {HKLM…CLSID} = “CContextScan Object”
            \InProcServer32\(Default) = “C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\context.dll” [“Anti-Malware Development a.s.”]
ewido\(Default) = “{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}”
  -> {HKLM…CLSID} = “Ctest Object”
            \InProcServer32\(Default) = “C:\Documents and Settings\HP_Ejer\Skrivebord\Spywarefri\security suite\context.dll” [“ewido networks”]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
AVG Anti-Spyware\(Default) = “{8934FCEF-F5B8-468f-951F-78A921CD3920}”
  -> {HKLM…CLSID} = “CContextScan Object”
            \InProcServer32\(Default) = “C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\context.dll” [“Anti-Malware Development a.s.”]
ewido\(Default) = “{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}”
  -> {HKLM…CLSID} = “Ctest Object”
            \InProcServer32\(Default) = “C:\Documents and Settings\HP_Ejer\Skrivebord\Spywarefri\security suite\context.dll” [“ewido networks”]


Default executables:
——————————

HKCU\Software\Classes\.bat\(Default) = (value not set)

HKCU\Software\Classes\.cmd\(Default) = (value not set)

HKCU\Software\Classes\.com\(Default) = (value not set)

HKCU\Software\Classes\.exe\(Default) = (value not set)

HKCU\Software\Classes\.hta\(Default) = (value not set)


Group Policies {policy setting}:
————————————————

Note: detected settings may not have any effect.

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\

“NoCDBurning” = (REG_DWORD) hex:0x00000000
{unrecognized setting}

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\

“DisableRegistryTools” = (REG_DWORD) hex:0x00000000
{Prevent access to registry editing tools}

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

“shutdownwithoutlogon” = (REG_DWORD) hex:0x00000001
{Shutdown: Allow system to be shut down without having to log on}

“undockwithoutlogon” = (REG_DWORD) hex:0x00000001
{Devices: Allow undock without having to log on}


Active Desktop and Wallpaper:
——————————————-

Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
“Wallpaper” = “C:\WINDOWS\system32\config\systemprofile\Lokale indstillinger\Application Data\Microsoft\Wallpaper1.bmp”

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
“Wallpaper” = “C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Wallpaper1.bmp”


Enabled Screen Saver:
——————————-

HKCU\Control Panel\Desktop\
“SCRNSAVE.EXE” = “C:\WINDOWS\system32\logon.scr” [MS]


Startup items in “HP_Ejer” & “All Users” startup folders:
————————————————————————————-

C:\Documents and Settings\All Users\Menuen Start\Programmer\Start
“Adobe Reader Hurtigstart” -> shortcut to: “C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe” [“Adobe Systems Incorporated”]
“HP Digital Imaging Monitor” -> shortcut to: “C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe” [“Hewlett-Packard Co.”]


Enabled Scheduled Tasks:
————————————

“Symantec NetDetect” -> launches: “C:\Programmer\Symantec\LiveUpdate\NDETECT.EXE” [“Symantec Corporation”]


Winsock2 Service Provider DLLs:
———————————————-

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS]
000000000002\LibraryPath = “%SystemRoot%\System32\winrnr.dll” [MS]
000000000003\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS]
000000000004\LibraryPath = “%SystemRoot%\system32\wshbth.dll” [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 20
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
——————————————————

Toolbars

HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
“{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}”
  -> {HKLM…CLSID} = “HP-visning”
            \InProcServer32\(Default) = “c:\Programmer\HP\Digital Imaging\bin\HPDTLK02.dll” [“Hewlett-Packard Company”]

HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
“{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}”
  -> {HKLM…CLSID} = “HP-visning”
            \InProcServer32\(Default) = “c:\Programmer\HP\Digital Imaging\bin\HPDTLK02.dll” [“Hewlett-Packard Company”]

HKLM\Software\Microsoft\Internet Explorer\Toolbar\
“{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}” = (no title provided)
  -> {HKLM…CLSID} = “HP-visning”
            \InProcServer32\(Default) = “c:\Programmer\HP\Digital Imaging\bin\HPDTLK02.dll” [“Hewlett-Packard Company”]

Explorer Bars

HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\

HKLM\Software\Classes\CLSID\{1E0DE227-5CE4-4EA3-AB0C-8B03E1AA76BC}\(Default) = “My Web Search Quick View”
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = “C:\WINDOWS\system32\shdocvw.dll” [MS]

HKLM\Software\Classes\CLSID\{22B8FE23-7824-FEC2-590C-B31BDC5DE9A0}\(Default) = “JavaScript console”
Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
InProcServer32\(Default) = “C:\WINDOWS\fitia1.dll” [file not found]

HKLM\Software\Classes\CLSID\{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}\(Default) = “HP-visning”
Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
InProcServer32\(Default) = “c:\Programmer\HP\Digital Imaging\bin\HPDTLK02.dll” [“Hewlett-Packard Company”]

HKLM\Software\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = “&Opslag;”
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = “C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL” [MS]

Extensions (Tools menu items, main toolbar menu buttons)

HKCU\Software\Microsoft\Internet Explorer\Extensions\
{E2D4D26B-0180-43A4-B05F-462D6D54C789}\
“ButtonText” = “Tilslutningshjælp”
“MenuText” = “Tilslutningshjælp”
“Script” = “C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm” [null data]

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
“MenuText” = “Sun Java Console”
“CLSIDExtension” = “{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}”
  -> {HKCU…CLSID} = “Java Plug-in”
            \InProcServer32\(Default) = “C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll” [null data]
  -> {HKLM…CLSID} = “Java Plug-in 1.5.0_06”
            \InProcServer32\(Default) = “C:\Programmer\Java\jre1.5.0_06\bin\npjpi150_06.dll” [“Sun Microsystems, Inc.”]

{92780B25-18CC-41C8-B9BE-3C9C571A8263}\
“ButtonText” = “Opslag”

{E2D4D26B-0180-43A4-B05F-462D6D54C789}\
“ButtonText” = “Tilslutningshjælp”
“MenuText” = “Tilslutningshjælp”
“Script” = “C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm” [null data]

{FB5F1910-F110-11D2-BB9E-00C04F795683}\
“ButtonText” = “Messenger”
“MenuText” = “Windows Messenger”
“Exec” = “C:\Programmer\Messenger\msmsgs.exe” [MS]


Miscellaneous IE Hijack Points
———————————————

C:\WINDOWS\INF\IERESET.INF (used to “Reset Web Settings”)

Added lines (compared with English-language version):
[Strings]: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

Missing lines (compared with English-language version):
[Strings]: 1 line


Running Services (Display Name, Service Name, Path {Service DLL}):
—————————————————————————————————

Ati HotKey Poller, Ati HotKey Poller, “C:\WINDOWS\system32\Ati2evxx.exe” [“ATI Technologies Inc.”]
AVG Anti-Spyware Guard, AVG Anti-Spyware Guard, “C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe” [“Anti-Malware Development a.s.”]
Bluetooth Support Service, BthServ, “C:\WINDOWS\system32\svchost.exe -k bthsvcs” {“C:\WINDOWS\System32\bthserv.dll” [MS]}
EPSON Printer Status Agent2, EPSONStatusAgent2, “C:\Programmer\Fælles filer\EPSON\EBAPI\SAgent2.exe” [“SEIKO EPSON CORPORATION”]
EpsonBidirectionalService, EpsonBidirectionalService, “C:\Programmer\Fælles filer\EPSON\EBAPI\eEBSVC.exe” [null data]
ewido security suite control, ewido security suite control, “C:\Documents and Settings\HP_Ejer\Skrivebord\Spywarefri\security suite\ewidoctrl.exe” [“ewido networks”]
iPodService, iPodService, “C:\Programmer\iPod\bin\iPodService.exe” [“Apple Computer, Inc.”]
LightScribeService Direct Disc Labeling Service, LightScribeService, ““c:\Programmer\Fælles filer\LightScribe\LSSrvc.exe”” [“Hewlett-Packard Company”]
Pml Driver HPZ12, Pml Driver HPZ12, “C:\WINDOWS\system32\HPZipm12.exe” [“HP”]
Windows User Mode Driver Framework, UMWdf, “C:\WINDOWS\system32\wdfmgr.exe” [MS]


Print Monitors:
———————-

HKLM\System\CurrentControlSet\Control\Print\Monitors\
EPSON V5 2KMonitor\Driver = “EBPMON2.DLL” [“SEIKO EPSON CORPORATION”]
Microsoft Document Imaging Writer Monitor\Driver = “mdimon.dll” [MS]
Microsoft Shared Fax Monitor\Driver = “FXSMON.DLL” [MS]


—————
<<!>>: Suspicious data at a malware launch point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
  launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
  DLL launch points, use the -supp parameter or answer “No” at the
  first message box and “Yes” at the second message box.
—————(total run time: 27 seconds, including 2 seconds for message boxes)

Administrator
Avatar
Antal indlæg: 32085

Der er tegn på infektioner i Silentrunners loggen, men lige for at blive ved avenger, prøv om du kan køre avenger fra fejlsikret tilstand, for der er ingen net forbindelse.

Alternativt- højreklik på avenger exe (eller den udgave du har fået pr. mail) omdøb den til - slet exe eller slet com, se om de kan køre


Prøv også om du kan køre alternativ exe fra fejlsikret tilstand

Signatur

Sund Computer fornuft

  d124mic
Antal indlæg: 62

Det er desværre det samme også i fejlssikret tilstand. (svaret er for nemheds skyld kopieret og genbrugt fra 3/11)

Jeg kan ikke hente Avenger her fra tråden. Jeg bliver smidt helt af og må åbne forum igen.
Den alternative udgave jeg har fået pr. mail kan jeg godt gemme, men jeg kan ikke køre den. Jeg får lige et hurtigt glimt af næste vindue med Avenger, men ikke nok til at jeg kan nå at aktivere vinduet, før så er det væk igen.
Jeg kan stadig ikke køre Hijackthis. Her er det det samme problem som tidligere. Lige et hurtigt glimt og så er vinduet væk igen.

  Ejvindh
Redaktør
Avatar
Antal indlæg: 6158

—Omdøb den alternative version af Avenger, som det er lykkedes dig at hente til “test.exe” (hvis den ikke hedder det allerede). Sørg for at den ligger på skrivebordet.

—Kopiér indholdet mellem de stiplede linier ind i et notepad-vindue, og gem indholdet på skrivebordet som vbsregfix.vbs. Når du gemmer, skal du sikre, at der under “filtyper” står “alle filer”.

——————-

Dim Wshshellfso
 Set WshShell 
Wscript.CreateObject("Wscript.Shell"
 
Set fso CreateObject("Scripting.FileSystemObject"
 
On Error Resume Next
  WshShell
.RegDelete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ErrorSafe"
  
WshShell.RegDelete "HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Alcmtr"
  
WshShell.RegDelete "HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Notification Utility"
  
WshShell.RegDelete "HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SweetIM"
  
WshShell.RegDelete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools"
  
WshShell.RegDelete "HKCU\Software\Classes\.bat\"
  
WshShell.RegDelete "HKCU\Software\Classes\.cmd\"
  
WshShell.RegDelete "HKCU\Software\Classes\.com\"
  
WshShell.RegDelete "HKCU\Software\Classes\.exe\"
  
WshShell.RegDelete "HKCU\Software\Classes\.hta\"
  
WshShell.RegWrite "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit""c:\windows\system32\userinit.exe,""REG_SZ"

Dim d
 Set d 
fso.OpenTextFile("script.txt"2True)
  
d.WriteLine "Files to delete:" 
  
d.WriteLine "C:\WINDOWS\fitia1.dll"
  
d.WriteLine "C:\WINDOWS\system32\com5.sit"
  
d.WriteLine
  d
.WriteLine "Registry values to replace with dummy:"
  
d.WriteLine "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs"
  
d.Close
 
Return = WshShell.Run("test.exe /nogui /qq /s script.txt"1true

——————-

—Dobbeltklik så på den fil, som du lige har lavet. Hvis alt går vel, skulle computeren efter kort tid herefter gerne genstarte. Efter genstarten vil der dukke et notepad-vindue op, med en log for Avengers handlinger. Den må du gerne lægge ind i dit næste svar.

—Uanset hvad der sker, må du gerne lave en ny log med SilentRunners, som du lægger herind.

  d124mic
Antal indlæg: 62

Efter omdøbning af avenger, og kopiering af tekst ind i et Notesblok vindue. Dobbeltklikkede jeg på Notesblokken på skrivebordet. der skete tilsyneladende ingenting. Ingen genstart af PC, eller anden synlig aktivitet, men der kom et lille nyt Notesblok dokument (script) på skrivebordet. Indhold er som følgende :

Files to delete:
C:\WINDOWS\fitia1.dll
C:\WINDOWS\system32\com5.sit

Registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs

Derefter kørte jeg en ny SilentRunners med følgende resultat :

“Silent Runners.vbs”, revision 49, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by “{++}”


Startup items buried in registry:
————————————————-

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
“MSMSGS” = ““C:\Programmer\Messenger\msmsgs.exe” /background” [MS]
“JewelQuestSetup.exe” = “C:\DOWNLO~1\JEWELQ~1.EXE /r” [file not found]
“ctfmon.exe” = “C:\WINDOWS\system32\ctfmon.exe” [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
“SunJavaUpdateSched” = “C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe” [“Sun Microsystems, Inc.”]
“hpsysdrv” = “c:\windows\system\hpsysdrv.exe” [“Hewlett-Packard Company”]
“Genvej til egenskabsside for High Definition Audio” = “HDAudPropShortcut.exe” [“Windows (R) Server 2003 DDK provider”]
“HPHUPD06” = “c:\Programmer\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe” [“Hewlett-Packard”]
“HPHmon06” = “C:\WINDOWS\system32\hphmon06.exe” [“Hewlett-Packard”]
“KBD” = “C:\HP\KBD\KBD.EXE” [“Hewlett-Packard Company”]
“Home Theater SchSvr” = ““C:\Programmer\Fælles filer\InterVideo\SchSvr\SchSvr.exe”” [“InterVideo Inc.”]
“WINREMOTE” = “C:\Programmer\InterVideo\Common\Bin\WinRemote.exe” [“InterVideo Inc.”]
“Recguard” = “C:\WINDOWS\SMINST\RECGUARD.EXE” [empty string]
“PS2” = “C:\WINDOWS\system32\ps2.exe” [“Hewlett-Packard Company”]
“ATIPTA” = “C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe” [“ATI Technologies, Inc.”]
“SoundMan” = “SOUNDMAN.EXE” [“Realtek Semiconductor Corp.”]
“AlcWzrd” = “ALCWZRD.EXE” [“RealTek Semicoductor Corp.”]
“LSBWatcher” = “c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe” [“Hewlett-Packard Company”]
“EPSON Stylus CX3200” = “C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 “EPSON Stylus CX3200” /O6 “USB001” /M “Stylus CX3200”” [“SEIKO EPSON CORPORATION”]
“BluetoothAuthenticationAgent” = “rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent” [MS]
“iTunesHelper” = ““C:\Programmer\iTunes\iTunesHelper.exe”” [“Apple Computer, Inc.”]
“QuickTime Task” = ““C:\Programmer\QuickTime\qttask.exe” -atboottime” [“Apple Computer, Inc.”]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
  -> {HKLM…CLSID} = “AcroIEHlprObj Class”
            \InProcServer32\(Default) = “C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll” [“Adobe Systems Incorporated”]
{2D68F875-ADCC-F2BC-A67A-75F6948BD923}\(Default) = (no title provided)
  -> {HKLM…CLSID} = “Class”
            \InProcServer32\(Default) = “C:\WINDOWS\fitia1.dll” [file not found]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
“{42071714-76d4-11d1-8b24-00a0c9068ff3}” = “Kontrolpanel-udvidelse til skærmpanorering”
  -> {HKLM…CLSID} = “Kontrolpanel-udvidelse til skærmpanorering”
            \InProcServer32\(Default) = “deskpan.dll” [file not found]
“{88895560-9AA2-1069-930E-00AA0030EBC8}” = “HyperTerminal-ikon”
  -> {HKLM…CLSID} = “HyperTerminal Icon Ext”
            \InProcServer32\(Default) = “C:\WINDOWS\system32\hticons.dll” [“Hilgraeve, Inc.”]
“{cc86590a-b60a-48e6-996b-41d25ed39a1e}” = “Portable Media Devices Menu”
  -> {HKLM…CLSID} = “Portable Media Devices Menu”
            \InProcServer32\(Default) = “C:\WINDOWS\system32\Audiodev.dll” [MS]
“{7F67036B-66F1-411A-AD85-759FB9C5B0DB}” = “SampleView”
  -> {HKLM…CLSID} = “SampleView”
            \InProcServer32\(Default) = “C:\WINDOWS\system32\ShellvRTF.dll” [“XSS”]
“{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}” = “iTunes”
  -> {HKLM…CLSID} = “iTunes”
            \InProcServer32\(Default) = “C:\Programmer\iTunes\iTunesMiniPlayer.dll” [“Apple Computer, Inc.”]
“{00020D75-0000-0000-C000-000000000046}” = “Microsoft Office Outlook Desktop Icon Handler”
  -> {HKLM…CLSID} = “Microsoft Office Outlook”
            \InProcServer32\(Default) = “C:\PROGRA~1\MICROS~3\OFFICE11\MLSHEXT.DLL” [MS]
“{0006F045-0000-0000-C000-000000000046}” = “Microsoft Office Outlook Custom Icon Handler”
  -> {HKLM…CLSID} = “Filtypenavn for Outlook-filikon”
            \InProcServer32\(Default) = “C:\PROGRA~1\MICROS~3\OFFICE11\OLKFSTUB.DLL” [MS]
“{42042206-2D85-11D3-8CFF-005004838597}” = “Microsoft Office HTML Icon Handler”
  -> {HKLM…CLSID} = (no title provided)
            \InProcServer32\(Default) = “C:\Programmer\Microsoft Office\OFFICE11\msohev.dll” [MS]
“{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}” = “Messenger Sharing Folders”
  -> {HKLM…CLSID} = “Mine delemapper”
            \InProcServer32\(Default) = “C:\Programmer\MSN Messenger\fsshext.8.0.0812.00.dll” [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
<<!>> “{57B86673-276A-48B2-BAE7-C6DBB3020EB8}” = “AVG Anti-Spyware 7.5”
  -> {HKLM…CLSID} = “CShellExecuteHookImpl Object”
            \InProcServer32\(Default) = “C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll” [“Anti-Malware Development a.s.”]
<<!>> “{54D9498B-CF93-414F-8984-8CE7FDE0D391}” = “ewido shell guard”
  -> {HKLM…CLSID} = “CShellExecuteHookImpl Object”
            \InProcServer32\(Default) = “C:\Documents and Settings\HP_Ejer\Skrivebord\Spywarefri\security suite\shellhook.dll” [“TODO: <Firmenname>”]
<<!>> “{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}” = (no title provided)
  -> {HKLM…CLSID} = “SABShellExecuteHook Class”
            \InProcServer32\(Default) = “C:\Programmer\SUPERAntiSpyware\SASSEH.DLL” [“SuperAdBlocker.com”]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\
<<!>> “AppInit_DLLs” = “\\?\C:\WINDOWS\system32\com5.sit” [file not found]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\
<<!>> “Userinit” = “c:\windows\system32\userinit.exe,“c:\windows\compaqsensor.exe”,” [MS], [null data]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
<<!>> AtiExtEvent\DLLName = “Ati2evxx.dll” [“ATI Technologies Inc.”]
<<!>> SASWinLogon\DLLName = “C:\Programmer\SUPERAntiSpyware\SASWINLO.dll” [“SUPERAntiSpyware.com”]

HKLM\Software\Classes\PROTOCOLS\Filter\
<<!>> text/xml\CLSID = “{807553E5-5146-11D5-A672-00B0D022E945}”
  -> {HKLM…CLSID} = (no title provided)
            \InProcServer32\(Default) = “C:\Programmer\Fælles filer\Microsoft Shared\OFFICE11\MSOXMLMF.DLL” [MS]

HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = “PDF Column Info”
  -> {HKLM…CLSID} = “PDF Shell Extension”
            \InProcServer32\(Default) = “C:\Programmer\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll” [“Adobe Systems, Inc.”]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
AVG Anti-Spyware\(Default) = “{8934FCEF-F5B8-468f-951F-78A921CD3920}”
  -> {HKLM…CLSID} = “CContextScan Object”
            \InProcServer32\(Default) = “C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\context.dll” [“Anti-Malware Development a.s.”]
ewido\(Default) = “{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}”
  -> {HKLM…CLSID} = “Ctest Object”
            \InProcServer32\(Default) = “C:\Documents and Settings\HP_Ejer\Skrivebord\Spywarefri\security suite\context.dll” [“ewido networks”]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
AVG Anti-Spyware\(Default) = “{8934FCEF-F5B8-468f-951F-78A921CD3920}”
  -> {HKLM…CLSID} = “CContextScan Object”
            \InProcServer32\(Default) = “C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\context.dll” [“Anti-Malware Development a.s.”]
ewido\(Default) = “{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}”
  -> {HKLM…CLSID} = “Ctest Object”
            \InProcServer32\(Default) = “C:\Documents and Settings\HP_Ejer\Skrivebord\Spywarefri\security suite\context.dll” [“ewido networks”]


Group Policies {policy setting}:
————————————————

Note: detected settings may not have any effect.

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\

“NoCDBurning” = (REG_DWORD) hex:0x00000000
{unrecognized setting}

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

“shutdownwithoutlogon” = (REG_DWORD) hex:0x00000001
{Shutdown: Allow system to be shut down without having to log on}

“undockwithoutlogon” = (REG_DWORD) hex:0x00000001
{Devices: Allow undock without having to log on}


Active Desktop and Wallpaper:
——————————————-

Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
“Wallpaper” = “C:\WINDOWS\system32\config\systemprofile\Lokale indstillinger\Application Data\Microsoft\Wallpaper1.bmp”

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
“Wallpaper” = “C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Wallpaper1.bmp”


Enabled Screen Saver:
——————————-

HKCU\Control Panel\Desktop\
“SCRNSAVE.EXE” = “C:\WINDOWS\system32\logon.scr” [MS]


Startup items in “HP_Ejer” & “All Users” startup folders:
————————————————————————————-

C:\Documents and Settings\All Users\Menuen Start\Programmer\Start
“Adobe Reader Hurtigstart” -> shortcut to: “C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe” [“Adobe Systems Incorporated”]
“HP Digital Imaging Monitor” -> shortcut to: “C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe” [“Hewlett-Packard Co.”]


Enabled Scheduled Tasks:
————————————

“Symantec NetDetect” -> launches: “C:\Programmer\Symantec\LiveUpdate\NDETECT.EXE” [“Symantec Corporation”]


Winsock2 Service Provider DLLs:
———————————————-

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS]
000000000002\LibraryPath = “%SystemRoot%\System32\winrnr.dll” [MS]
000000000003\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS]
000000000004\LibraryPath = “%SystemRoot%\system32\wshbth.dll” [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 20
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
——————————————————

Toolbars

HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
“{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}”
  -> {HKLM…CLSID} = “HP-visning”
            \InProcServer32\(Default) = “c:\Programmer\HP\Digital Imaging\bin\HPDTLK02.dll” [“Hewlett-Packard Company”]

HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
“{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}”
  -> {HKLM…CLSID} = “HP-visning”
            \InProcServer32\(Default) = “c:\Programmer\HP\Digital Imaging\bin\HPDTLK02.dll” [“Hewlett-Packard Company”]

HKLM\Software\Microsoft\Internet Explorer\Toolbar\
“{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}” = (no title provided)
  -> {HKLM…CLSID} = “HP-visning”
            \InProcServer32\(Default) = “c:\Programmer\HP\Digital Imaging\bin\HPDTLK02.dll” [“Hewlett-Packard Company”]

Explorer Bars

HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\

HKLM\Software\Classes\CLSID\{1E0DE227-5CE4-4EA3-AB0C-8B03E1AA76BC}\(Default) = “My Web Search Quick View”
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = “C:\WINDOWS\system32\shdocvw.dll” [MS]

HKLM\Software\Classes\CLSID\{22B8FE23-7824-FEC2-590C-B31BDC5DE9A0}\(Default) = “JavaScript console”
Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
InProcServer32\(Default) = “C:\WINDOWS\fitia1.dll” [file not found]

HKLM\Software\Classes\CLSID\{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}\(Default) = “HP-visning”
Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
InProcServer32\(Default) = “c:\Programmer\HP\Digital Imaging\bin\HPDTLK02.dll” [“Hewlett-Packard Company”]

HKLM\Software\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = “&Opslag;”
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = “C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL” [MS]

Extensions (Tools menu items, main toolbar menu buttons)

HKCU\Software\Microsoft\Internet Explorer\Extensions\
{E2D4D26B-0180-43A4-B05F-462D6D54C789}\
“ButtonText” = “Tilslutningshjælp”
“MenuText” = “Tilslutningshjælp”
“Script” = “C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm” [null data]

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
“MenuText” = “Sun Java Console”
“CLSIDExtension” = “{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}”
  -> {HKCU…CLSID} = “Java Plug-in”
            \InProcServer32\(Default) = “C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll” [null data]
  -> {HKLM…CLSID} = “Java Plug-in 1.5.0_06”
            \InProcServer32\(Default) = “C:\Programmer\Java\jre1.5.0_06\bin\npjpi150_06.dll” [“Sun Microsystems, Inc.”]

{92780B25-18CC-41C8-B9BE-3C9C571A8263}\
“ButtonText” = “Opslag”

{E2D4D26B-0180-43A4-B05F-462D6D54C789}\
“ButtonText” = “Tilslutningshjælp”
“MenuText” = “Tilslutningshjælp”
“Script” = “C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm” [null data]

{FB5F1910-F110-11D2-BB9E-00C04F795683}\
“ButtonText” = “Messenger”
“MenuText” = “Windows Messenger”
“Exec” = “C:\Programmer\Messenger\msmsgs.exe” [MS]


Miscellaneous IE Hijack Points
———————————————

C:\WINDOWS\INF\IERESET.INF (used to “Reset Web Settings”)

Added lines (compared with English-language version):
[Strings]: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

Missing lines (compared with English-language version):
[Strings]: 1 line


Running Services (Display Name, Service Name, Path {Service DLL}):
—————————————————————————————————

Ati HotKey Poller, Ati HotKey Poller, “C:\WINDOWS\system32\Ati2evxx.exe” [“ATI Technologies Inc.”]
AVG Anti-Spyware Guard, AVG Anti-Spyware Guard, “C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe” [“Anti-Malware Development a.s.”]
Bluetooth Support Service, BthServ, “C:\WINDOWS\system32\svchost.exe -k bthsvcs” {“C:\WINDOWS\System32\bthserv.dll” [MS]}
EPSON Printer Status Agent2, EPSONStatusAgent2, “C:\Programmer\Fælles filer\EPSON\EBAPI\SAgent2.exe” [“SEIKO EPSON CORPORATION”]
EpsonBidirectionalService, EpsonBidirectionalService, “C:\Programmer\Fælles filer\EPSON\EBAPI\eEBSVC.exe” [null data]
ewido security suite control, ewido security suite control, “C:\Documents and Settings\HP_Ejer\Skrivebord\Spywarefri\security suite\ewidoctrl.exe” [“ewido networks”]
iPodService, iPodService, “C:\Programmer\iPod\bin\iPodService.exe” [“Apple Computer, Inc.”]
LightScribeService Direct Disc Labeling Service, LightScribeService, ““c:\Programmer\Fælles filer\LightScribe\LSSrvc.exe”” [“Hewlett-Packard Company”]
Læsetjeneste til USN-poster for deling i Messenger, usnsvc, “C:\WINDOWS\system32\svchost.exe -k usnsvc” {“C:\Programmer\MSN Messenger\usnsvc.dll” [MS]}
Pml Driver HPZ12, Pml Driver HPZ12, “C:\WINDOWS\system32\HPZipm12.exe” [“HP”]
Windows User Mode Driver Framework, UMWdf, “C:\WINDOWS\system32\wdfmgr.exe” [MS]


Print Monitors:
———————-

HKLM\System\CurrentControlSet\Control\Print\Monitors\
EPSON V5 2KMonitor\Driver = “EBPMON2.DLL” [“SEIKO EPSON CORPORATION”]
Microsoft Document Imaging Writer Monitor\Driver = “mdimon.dll” [MS]
Microsoft Shared Fax Monitor\Driver = “FXSMON.DLL” [MS]


—————
<<!>>: Suspicious data at a malware launch point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
  launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
  DLL launch points, use the -supp parameter or answer “No” at the
  first message box and “Yes” at the second message box.
—————(total run time: 31 seconds, including 6 seconds for message boxes)

 

  Ejvindh
Redaktør
Avatar
Antal indlæg: 6158

Der er nu ellers sket nogle fremskridt i SilentRunners loggen, men den sværeste rettelse mangler desværre stadigvæk.

(1) Jeg kunne godt tænke mig at vide om du efter en genstart stadig ikke kan køre Hijackthis og den omdøbte version af Avenger?

(2) Prøv om du kan få lov til at downloade og køre den store version af Gmer’s antirootkit-scanner. Download Gmer-rootkit scanner, og pak den ud til skrivebordet:
http://www.gmer.net/gmer.zip

Omdøb “Gmer.exe” til “omdøbt.exe”. Kør programmet, klik på fanebladet “Rootkit”, og klik på “Scan”. Når scanningen er færdig, skal du klikke på “Copy”. Så dukker et vindue op, som fortæller at resultatet af rootkit-scanningen er blevet lagt ind i udklipsholderen. Du kan herefter gå ind i denne tråd, og kopiere indholdet herind, ved at stille dig i indtastningsfeltet, og trykke ctrl-v.

  d124mic
Antal indlæg: 62

1 - jeg kan stadig ikke køre Hijackthis ( jeg har den ellers liggende under 3 originale/omdøbte navne, nemlig: danborg.org-spy-hj og hijackthis alternativ og slet com, men ingen af dem kan køres )og ej heller den på skrivebordet liggende til: test.exe, omdøbte Avenger.
Jeg får lige et kort glimt af næste vindue, men ikke nok til at jeg kan nå at aktivere vinduet før så er det væk igen.
2 - jeg kan heller ikke hverken åbne eller køre den store version af gmer iht. dit link.
Det er endnu længere væk end punkt 1. Jeg får lige et kort glimt af næste vindue, men ikke nok til at jeg kan nå at aktivere vinduet før så er det væk igen. Men her bliver jeg samtidig smidt helt af tråden og må åbne alt påny igen.

NB skal man have WinZip for at åbne gmer ??? jeg får på min anden PC et vindue om at købe winzip til $29. Og så skal jeg jo nok anskaffe den for at kunne åbne når/hvis det engang lykkedes at komme så langt her på denne PC også.

  Ejvindh
Redaktør
Avatar
Antal indlæg: 6158

NB skal man have WinZip for at åbne gmer ??? jeg får på min anden PC et vindue om at købe winzip til $29. Og så skal jeg jo nok anskaffe den for at kunne åbne når/hvis det engang lykkedes at komme så langt her på denne PC også.

Det skulle ikke være nødvendigt at købe Winzip. For det første kan man blive ved med at bruge trial-udgaven. For det andet burde den indbyggede zip-udpakker i XP også kunne gøre jobbet. Blot er det vigtigt at du faktisk udpakker programmet, og ikke bare prøver at køre den inde fra zip-filen. Du skal altså dobbeltklikke på zip-filen, og i det vindue som åbnes skal du ovre til venstre klikke på “Udpak alle filer”, og herefter følge instruksionerne, for at få filen pakket ud.

Prøv nu følgende:

(1)
Jeg har uploadet en udpakket og omdøbt version af Gmer-scanneren her:
http://uploads.ejvindh.net/xyz.exe

Prøv om du kan hente den, og køre den. Hvis ja, så følg instruksionerne fra forrige indlæg.

(2)
Du skal være logget ind med en bruger, der har administratorrettigheder.

Hent “System Virginity Verifier” herfra, og pak det ud til en selvstændig mappe på skrivebordet.
http://www.invisiblethings.org/tools/svv/svv-2.3-bin.zip

Kopiér indholdet mellem de stiplede linier, ind i et notepad-vindue, og gem indholdet i den mappe, hvor “System Virginity Verifier” ligger. Når du gemmer filen, skal du kalde den runssv.bat, og du skal sikre dig, at der under “Filtyper” står “Alle filer”:

——————
@echo off
echo yes|svv check /a /m>logit.txt
start logit.txt
——————
Dobbeltklik herefter på runssv.bat. Så vil et sort vindue dukke op, med teksten “Warming up…”. Efter lidt tid lukker dette vindue ned, og et notepad vindue dukker op med en logfil. Prøv at lægge denne fil herind.

(3)
Hent WinPfind2 herfra:
http://download.bleepingcomputer.com/oldtimer/winpfind2.exe

Dobbeltklik på filen, og klik på Extract, for at pakke programmet ud. Så dukker der en ny mappe op på skrivebordet, der hedder WinPfind2. Inde i denne mappe skal du klikke på Winpfind2.exe. Ovre til højre skal du markere “Policies.def”, Security.def”, “ShellState.def”.

Klik herefter på “Run all scans”. Så vil computeren blive scannet. Når der nederst til venstre står “Scans Complete!”, klikker du på “Simple report”, hvorefter der vil åbnes en logfil, som du skal lægge herind.

  d124mic
Antal indlæg: 62

nr.(1) virker ikke. Jeg får kun lige et glimt af næste vindue, men kan ikke nå at se og aktivere noget. Men der kom et nyt “billed” eller ikon hvis det hedder sådan, på skrivebordet. Det er en firkant med et gult og et grønt tandhjul på. ???

nr.(2) var bedre, filen blev som følgende:

Important module ntoskrnl.exe not found
WARNING: Veryfing integrity of ALL kernel modules may cause a SYSTEM CRASH!
Do you want to continue (yes/no)?
                                       
verifying module: [        svv.exe]  9%... -
verifying module: [        ntdll.dll] 18%... \
verifying module: [      kernel32.dll] 27%... |
verifying module: [        PSAPI.DLL] 36%... /
verifying module: [      WS2_32.dll] 45%... -
verifying module: [      msvcrt.dll] 54%... \
verifying module: [      WS2HELP.dll] 63%... |
verifying module: [      ADVAPI32.dll] 72%... /
verifying module: [      RPCRT4.dll] 81%... -
verifying module: [      USER32.dll] 90%... \
verifying module: [        GDI32.dll] 100%... |
                                       

SYSTEM INFECTION LEVEL: 0
—> 0 - BLUE
  1 - GREEN
  2 - YELLOW
  3 - ORANGE
  4 - RED
  5 - DEEPRED
Nothing suspected was detected.

nr.(3) filen blev som følgende :

Logfile created on: 13-11-2006 23:28:23
WinPFind2 by OldTimer - Version 1.0.14 Folder = C:\Documents and Settings\HP_Ejer\Skrivebord\WinPFind2\
Microsoft Windows XP Service Pack 2 (Version = 5.1.2600)
Internet Explorer (Version = 6.0.2900.2180)


< Processes (Non-Microsoft Only) >
c:\windows\alcwzrd.exe - (RealTek Semicoductor Corp. )
c:\windows\system32\ati2evxx.exe - (ATI Technologies Inc. )
c:\windows\system32\ati2evxx.exe - (ATI Technologies Inc. )
c:\programmer\ati technologies\ati control panel\atiptaxx.exe - (ATI Technologies, Inc. )
c:\windows\compaqsensor.exe - ( )
c:\windows\system32\spool\drivers\w32x86\3\e_s10ic2.exe - (SEIKO EPSON CORPORATION )
c:\programmer\fælles filer\epson\ebapi\eebsvc.exe - ( )
c:\documents and settings\hp_ejer\skrivebord\spywarefri\security suite\ewidoctrl.exe - (ewido networks )
c:\programmer\grisoft\avg anti-spyware 7.5\guard.exe - (Anti-Malware Development a.s. )
c:\windows\system32\hphmon06.exe - (Hewlett-Packard )
c:\programmer\hp\digital imaging\bin\hpqtra08.exe - (Hewlett-Packard Co. )
c:\windows\system\hpsysdrv.exe - (Hewlett-Packard Company )
c:\windows\system32\hpzipm12.exe - (HP )
c:\programmer\ipod\bin\ipodservice.exe - (Apple Computer, Inc. )
c:\programmer\itunes\ituneshelper.exe - (Apple Computer, Inc. )
c:\programmer\java\jre1.5.0_06\bin\jusched.exe - (Sun Microsystems, Inc. )
c:\hp\kbd\kbd.exe - (Hewlett-Packard Company )
c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe - (Hewlett-Packard Company )
c:\programmer\fælles filer\lightscribe\lssrvc.exe - (Hewlett-Packard Company )
c:\programmer\quicktime\qttask.exe - (Apple Computer, Inc. )
c:\programmer\fælles filer\epson\ebapi\sagent2.exe - (SEIKO EPSON CORPORATION )
c:\programmer\fælles filer\intervideo\schsvr\schsvr.exe - (InterVideo Inc. )
c:\windows\soundman.exe - (Realtek Semiconductor Corp. )
c:\documents and settings\hp_ejer\skrivebord\winpfind2\winpfind2.exe - (OldTimer Tools )
c:\programmer\intervideo\common\bin\winremote.exe - (InterVideo Inc. )

< Registry Entries >

[>> Internet Explorer Settings <<]
HKLM->Main\\Start Page - http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid;={SUB_CLSID}&pver;={SUB_PVER}&ar=home
HKLM->Main\\Search Bar - http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=Q305&bd=pavilion&pf=desktop
HKLM->Main\\Search Page - http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM->Main\\Default_Page_URL - http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKLM->Main\\Default_Search_URL - http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM->Main\\Local Page - %SystemRoot%\system32\blank.htm
HKCU->Main\\Start Page - http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKCU->Main\\Search Bar - http://g.msn.dk/0SEDADK/SAOS01?FORM=TOOLBR
HKCU->Main\\Search Page - http://g.msn.dk/0SEDADK/SAOS01?FORM=TOOLBR
HKCU->Main\\Default_Search_URL - http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=Q305&bd=pavilion&pf=desktop
HKCU->Main\\Local Page - C:\WINDOWS\system32\blank.htm
HKLM->Search\\CustomizeSearch - http://ie.search.msn.com/da/srchasst/srchcust.htm
HKLM->Search\\SearchAssistant - http://ie.search.msn.com/da-dk/srchasst/srchasst.htm
HKCU->URLSearchHooks\\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Microsoft Url Search Hook = %SystemRoot%\system32\shdocvw.dll (Microsoft Corporation )
HKCU->Internet Settings\\ProxyEnable - 1

[>> BHO’s <<]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class = C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated )
{2D68F875-ADCC-F2BC-A67A-75F6948BD923} - Class = C:\WINDOWS\fitia1.dll (File not found)
{BDF3E430-B101-42AD-A544-FADC6B084872} - Reg Data - Key not found = Reg Data - Key not found (File not found)

[>> Internet Explorer Bars, Toolbars and Extensions <<]

[HKLM-> Internet Explorer Bars]
{4D5C8C25-D075-11d0-B416-00C04FB90376} - Dagens &tip; = %SystemRoot%\system32\shdocvw.dll (Microsoft Corporation )

[HKCU-> Internet Explorer Bars]
{30D02401-6A81-11D0-8274-00C04FD5AE38} - Search Band = %SystemRoot%\system32\browseui.dll (Microsoft Corporation )
{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1} - File Search Explorer Band = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
{EFA24E61-B078-11D0-89E4-00C04FC9E26E} - Favorites Band = %SystemRoot%\system32\shdocvw.dll (Microsoft Corporation )
{EFA24E64-B078-11D0-89E4-00C04FC9E26E} - Explorer Band = %SystemRoot%\system32\shdocvw.dll (Microsoft Corporation )

[HKLM-> Internet Explorer ToolBars]
- Reg Data - Value does not exist = Reg Data - Key not found (File not found)
{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - HP-visning = c:\Programmer\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company )

[HKCU-> Internet Explorer ToolBars]
ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Data - Key not found = Reg Data - Key not found (File not found)
ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Data - Key not found = Reg Data - Key not found (File not found)
ShellBrowser\\{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - HP-visning = c:\Programmer\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company )
WebBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383} - &Adresse; = %SystemRoot%\system32\browseui.dll (Microsoft Corporation )
WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383} - &Hyperlinks; = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Data - Key not found = Reg Data - Key not found (File not found)
WebBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Data - Key not found = Reg Data - Key not found (File not found)
WebBrowser\\{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - HP-visning = c:\Programmer\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company )
WebBrowser\\{BC4FFE41-DE9F-46FA-B455-AAD49B9F9938} - Reg Data - Key not found = Reg Data - Key not found (File not found)
WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} - &Yahoo;! Toolbar = Reg Data - Key not found (File not found)

[HKCU-> Internet Explorer CmdMapping]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - 8193 - Sun Java Console
{92780B25-18CC-41C8-B9BE-3C9C571A8263} - 8195 - Reg Data - Value does not exist
{E2D4D26B-0180-43a4-B05F-462D6D54C789} - 8192 - Tilslutningshjælp
{FB5F1910-F110-11d2-BB9E-00C04F795683} - 8194 - Windows Messenger
NextId - 8198

[HKLM-> Internet Explorer Extensions]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - MenuText: Sun Java Console = C:\Programmer\Java\jre1.5.0_06\bin\npjpi150_06.dll (Sun Microsystems, Inc. )
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} (HKCU CLSID) - MenuText: Sun Java Console = C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll ( )
{92780B25-18CC-41C8-B9BE-3C9C571A8263} - ButtonText: Opslag = Reg Data - Value does not exist (File not found)
{E2D4D26B-0180-43a4-B05F-462D6D54C789} - ButtonText: Tilslutningshjælp = C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ( )
{FB5F1910-F110-11d2-BB9E-00C04F795683} - ButtonText: Messenger = C:\Programmer\Messenger\msmsgs.exe (Microsoft Corporation )

[HKCU-> Internet Explorer Menu Extensions]
&Google;-søgning - res://c:\programmer\google\GoogleToolbar1.dll/cmsearch.html (Google Inc. )
&Overs;æt engelsk ord - res://c:\programmer\google\GoogleToolbar1.dll/cmwordtrans.html (Google Inc. )
&Search; - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZSzed055YYDK_ZCxdm490YYDK (File not found)
E&ksporter; til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation )
Lignende sider - res://c:\programmer\google\GoogleToolbar1.dll/cmsimilar.html (Google Inc. )
Tilbage via links - res://c:\programmer\google\GoogleToolbar1.dll/cmbacklinks.html (Google Inc. )
Øjebliksbillede af side i cache - res://c:\programmer\google\GoogleToolbar1.dll/cmcache.html (Google Inc. )

[HKLM-> Internet Explorer Plugins]
.spop - Reg Data - Value does not exist = C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll (Intertrust Technologies, Inc. )

[>> Approved Shell Extensions (Non-Microsoft only) <<]

[HKLM-> Approved Shell Extensions]
{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} - Autoplay for SlideShow = Reg Data - Key not found (File not found)
{0DF44EAA-FF21-4412-828E-260A8728E7F1} - Proceslinje og menuen Start = Reg Data - Key not found (File not found)
{42071714-76d4-11d1-8b24-00a0c9068ff3} - Kontrolpanel-udvidelse til skærmpanorering = deskpan.dll (File not found)
{764BF0E1-F219-11ce-972D-00AA00A14F56} - Grænsefladeudvidelser til filkomprimering = Reg Data - Key not found (File not found)
{7A9D77BD-5403-11d2-8785-2E0420524153} - Brugerkonti = Reg Data - Key not found (File not found)
{7F67036B-66F1-411A-AD85-759FB9C5B0DB} - SampleView = C:\WINDOWS\system32\ShellvRTF.dll (XSS )
{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} - Kontekstmenu til kryptering = Reg Data - Key not found (File not found)
{88895560-9AA2-1069-930E-00AA0030EBC8} - HyperTerminal-ikon = C:\WINDOWS\system32\hticons.dll (Hilgraeve, Inc. )
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} - iTunes = C:\Programmer\iTunes\iTunesMiniPlayer.dll (Apple Computer, Inc. )

[>> ContextMenuHandlers (Non-Microsoft only) <<]

[HKLM-> ContextMenuHandlers]
* - AVG Anti-Spyware - {8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\context.dll (Anti-Malware Development a.s. )
* - ewido - {57BD36D7-CE32-4600-9B1C-1A0C47EFC02E} = C:\Documents and Settings\HP_Ejer\Skrivebord\Spywarefri\security suite\context.dll (ewido networks )
Directory - AVG Anti-Spyware - {8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\context.dll (Anti-Malware Development a.s. )
Directory - ewido - {57BD36D7-CE32-4600-9B1C-1A0C47EFC02E} = C:\Documents and Settings\HP_Ejer\Skrivebord\Spywarefri\security suite\context.dll (ewido networks )

[>> ColumnHandlers (Non-Microsoft only) <<]

[HKLM-> ColumnHandlers]
Folder - {F9DB5320-233E-11D1-9F84-707F02C10627} - PDF Shell Extension = C:\Programmer\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll (Adobe Systems, Inc. )

[>> File Associations Keys <<]
HKLM->SOFTWARE\Classes\.bat\\’’ - batfile
HKLM->SOFTWARE\Classes\batfile\shell\open\command\\’’ - “%1” %*
HKLM->SOFTWARE\Classes\.cmd\\’’ - cmdfile
HKLM->SOFTWARE\Classes\cmdfile\shell\open\command\\’’ - “%1” %*
HKLM->SOFTWARE\Classes\.com\\’’ - comfile
HKLM->SOFTWARE\Classes\comfile\shell\open\command\\’’ - “%1” %*
HKLM->SOFTWARE\Classes\.exe\\’’ - exefile
HKLM->SOFTWARE\Classes\exefile\shell\open\command\\’’ - “%1” %*
HKLM->SOFTWARE\Classes\.hta\\’’ - htafile
HKLM->SOFTWARE\Classes\htafile\shell\open\command\\’’ - C:\WINDOWS\system32\mshta.exe “%1” %*
HKLM->SOFTWARE\Classes\.js\\’’ - JSFile
HKLM->SOFTWARE\Classes\jsfile\shell\open\command\\’’ - %SystemRoot%\System32\WScript.exe “%1” %*
HKLM->SOFTWARE\Classes\.jse\\’’ - JSEFile
HKLM->SOFTWARE\Classes\jsefile\shell\open\command\\’’ - %SystemRoot%\System32\WScript.exe “%1” %*
HKLM->SOFTWARE\Classes\.scr\\’’ - scrfile
HKLM->SOFTWARE\Classes\scrfile\shell\open\command\\’’ - “%1” /S
HKLM->SOFTWARE\Classes\.vbe\\’’ - VBEFile
HKLM->SOFTWARE\Classes\vbefile\shell\open\command\\’’ - %SystemRoot%\System32\WScript.exe “%1” %*
HKLM->SOFTWARE\Classes\.vbs\\’’ - VBSFile
HKLM->SOFTWARE\Classes\vbsfile\shell\open\command\\’’ - %SystemRoot%\System32\WScript.exe “%1” %*
HKLM->SOFTWARE\Classes\.wsf\\’’ - WSFFile
HKLM->SOFTWARE\Classes\wsffile\shell\open\command\\’’ - %SystemRoot%\System32\WScript.exe “%1” %*
HKLM->SOFTWARE\Classes\.wsh\\’’ - WSHFile
HKLM->SOFTWARE\Classes\wshfile\shell\open\command\\’’ - %SystemRoot%\System32\WScript.exe “%1” %*
HKLM->SOFTWARE\Classes\.txt\\’’ - txtfile
HKLM->SOFTWARE\Classes\txtfile\shell\open\command\\’’ - %SystemRoot%\system32\NOTEPAD.EXE %1

[>> Registry Run Keys <<]
HKLM->Run\\AlcWzrd - ALCWZRD.EXE (RealTek Semicoductor Corp. )
HKLM->Run\\ATIPTA - C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc. )
HKLM->Run\\BluetoothAuthenticationAgent - rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent (Microsoft Corporation )
HKLM->Run\\EPSON Stylus CX3200 - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 “EPSON Stylus CX3200” /O6 “USB001” /M “Stylus CX3200” (SEIKO EPSON CORPORATION )
HKLM->Run\\Genvej til egenskabsside for High Definition Audio - HDAudPropShortcut.exe (Windows (R) Server 2003 DDK provider )
HKLM->Run\\Home Theater SchSvr - “C:\Programmer\Fælles filer\InterVideo\SchSvr\SchSvr.exe” (InterVideo Inc. )
HKLM->Run\\HPHmon06 - C:\WINDOWS\system32\hphmon06.exe (Hewlett-Packard )
HKLM->Run\\HPHUPD06 - c:\Programmer\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe (Hewlett-Packard )
HKLM->Run\\hpsysdrv - c:\windows\system\hpsysdrv.exe (Hewlett-Packard Company )
HKLM->Run\\iTunesHelper - “C:\Programmer\iTunes\iTunesHelper.exe” (Apple Computer, Inc. )
HKLM->Run\\KBD - C:\HP\KBD\KBD.EXE (Hewlett-Packard Company )
HKLM->Run\\LSBWatcher - c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe (Hewlett-Packard Company )
HKLM->Run\\PS2 - C:\WINDOWS\system32\ps2.exe (Hewlett-Packard Company )
HKLM->Run\\QuickTime Task - “C:\Programmer\QuickTime\qttask.exe” -atboottime (Apple Computer, Inc. )
HKLM->Run\\Recguard - C:\WINDOWS\SMINST\RECGUARD.EXE ( )
HKLM->Run\\SoundMan - SOUNDMAN.EXE (Realtek Semiconductor Corp. )
HKLM->Run\\SunJavaUpdateSched - C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe (Sun Microsystems, Inc. )
HKLM->Run\\WINREMOTE - C:\Programmer\InterVideo\Common\Bin\WinRemote.exe (InterVideo Inc. )
HKLM->Run\OptionalComponents\IMAIL - Installed = 1
HKLM->Run\OptionalComponents\MAPI - Installed = 1
HKLM->Run\OptionalComponents\MSFS - Installed = 1
HKCU->Run\\ctfmon.exe - C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation )
HKCU->Run\\JewelQuestSetup.exe - C:\DOWNLO~1\JEWELQ~1.EXE /r (File not found)
HKCU->Run\\MSMSGS - “C:\Programmer\Messenger\msmsgs.exe” /background (Microsoft Corporation )

[>> Miscellaneous Startup Keys <<]

[AppInit DLLs]
AppInit_DLL - \\?\C:\WINDOWS\system32\com5.sit (File not found)

[Image File Execution Options]
Your Image File Name Here without a path - Debugger = ntsd -d

[Shell Service Object Delay Load]
CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\system32\stobject.dll (Microsoft Corporation )
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\system32\webcheck.dll (Microsoft Corporation )

[Shell Execute Hooks]
{54D9498B-CF93-414F-8984-8CE7FDE0D391} - CShellExecuteHookImpl Object = C:\Documents and Settings\HP_Ejer\Skrivebord\Spywarefri\security suite\shellhook.dll ( )
{57B86673-276A-48B2-BAE7-C6DBB3020EB8} - CShellExecuteHookImpl Object = C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll (Anti-Malware Development a.s. )
{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - SABShellExecuteHook Class = C:\Programmer\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com )
{AEB6717E-7E19-11d0-97EE-00C04FD91972} - URL Exec Hook = shell32.dll (Microsoft Corporation )

[Shared Task Scheduler]
{438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader = %SystemRoot%\system32\browseui.dll (Microsoft Corporation )
{8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon = %SystemRoot%\system32\browseui.dll (Microsoft Corporation )

[SafeBoot Option]

[HKLM Command Processor AutoRun]
HKLM->Command Processor\\AutoRun - 

[HKCU Command Processor AutoRun]

[Security Providers]
SecurityProviders\\SecurityProviders - msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll

[BootExecute]
Session Manager\\BootExecute - autocheck autochk *;

[PendingFileRenameOperations]

[FileRenameOperations]

[ExcludeFromKnownDlls]
Session Manager\\ExcludeFromKnownDlls - 

[>> Disabled MSConfig Items <<]

[>> User Agent Post Platform <<]
FunWebProducts - 
SV1 - 

[>> Winlogon <<]
HMLM->AltDefaultDomainName - HP
HMLM->AltDefaultUserName - HP_Ejer
HMLM->AutoAdminLogon - Reg Data - Value does not exist
HMLM->DefaultDomainName - HP
HMLM->DefaultUserName - HP_Ejer
HKLM->Shell - Explorer.exe (Microsoft Corporation )
HKLM->System -  (File not found)
HMLM->UserInit - c:\windows\system32\userinit.exe,“c:\windows\compaqsensor.exe”, (File not found)
HKLM->VMApplet - rundll32 shell32,Control_RunDLL “sysdm.cpl”
Notify\AtiExtEvent - Ati2evxx.dll (ATI Technologies Inc. )
Notify\crypt32chain - crypt32.dll (Microsoft Corporation )
Notify\cryptnet - cryptnet.dll (Microsoft Corporation )
Notify\cscdll - cscdll.dll (Microsoft Corporation )
Notify\SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com )
Notify\ScCertProp - wlnotify.dll (Microsoft Corporation )
Notify\Schedule - wlnotify.dll (Microsoft Corporation )
Notify\sclgntfy - sclgntfy.dll (Microsoft Corporation )
Notify\SensLogn - WlNotify.dll (Microsoft Corporation )
Notify\termsrv - wlnotify.dll (Microsoft Corporation )
Notify\wlballoon - wlnotify.dll (Microsoft Corporation )

[>> DNS Name Servers <<]
{0AA0C0A3-ABB8-4929-A2CE-80CCB4A02C9F} -  ()
{23A773DB-8EB9-4A18-A4D7-ED67621F0A15} -  (1394-netværkskort)
{50522ACC-1895-440D-8D73-E82C92DD0E22} -  (Realtek RTL8139/810x Family Fast Ethernet NIC)
{62177FEE-7842-40E4-A7C2-DF5D975E846F} -  (Wireless LAN PCI 802.11 a/b/g adapter WN5401A)
{B47A2427-C893-400D-AC58-CA643A039082} -  ()

[>> All Winsock2 Catalogs <<]
NameSpace_Catalog5\Catalog_Entries\000000000001 (Tcpip) - %SystemRoot%\System32\mswsock.dll (Microsoft Corporation )
NameSpace_Catalog5\Catalog_Entries\000000000002 (NTDS) - %SystemRoot%\System32\winrnr.dll (Microsoft Corporation )
NameSpace_Catalog5\Catalog_Entries\000000000003 (NLA-navneområde (Network Location Awareness)) - %SystemRoot%\System32\mswsock.dll (Microsoft Corporation )
NameSpace_Catalog5\Catalog_Entries\000000000004 (Bluetooth-navneområde) - %SystemRoot%\system32\wshbth.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\system32\rsvpsp.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\system32\rsvpsp.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000012 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000013 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000014 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000015 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000016 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000017 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000018 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000019 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000020 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )

[>> Protocol Handlers (Non-Microsoft only) <<]
ipp -  (File not found)
msdaipp -  (File not found)

[>> Protocol Filters (Non-Microsoft only) <<]

< Services (Non-Microsoft Only) >
Ati HotKey Poller (Ati HotKey Poller) - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc. ) [Automatic - Running - Win32, running in it’s own process]
AVG Anti-Spyware Guard (AVG Anti-Spyware Guard) - C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe (Anti-Malware Development a.s. ) [Automatic - Running - Win32, running in it’s own process]
EpsonBidirectionalService (EpsonBidirectionalService) - C:\Programmer\Fælles filer\EPSON\EBAPI\eEBSVC.exe ( ) [Automatic - Running - Win32, running in it’s own process]
EPSON Printer Status Agent2 (EPSONStatusAgent2) - C:\Programmer\Fælles filer\EPSON\EBAPI\SAgent2.exe (SEIKO EPSON CORPORATION ) [Automatic - Running - Win32, running in it’s own process]
ewido security suite control (ewido security suite control) - C:\Documents and Settings\HP_Ejer\Skrivebord\Spywarefri\security suite\ewidoctrl.exe (ewido networks ) [Automatic - Running - Win32, running in it’s own process]
iPodService (iPodService) - C:\Programmer\iPod\bin\iPodService.exe (Apple Computer, Inc. ) [On Demand - Running - Win32, running in it’s own process]
LightScribeService Direct Disc Labeling Service (LightScribeService) - “c:\Programmer\Fælles filer\LightScribe\LSSrvc.exe” (Hewlett-Packard Company ) [Automatic - Running - Win32, running in it’s own process]
Pml Driver HPZ12 (Pml Driver HPZ12) - C:\WINDOWS\system32\HPZipm12.exe (HP ) [Automatic - Running - Win32, running in it’s own process]

< Files >

Auto-Start Folders

HKLM->Explorer\Shell Folders\\Common Startup = C:\Documents and Settings\All Users\Menuen Start\Programmer\Start
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Adobe Reader Hurtigstart.lnk - C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated [Ver = 7.0.5.2005092300 | Size = 29696 bytes | Date = 23-09-2005 22:05:26 | Attr =  ])
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\desktop.ini - ( [Ver =  | Size = 84 bytes | Date = 03-12-2004 20:25:36 | Attr =  HS])
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\HP Digital Imaging Monitor.lnk - C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co. [Ver = 45.4.157.000 | Size = 258048 bytes | Date = 05-11-2004 02:28:24 | Attr =  ])

HKLM->Explorer\User Shell Folders\\Common Startup = %ALLUSERSPROFILE%\Menuen Start\Programmer\Start

HKLM->Explorer\Shell Folders\\Startup = C:\Documents and Settings\HP_Ejer\Menuen Start\Programmer\Start
C:\Documents and Settings\HP_Ejer\Menuen Start\Programmer\Start\desktop.ini - ( [Ver =  | Size = 84 bytes | Date = 03-12-2004 20:25:36 | Attr =  HS])

HKCU->Explorer\User Shell Folders\\Startup = %USERPROFILE%\Menuen Start\Programmer\Start

Miscellaneous Auto-Start Files
System.ini->[Boot]\\Shell - Explorer.exe

Miscellaneous Folders

AllUsers ApplicationData Folder
C:\Documents and Settings\All Users\Application Data\desktop.ini -              ( [Ver =  | Size = 62 bytes | Date = 03-12-2004 21:17:08 | Attr =  HS]) 
C:\Documents and Settings\All Users\Application Data\hpzinstall.log -              ( [Ver =  | Size = 1888 bytes | Date = 02-01-2005 00:35:08 | Attr =  ]) 
C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache -              ( [Ver =  | Size = 1398 bytes | Date = 11-11-2006 13:30:50 | Attr =  ]) 

CurrentUser ApplicationData Folder
C:\Documents and Settings\HP_Ejer\Application Data\desktop.ini -              ( [Ver =  | Size = 62 bytes | Date = 03-12-2004 21:17:08 | Attr =  HS]) 
C:\Documents and Settings\HP_Ejer\Application Data\SecureTraveler.exe -              ( [Ver = 1, 1, 0, 23 | Size = 1597440 bytes | Date = 05-11-2004 13:31:00 | Attr =  ]) 
C:\Documents and Settings\HP_Ejer\Application Data\wklnhst.dat -              ( [Ver =  | Size = 2432 bytes | Date = 19-12-2005 22:19:50 | Attr =  ]) 

Program Files Folder

Common Files Folder

DPF files
{14B87622-7E19-4EA8-93B3-97215F77A6BC} - MessengerStatsClient Class - CodeBase = http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
{166B1BCA-3F9C-11CF-8075-444553540000} - Shockwave ActiveX Control - CodeBase = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
{17492023-C23A-453E-A040-C7C580BBF700} - Windows Genuine Advantage Validation Tool - CodeBase = http://go.microsoft.com/fwlink/?linkid=39204
{2917297F-F02B-4B9D-81DF-494B6333150B} - Minesweeper Flags Class - CodeBase = http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
{3D2CB570-D425-11D5-ABD0-00008369C46F} - CSMenu Class - CodeBase = http://netbank.danskebank.dk/html/activex/DB/Menu.cab
{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - Office Update Installation Engine - CodeBase = http://office.microsoft.com/officeupdate/content/opuc3.cab
{4F1E5B1A-2A80-42CA-8532-2D05CB959537} - MSN Photo Upload Tool - CodeBase = http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
{74D05D43-3236-11D4-BDCD-00C04F9A3B61} - HouseCall Control - CodeBase = http://safehouse1.cybercity.dk/privat/xscan53.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} - Java Plug-in 1.5.0_06 - CodeBase = http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
{8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - MessengerStatsClient Class - CodeBase = http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
{B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - MsnMessengerSetupDownloadControl Class - CodeBase = http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
{B8BE5E93-A60C-4D26-A2DC-220313175592} - ZoneIntro Class - CodeBase = http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - Java Plug-in 1.5.0 - CodeBase = http://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - Java Plug-in 1.5.0_04 - CodeBase = http://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - Java Plug-in 1.5.0_06 - CodeBase = http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - Java Plug-in 1.5.0_06 - CodeBase = http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} -  - CodeBase = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
{D8575CE3-3432-4540-88A9-85A1325D3375} - e-Safekey - CodeBase = https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
{DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} - IP-Uploader Control - CodeBase = http://asp03.photoprintit.de/microsite/10021/defaults/activex/ImageUploader3.cab
Microsoft XML Parser for Java -  - CodeBase = file://C:\WINDOWS\Java\classes\xmldso.cab

Hosts file = 723 bytes. Reading all entries. C:\WINDOWS\System32\drivers\etc\Hosts
# Copyright (c) 1993-1999 Microsoft Corp. -
# -
# Dette er HOSTS-eksempelfilen, der bruges af Microsoft TCP/IP til Windows. -
# -
# Denne fil indeholder IP-adressetilknytninger til værtsnavne. Du bør ikke -
# angive flere end en post pr. linje. IP-adressen skal placeres i den første -
# kolonne efterfulgt af det tilsvarende værtsnavn. -
# IP-adressen og værtsnavnet kan adskilles af mindst ét mellemrum. -
# -
# Kommentarer (som disse) kan indsættes på individuelle linjer eller efter- -
# følge computernavn. Kommentarer skal anføres med nummertegn ‘#’. -
# -
# Eksempel: -
# -
#    102.54.94.97   rhino.acme.com       # kildeserver -
#    38.25.63.10   x.acme.com         # x-klientvært -
127.0.0.1     localhost -
-

< Add On’s >

>>>>Output for AddOn file Policies.def<<<<

KEY - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies - Include SUBKEYS
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies -
policies\explorer -
policies\explorer\\NoCDBurning - 0
policies\explorer\run -
policies\NonEnum -
policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} - 1
policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} - 1073741857
policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} - 32
policies\Ratings -
policies\system -
policies\system\\dontdisplaylastusername - 0
policies\system\\legalnoticecaption -
policies\system\\legalnoticetext -
policies\system\\shutdownwithoutlogon - 1
policies\system\\undockwithoutlogon - 1

KEY - HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer - Include SUBKEYS
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer not found. -

KEY - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies - Include SUBKEYS
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies -
policies\Associations -
policies\Explorer -
policies\Explorer\\NoDriveTypeAutoRun - 145
policies\Explorer\Run -
policies\System -

KEY - HKCU\SOFTWARE\Policies\Microsoft\Internet Explorer - Include SUBKEYS
HKCU\SOFTWARE\Policies\Microsoft\Internet Explorer not found. -

>>>>Output for AddOn file Security.def<<<<

KEY - HKLM\SOFTWARE\Microsoft\Security Center - Include SUBKEYS
HKLM\SOFTWARE\Microsoft\Security Center -
Security Center\\FirstRunDisabled - 1
Security Center\\AntiVirusDisableNotify - 0
Security Center\\FirewallDisableNotify - 1
Security Center\\UpdatesDisableNotify - 0
Security Center\\AntiVirusOverride - 0
Security Center\\FirewallOverride - 0
Security Center\Monitoring -
Security Center\Monitoring\AhnlabAntiVirus -
Security Center\Monitoring\ComputerAssociatesAntiVirus -
Security Center\Monitoring\KasperskyAntiVirus -
Security Center\Monitoring\McAfeeAntiVirus -
Security Center\Monitoring\McAfeeFirewall -
Security Center\Monitoring\PandaAntiVirus -
Security Center\Monitoring\PandaFirewall -
Security Center\Monitoring\SophosAntiVirus -
Security Center\Monitoring\SymantecAntiVirus -
Security Center\Monitoring\SymantecFirewall -
Security Center\Monitoring\TinyFirewall -
Security Center\Monitoring\TrendAntiVirus -
Security Center\Monitoring\TrendFirewall -
Security Center\Monitoring\ZoneLabsFirewall -

KEY - HKLM\SYSTEM\CurrentControlSet\Services\BITS - Include SUBKEYS
HKLM\SYSTEM\CurrentControlSet\Services\BITS -
BITS\\Type - 32
BITS\\Start - 2
BITS\\ErrorControl - 1
BITS\\ImagePath - %SystemRoot%\system32\svchost.exe -k netsvcs
BITS\\DisplayName - Tjenesten Background Intelligent Transfer
BITS\\DependOnService - RpcSs;
BITS\\DependOnGroup -
BITS\\ObjectName - LocalSystem
BITS\\Description - Overfører data mellem klienter og servere i baggrunden. Hvis BITS deaktiveres, vil programmer som f.eks. Windows Update ikke fungere korrekt.
BITS\\FailureActions - 00 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 68 E3 0C 00 01 00 00 00 60 EA 00 00 01 00 00 00 60 EA 00 00 01 00 00 00 60 EA 00 00
BITS\Parameters -
BITS\Parameters\\ServiceDll - C:\WINDOWS\system32\qmgr.dll
BITS\Security -
BITS\Security\\Security - 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00
BITS\Enum -
BITS\Enum\\0 - Root\LEGACY_BITS\0000
BITS\Enum\\Count - 1
BITS\Enum\\NextInstance - 1

KEY - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess - Include SUBKEYS
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess -
SharedAccess\\DependOnGroup -
SharedAccess\\DependOnService - Netman;WinMgmt;
SharedAccess\\Description - Giver mulighed for adresseoversættelse, adressering, navnefortolkning og/eller tjenester til forebyggelse af uautoriseret brug for netværksadresser på et hjemmenetværk eller mindre kontornetværk.
SharedAccess\\DisplayName - Windows Firewall/Deling af Internetforbindelse
SharedAccess\\ErrorControl - 1
SharedAccess\\ImagePath - %SystemRoot%\system32\svchost.exe -k netsvcs
SharedAccess\\ObjectName - LocalSystem
SharedAccess\\Start - 2
SharedAccess\\Type - 32
SharedAccess\Epoch -
SharedAccess\Epoch\\Epoch - 5217
SharedAccess\Parameters -
SharedAccess\Parameters\\ServiceDll - %SystemRoot%\System32\ipnathlp.dll
SharedAccess\Parameters\FirewallPolicy -
SharedAccess\Parameters\FirewallPolicy\DomainProfile -
SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications -
SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List -
SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe - %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\%ProgramFiles%\iTunes\iTunes.exe - %ProgramFiles%\iTunes\iTunes.exe:*:enabled:iTunes
SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Programmer\MSN Messenger\msnmsgr.exe - C:\Programmer\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0
SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Programmer\MSN Messenger\msncall.exe - C:\Programmer\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)
SharedAccess\Parameters\FirewallPolicy\StandardProfile -
SharedAccess\Parameters\FirewallPolicy\StandardProfile\\EnableFirewall - 1
SharedAccess\Parameters\FirewallPolicy\StandardProfile\\DoNotAllowExceptions - 0
SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications -
SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -
SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe - %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Programmer\iTunes\iTunes.exe - C:\Programmer\iTunes\iTunes.exe:*:Enabled:iTunes
SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Programmer\Messenger\msmsgs.exe - C:\Programmer\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Programmer\MSN Messenger\msnmsgr.exe - C:\Programmer\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0
SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Programmer\MSN Messenger\msncall.exe - C:\Programmer\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)
SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Programmer\LimeWire\LimeWire.exe - C:\Programmer\LimeWire\LimeWire.exe:*:Enabled:LimeWire
SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Programmer\Skype\Phone\Skype.exe - C:\Programmer\Skype\Phone\Skype.exe:*:Enabled:Skype
SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts -
SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List -
SharedAccess\Setup -
SharedAccess\Setup\\ServiceUpgrade - 1
SharedAccess\Setup\InterfacesUnfirewalledAtUpdate -
SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\All - 1
SharedAccess\Enum -
SharedAccess\Enum\\0 - Root\LEGACY_SHAREDACCESS\0000
SharedAccess\Enum\\Count - 1
SharedAccess\Enum\\NextInstance - 1

KEY - HKLM\SYSTEM\CurrentControlSet\Services\wuauserv - Include SUBKEYS
HKLM\SYSTEM\CurrentControlSet\Services\wuauserv -
wuauserv\\Type - 32
wuauserv\\Start - 2
wuauserv\\ErrorControl - 1
wuauserv\\ImagePath - %systemroot%\system32\svchost.exe -k netsvcs
wuauserv\\DisplayName - Automatiske opdateringer
wuauserv\\ObjectName - LocalSystem
wuauserv\\Description - Muliggør hentning og installation af Windows-opdateringer. Hvis denne tjeneste deaktiveres, vil computeren ikke være i stand til at bruge funktionen automatiske opdateringer eller webstedet Windows Update.
wuauserv\Parameters -
wuauserv\Parameters\\ServiceDll - C:\WINDOWS\system32\wuauserv.dll
wuauserv\Security -
wuauserv\Security\\Security - 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00
wuauserv\Enum -
wuauserv\Enum\\0 - Root\LEGACY_WUAUSERV\0000
wuauserv\Enum\\Count - 1
wuauserv\Enum\\NextInstance - 1

>>>>Output for AddOn file ShellState.def<<<<

KEY - HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer - No SUBKEYS
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer -
Explorer\\WebFindBandHook - {68F2D3FC-8366-4a46-8224-58EFA2749425}
Explorer\\FileFindBandHook - {FFAC7A18-EDF9-40de-BA3F-49FC2269855E}
Explorer\\Logon User Name - HP_Ejer
Explorer\\ShellState - 24 00 00 00 38 28 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 0D 00 00 00 00 00 00 00 02 00 00 00
Explorer\\CleanShutdown - 0
Explorer\\FaultCount - 0
Explorer\\FaultTime - 0
Explorer\\Browse For Folder Width - 318
Explorer\\Browse For Folder Height - 330
Explorer\\SearchSystemDirs - 1
Explorer\\SearchHidden - 1
Explorer\\IncludeSubFolders - 1
Explorer\\CaseSensitive - 0
Explorer\\SearchSlowFiles - 0
Explorer\\link - 18 00 00 00
Explorer\Advanced -
Explorer\AutoComplete -
Explorer\AutoplayHandlers -
Explorer\BitBucket -
Explorer\CabinetState -
Explorer\CD Burning -
Explorer\CLSID -
Explorer\ComDlg32 -
Explorer\ComputerDescriptions -
Explorer\CopyMoveTo -
Explorer\Desktop -
Explorer\Discardable -
Explorer\FileExts -
Explorer\HideMyComputerIcons -
Explorer\Map Network Drive MRU -
Explorer\MenuOrder -
Explorer\MountPoints2 -
Explorer\MyComputer -
Explorer\NewShortcutHandlers -
Explorer\PropSummary -
Explorer\RecentDocs -
Explorer\RunMRU -
Explorer\Shell Folders -
Explorer\ShellImageView -
Explorer\SmallIcons -
Explorer\StartPage -
Explorer\StreamMRU -
Explorer\Streams -
Explorer\StuckRects2 -
Explorer\tips -
Explorer\TrayNotify -
Explorer\User Shell Folders -
Explorer\UserAssist -
Explorer\VisualEffects -
Explorer\Wallpaper -
Explorer\WebView -
Explorer\WorkgroupCrawler -
Explorer\SessionInfo -

< End of report >

  Ejvindh
Redaktør
Avatar
Antal indlæg: 6158

Det er mystisk, for alle de rootkit-scannere som virker, finder ikke noget. Og samtidig er der rester efter et rootkit, som normalt forhindrer kørslen af visse rootkit-scannere. Så dette tyder jo på, at den er aktiv. Men lad os lige prøve at se om vi simpelthen kan fixe resterne manuelt først. Hvis dette lykkes, skal årsagen til problemerne med kørslen af scannerne findes andetsteds…

—Klik på Start=>Kør skriv: SFC /scannow (husk mellemrum mellem SFC og /scannow)
Din windowsXP-CD skal sidde i drevet. Den tjekker og reparer dine systemfiler.

—Kopiér indholdet mellem de stiplede linier ind i et notepad-vindue, og gem indholdet på skrivebordet som vbsregfix2.vbs. Når du gemmer, skal du sikre, at der under “filtyper” står “alle filer”.

——————-

Dim Wshshellfso
 Set WshShell 
Wscript.CreateObject("Wscript.Shell"
 
Set fso CreateObject("Scripting.FileSystemObject"
 
On Error Resume Next
  set objFile 
objFSO.GetFile("c:\windows\compaqsensor.exe")
   
objFile.Attributes 0
   fso
.DeleteFile("c:\windows\compaqsensor.exe")
  
set objFile objFSO.GetFile("C:\WINDOWS\fitia1.dll")
   
objFile.Attributes 0
   fso
.DeleteFile("C:\WINDOWS\fitia1.dll")
  
set objFile objFSO.GetFile("C:\WINDOWS\system32\com5.sit")
   
objFile.Attributes 0
   fso
.DeleteFile("C:\WINDOWS\system32\com5.sit")
  
set objFile objFSO.GetFile("\\?\C:\WINDOWS\system32\com5.sit")
   
objFile.Attributes 0
   fso
.DeleteFile("\\?\C:\WINDOWS\system32\com5.sit")
  
WshShell.RegDelete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2D68F875-ADCC-F2BC-A67A-75F6948BD923}\"
  
WshShell.RegDelete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D68F875-ADCC-F2BC-A67A-75F6948BD923}\"
  
WshShell.RegDelete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}\"
  
WshShell.RegDelete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
  
WshShell.RegDelete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"
  
WshShell.RegDelete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
  
WshShell.RegDelete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"
  
WshShell.RegDelete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{BC4FFE41-DE9F-46FA-B455-AAD49B9F9938}"
  
WshShell.RegDelete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
  
WshShell.RegDelete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Menu Extensions\&Search"
  
WshShell.RegDelete "HKLM\Software\Microsoft\Internet Explorer\Extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263}"
  
WshShell.RegDelete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts"
  
WshShell.RegWrite "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs"" "
  
WshShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit""C:\WINDOWS\system32\userinit.exe,"
------------------- 

—Dobbeltklik så på den fil, som du lige har lavet.

—Genstart herefter til fejlsikret tilstand, og dobbeltklik på den nye fil igen.

—Genstart herefter til normal tilstand, og læg en ny log fra WinPfind2 herind, så jeg kan se, hvor meget det har hjulpet.

—Prøv også igen om du kan lave en log med Hijackthis, og meld resultatet herind.