HiJackThis log - langsom opstart
Stort set nyinstalleret pc med XP service pack 3 tager 20 om at starte op. Dvs. den kommer hurtigt med baggrundsbilledet i XP men uden iconer - de kommer først efter 20 min. Herefter virker PC'en fint - HELP.Jeg har fulgt vedlagt ComboFix log og HiJackThis nedenfor:
ComboFix 11-01-13.01 - Receptionen 14-01-2011 17:30:29.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1030.18.511.223 [GMT 1:00]
Kører fra: c:\documents and settings\Receptionen\Dokumenter\PC doktor\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\Receptionen\Dokumenter\PC doktor\CFScript.txt
AV: Symantec Endpoint Protection *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.
((((((((((((((((((((((((((((( Filer skabt fra 2010-12-14 til 2011-01-14 )))))))))))))))))))))))))))))))))))
.
2011-01-14 15:13 . 2011-01-14 15:13 -------- d-----w- c:\documents and settings\Receptionen\Application Data\Malwarebytes
2011-01-14 14:25 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-14 14:25 . 2011-01-14 14:25 -------- d-----w- c:\programmer\Malwarebytes' Anti-Malware
2011-01-14 14:25 . 2011-01-14 14:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-01-14 14:25 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-14 14:18 . 2011-01-14 14:18 -------- d-----w- c:\programmer\CCleaner
2011-01-14 14:14 . 2011-01-14 14:14 -------- d-----w- c:\documents and settings\Receptionen\Application Data\Reviversoft
2011-01-14 14:14 . 2010-12-13 12:24 11264 ----a-w- c:\windows\system32\roboot.exe
2011-01-13 20:27 . 2011-01-13 20:27 -------- d--h--w- c:\windows\system32\GroupPolicy
2011-01-12 21:53 . 2011-01-12 21:54 -------- d-----w- C:\5bba95bfeb7fdf19672e80cd
2010-12-27 12:16 . 2010-12-27 12:16 -------- d-----w- c:\windows\Sun
2010-12-21 14:18 . 2010-12-21 14:18 -------- d-----w- c:\documents and settings\Receptionen\Lokale indstillinger\Application Data\Symantec
2010-12-21 14:16 . 2010-12-21 14:16 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2010-12-21 14:16 . 2010-12-21 14:16 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-12-21 14:15 . 2007-03-21 19:39 1060864 ----a-w- c:\windows\system32\MFC71.DLL
2010-12-21 14:15 . 2007-03-21 19:33 503808 ----a-w- c:\windows\system32\MSVCP71.DLL
2010-12-21 14:15 . 2007-03-21 19:33 348160 ----a-w- c:\windows\system32\MSVCR71.DLL
2010-12-21 14:15 . 2010-12-21 14:19 -------- d-----w- c:\programmer\Fælles filer\Symantec Shared
2010-12-21 14:15 . 2010-12-21 14:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-12-21 14:15 . 2010-12-21 14:16 -------- d-----w- c:\programmer\Symantec
2010-12-15 20:27 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2010-12-15 20:27 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2010-12-15 17:40 . 2010-12-15 17:40 -------- d-----w- c:\documents and settings\Receptionen\Application Data\OpenOffice.org
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-18 18:15 . 2010-12-10 17:10 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-12 17:53 . 2010-12-12 18:55 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-12 15:34 . 2010-12-12 18:55 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-11-09 14:52 . 2004-08-27 12:00 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:23 . 2004-08-27 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:23 . 2004-08-27 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2010-11-06 00:23 . 2004-08-27 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25 . 2004-08-27 12:00 385024 ----a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2004-08-27 12:00 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:08 . 2004-08-27 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:58 . 2004-08-27 12:00 1853312 ----a-w- c:\windows\system32\win32k.sys
2010-10-19 09:41 . 2010-12-11 23:24 222080 ------w- c:\windows\system32\MpSigStub.exe
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\programmer\Fælles filer\Java\Java Update\jusched.exe" [2010-05-14 248552]
"ccApp"="c:\programmer\Fælles filer\Symantec Shared\ccApp.exe" [2010-12-21 115560]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Receptionen\Menuen Start\Programmer\Start\
OpenOffice.org 3.2.lnk - c:\programmer\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\Symantec\\Symantec Endpoint Protection\\Smc.exe"=
"c:\\Programmer\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"=
"c:\\Programmer\\Fælles filer\\Symantec Shared\\ccApp.exe"=
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\programmer\Fælles filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [21-12-2010 15:22 102448]
.
Indhold af mappen 'Planlagte Opgaver'
2011-01-14 c:\windows\Tasks\User_Feed_Synchronization-{1B3C4557-ECA4-4DB8-9D65-E9B443E97636}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
.
------- Yderligere scanning -------
.
uStart Page = hxxp://www.google.dk/
.
- - - - TOMME GENVEJE FJERNET - - - -
HKU-Default-Run-DWQueuedReporting - c:\progra~1\FLLESF~1\MICROS~1\DW\dwtrig20.exe
SafeBoot-Symantec Antvirus
MSConfigStartUp-Registry Reviver - c:\programmer\Reviversoft\Registry Reviver\RegistryReviver.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-14 17:39
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs startet under kørende Processer ---------------------
- - - - - - - > 'explorer.exe'(2560)
c:\windows\system32\webcheck.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\programmer\Symantec\Symantec Endpoint Protection\Smc.exe
c:\windows\system32\WgaTray.exe
c:\programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
c:\programmer\Symantec\Symantec Endpoint Protection\SescLU.exe
c:\programmer\Java\jre6\bin\jqs.exe
c:\programmer\Symantec\Symantec Endpoint Protection\Rtvscan.exe
c:\programmer\OpenOffice.org 3\program\soffice.exe
c:\programmer\OpenOffice.org 3\program\soffice.bin
.
**************************************************************************
.
Gennemført tid: 2011-01-14 17:39:58 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2011-01-14 16:39
Pre-Kørsel: 74.210.295.808 byte ledig
Post-Kørsel: 74.193.235.968 byte ledig
- - End Of File - - C3989943CC61CCB20CC8A892CC59AB50
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:01:51, on 14-01-2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\Programmer\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Programmer\Fælles filer\Java\Java Update\jusched.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\Programmer\OpenOffice.org 3\program\soffice.exe
C:\Programmer\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\explorer.exe
C:\Programmer\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Documents and Settings\Receptionen\Dokumenter\PC doktor\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmer\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Fælles filer\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Programmer\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1292001851093
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: BrSplService (Brother XP spl Service) - Unknown owner - C:\WINDOWS\system32\brsvc01a.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmer\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Programmer\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Programmer\Symantec\Symantec Endpoint Protection\Rtvscan.exe
--
End of file - 4249 bytes