Vinnaren i pepparkakshustävlingen!
2007-03-30, 15:33
  #1
Medlem
Har skrivit i 2 andra forum och inte fått nån hjälp. Hade vundo virus för en vecka sedan, och datorn uppför sig fortfarande konstigt. Vad är fel? Nedan är en deckerd DSS scan. Kan någon svara vad jag kan göra eller bör göra om loggen ser fel ut?
/M

Deckard's System Scanner v20070328.36
Run by Martin & Kristofer on 2007-03-29 at 18:44:31
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

-- HijackThis (run as Martin & Kristofer.exe) ----------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 06:45, on 2007-03-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\Delade filer\Symantec Shared\ccProxy.exe
C:\Program\Delade filer\Symantec Shared\ccSetMgr.exe
C:\Program\Norton Internet Security\ISSVC.exe
C:\Program\Delade filer\Symantec Shared\SNDSrvc.exe
C:\Program\Delade filer\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program\Delade filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program\ewido anti-spyware 4.0\guard.exe
C:\Program\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\Program\Delade filer\Symantec Shared\Security Center\SymWSC.exe
C:\Program\Java\jre1.5.0_03\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program\Dell\Media Experience\DMXLauncher.exe
C:\Program\Delade filer\Symantec Shared\ccApp.exe
C:\Program\iTunes\iTunesHelper.exe
C:\Program\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program\iPod\bin\iPodService.exe
C:\Program\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Delade filer\Teleca Shared\CapabilityManager.exe
C:\Program\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\LVComS.exe
C:\Program\Logitech\Video\LowLight.exe
C:\Program\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program\Delade filer\Teleca Shared\Generic.exe
C:\Program\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program\MSN Messenger\usnsvc.exe
C:\martin\Radera\dss.exe
C:\martin\Radera\Martin & Kristofer.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {24EAD2A4-1ED7-4BB5-B2BA-F9EF9FDF5DD6} - (no file)
O2 - BHO: (no name) - {4F0388F6-7635-4CD6-8B10-82DF3379386D} - (no file)
O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {5D639810-E86F-42EE-9FD3-1702B4D6B83C} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {84BAC657-9C09-4524-8E85-1C6A3378BADC} - (no file)
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program\Delade filer\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: (no name) - {A496ED38-F4D7-4395-8E8E-373A80ED314D} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program\Delade filer\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program\CyberLink\PowerDVD\DVDLauncher.exe "
O4 - HKLM\..\Run: [DMXLauncher] C:\Program\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program\Delade filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\Program\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\chvxqhpn.dll",setvm
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program\Delade filer\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [!ewido] "C:\Program\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Snabbstarta.lnk = C:\Program\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Personal.lnk = C:\Program\Personal\bin\Personal.exe
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MICROS~3\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by121fd.bay121.hotmail.msn.co...s/MsnPUpld.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/...toUploader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatisk LiveUpdate-schemaläggare - Symantec Corporation - C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program\Norton Internet Security\ISSVC.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto Protect-tjänst (navapsvc) - Symantec Corporation - C:\Program\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\Program\DELADE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
Citera
2007-03-30, 15:34
  #2
Medlem
forts på DSS....

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R0 drvmcdb - c:\windows\system32\drivers\drvmcdb.sys
R1 omci (OMCI WDM Device Driver) - c:\windows\system32\drivers\omci.sys
R1 sscdbhk5 - c:\windows\system32\drivers\sscdbhk5.sys
R1 ssrtln - c:\windows\system32\drivers\ssrtln.sys
R2 drvnddm - c:\windows\system32\drivers\drvnddm.sys
R2 tfsnboio - c:\windows\system32\dla\tfsnboio.sys
R2 tfsncofs - c:\windows\system32\dla\tfsncofs.sys
R2 tfsndrct - c:\windows\system32\dla\tfsndrct.sys
R2 tfsndres - c:\windows\system32\dla\tfsndres.sys
R2 tfsnifs - c:\windows\system32\dla\tfsnifs.sys
R2 tfsnopio - c:\windows\system32\dla\tfsnopio.sys
R2 tfsnpool - c:\windows\system32\dla\tfsnpool.sys
R2 tfsnudf - c:\windows\system32\dla\tfsnudf.sys
R2 tfsnudfa - c:\windows\system32\dla\tfsnudfa.sys
R3 PhilCam8116 (Logitech QuickCam Pro 3000(PID_08B0)) - c:\windows\system32\drivers\camdrl21.sys
R3 STHDA (High Definition Audio Driver (WDM) - SigmaTel CODEC) - c:\windows\system32\drivers\sthda.sys

S1 ewido anti-spyware 4.0 driver - c:\program\ewido anti-spyware 4.0\guard.sys (file missing)
S3 ATE_PROCMON - c:\program\anti trojan elite\atepmon.sys (file missing)
S3 NAL (Nal Service ) - c:\windows\system32\drivers\iqvw32.sys
S3 SE26bus (Sony Ericsson Device 038 Driver driver (WDM)) - c:\windows\system32\drivers\se26bus.sys
S4 cbidf - c:\windows\system32\drivers\cbidf2k.sys
S4 dac2w2k - c:\windows\system32\drivers\dac2w2k.sys


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Automatisk LiveUpdate-schemaläggare - "c:\program\symantec\liveupdate\aluschedulersvc.ex e"
R2 ISSVC - "c:\program\norton internet security\issvc.exe"
R2 UStorage Server Service - c:\windows\system32\ustorsrv.exe /service


-- Scheduled Tasks -------------------------------------------------------------

2007-03-29 18:43:00 342 --a------ C:\WINDOWS\Tasks\Symantec NetDetect.job<SYMANT~1.JOB>
2007-03-28 20:02:00 308 --a------ C:\WINDOWS\Tasks\WebReg officejet 6200 series.job<WEBREG~1.JOB>
2007-03-27 17:57:16 302 --a------ C:\WINDOWS\Tasks\XoftSpy.job
2007-03-16 21:00:00 574 --a------ C:\WINDOWS\Tasks\Norton AntiVirus - Sök igenom datorn - Karin & Bengt.job<NORTON~1.JOB>


-- Files created between 2007-02-28 and 2007-03-29 -----------------------------

2007-03-29 15:56:15 0 d-------- C:\WINDOWS\system32\ActiveScan<ACTIVE~1>
2007-03-29 15:56:12 0 d-------- C:\WINDOWS\LastGood
2007-03-28 16:20:16 4120 --a------ C:\WINDOWS\system32\tmp.reg
2007-03-28 16:19:49 79360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-03-28 16:19:49 40960 --a------ C:\WINDOWS\system32\swsc.exe
2007-03-28 16:19:49 135168 --a------ C:\WINDOWS\system32\swreg.exe
2007-03-28 16:19:49 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-03-28 16:19:49 53248 --a------ C:\WINDOWS\system32\Process.exe
2007-03-28 16:19:49 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-03-28 16:00:43 0 d-------- C:\Program\SpywareBlaster<SPYWAR~1>
2007-03-28 13:15:24 0 --a------ C:\WINDOWS\system32\SBRC.dat
2007-03-28 13:15:24 0 --a------ C:\WINDOWS\system32\SBFC.dat
2007-03-28 12:50:30 0 d-------- C:\Program\ewido anti-spyware 4.0<EWIDOA~1.0>
2007-03-28 11:45:24 0 d-------- C:\VundoFix Backups<VUNDOF~1>
2007-03-28 00:30:35 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy<SPYBOT~1>
2007-03-27 23:56:15 0 d-------- C:\Program\Enigma Software Group<ENIGMA~1>
2007-03-27 23:01:45 0 d-------- C:\Program\Anti Trojan Elite<ANTITR~1>
2007-03-27 22:33:43 0 d-------- C:\Program\SoftwareRevenue.org<SOFTWA~1.ORG>
2007-03-27 22:33:21 475770 --a------ C:\WINDOWS\system32\mi1.exe
2007-03-26 23:08:48 0 d-------- C:\WINDOWS\pss
2007-03-25 16:49:51 139264 --a------ C:\WINDOWS\system32\UStorSrv.exe
2007-03-25 16:49:51 139264 --a------ C:\WINDOWS\system32\OPDSL.DLL
2007-03-25 14:44:04 230400 --a------ C:\WINDOWS\system32\SNWValid.dll
2007-03-25 14:44:04 1016832 --a------ C:\WINDOWS\system32\SierraNW.DLL
2007-03-25 14:44:03 0 d-------- C:\SIERRA
2007-03-25 14:44:03 0 d-------- C:\Program\Sierra On-Line<SIERRA~1>
2007-03-16 09:48:54 249856 -----n--- C:\WINDOWS\Setup1.exe
2007-03-16 09:48:52 73216 --a------ C:\WINDOWS\ST6UNST.EXE
2007-03-15 11:23:16 497496 --a------ C:\WINDOWS\system32\XceedZip.dll
2007-03-15 11:19:58 526184 --a------ C:\WINDOWS\system32\XceedCry.dll


-- Find3M Report ---------------------------------------------------------------

2007-03-29 16:40:05 0 d-------- C:\Program\Norton Internet Security<NORTON~1>
2007-03-29 16:39:37 0 d-------- C:\Program\MSN Messenger<MSNMES~1>
2007-03-29 16:34:00 0 d-------- C:\Program\iTunes
2007-03-29 16:32:23 0 d-------- C:\Program\Delade filer\Teleca Shared<TELECA~1>
2007-03-29 16:32:11 0 d-------- C:\Program\Delade filer\Symantec Shared<SYMANT~1>
2007-03-29 16:31:04 0 d-------- C:\Program\D-Tools
2007-03-29 16:01:33 0 d-------- C:\Program\BitLord
2007-03-29 15:07:23 0 d-------- C:\Program\Delade filer<DELADE~1>
2007-03-27 22:37:15 0 d-------- C:\Program\TweakNow RegCleaner Std<TWEAKN~1>
2007-03-27 20:58:48 0 d-------- C:\Documents and Settings\Martin & Kristofer\Application Data\Lavasoft
2007-03-27 19:37:03 0 d-------- C:\Documents and Settings\Martin & Kristofer\Application Data\AVG7
2007-03-25 10:40:57 387578 --a------ C:\WINDOWS\system32\perfh01D.dat
2007-03-25 10:40:57 64614 --a------ C:\WINDOWS\system32\perfc01D.dat
2007-03-21 20:04:18 0 d-------- C:\Program\nordicbetMPP<NORDIC~1>
2007-03-21 16:22:49 0 d-------- C:\Documents and Settings\Martin & Kristofer\Application Data\Microgaming<MICROG~1>
2007-03-18 13:16:36 0 d---s---- C:\Documents and Settings\Martin & Kristofer\Application Data\Microsoft<MICROS~1>
2007-03-16 10:03:51 0 d-------- C:\Program\Delade filer\InstallShield<INSTAL~1>
2007-03-16 10:03:36 0 d--h----- C:\Program\InstallShield Installation Information<INSTAL~1>
2007-01-30 14:18:43 0 d-------- C:\Program\LimeWire
2007-01-30 14:18:19 0 d-------- C:\Program\Java
2007-01-19 13:53:04 51056 --a------ C:\WINDOWS\system32\sirenacm.dll


-- Registry Dump ---------------------------------------------------------------


[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.ex e"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run]
"SunJavaUpdateSched"="C:\\Program\\Java\\jre1.5.0_ 03\\bin\\jusched.exe"
"SigmatelSysTrayApp"="stsystra.exe"
"ATIPTA"="C:\\Program\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"DVDLauncher"="\"C:\\Program\\CyberLink\\PowerDVD\ \DVDLauncher.exe\""
"DMXLauncher"="C:\\Program\\Dell\\Media Experience\\DMXLauncher.exe"
"ccApp"="\"C:\\Program\\Delade filer\\Symantec Shared\\ccApp.exe\""
"Symantec NetDriver Monitor"="C:\\Program\\SYMNET~1\\SNDMon.exe /Consumer"
"iTunesHelper"="\"C:\\Program\\iTunes\\iTunesHelpe r.exe\""
"QuickTime Task"="\"C:\\Program\\QuickTime\\qttask.exe\" -atboottime"
"Sony Ericsson PC Suite"="\"C:\\Program\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions"
"LogitechVideoRepair"="C:\\Program\\Logitech\\Vide o\\ISStart.exe"
"LogitechVideoTray"="C:\\Program\\Logitech\\Video\ \LogiTray.exe"
"HP Software Update"="C:\\Program\\HP\\HP Software Update\\HPWuSchd2.exe"
"SoundService"="rundll32.exe \"C:\\WINDOWS\\system32\\chvxqhpn.dll\",setvm"
"UserFaultCheck"="%systemroot%\\system32\\dump rep 0 -u"
"ISUSScheduler"="\"C:\\Program\\Delade filer\\InstallShield\\UpdateService\\issch.exe\" -start"
"dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.ex e"
"DAEMON Tools-1033"="\"C:\\Program\\D-Tools\\daemon.exe\" -lang 1033"
"!ewido"="\"C:\\Program\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shellexecutehooks]
"{4F0388F6-7635-4CD6-8B10-82DF3379386D}"=""
"{182B90A3-F372-438A-800C-6814B4DE417B}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

[HKEY_USERS\.default\software\microsoft\windows\cur rentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EX E"

[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\system]
"DisableRegistryTools"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnph ost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0


[HKCU\Software\Microsoft\Windows\CurrentVersion\Exp lorer\MountPoints2\{20af79a5-d2f7-11db-a64e-00123f8a9520}]
Shell\AutoRun\command J:\LaunchU3.exe -a


-- End of Deckard's System Scanner: finished at 2007-03-29 at 18:45:58 ---------
Citera
2007-03-30, 16:05
  #3
Medlem
jaccees avatar
Har du använt vundofix? Funkar jättebra om man drabats av vundo.
Citera
2007-03-30, 16:13
  #4
Medlem
ja

ja, har kört vundofix och flera smitfraud och tror viruset är borta.. norton hittar inget men datan uppför sig konstigt. Vore snällt om någon kunde kolla igenom min logg.
Citera
2007-03-30, 16:34
  #5
Medlem
groils avatar
Citat:
Ursprungligen postat av martinvernmark
norton hittar inget


Det är för att det är norton.
Citera
2007-03-30, 18:44
  #6
Medlem
RollerBoySEs avatar
Inte Datasäkerhet, trådar av denna typ skall fortsättningsvis läggas i Datoranvändning. Flyttar tråden.

/Mod
Citera

Skapa ett konto eller logga in för att kommentera

Du måste vara medlem för att kunna kommentera

Skapa ett konto

Det är enkelt att registrera ett nytt konto

Bli medlem

Logga in

Har du redan ett konto? Logga in här

Logga in