Efter at ha' kæmpet en kamp om at kunne komme på nettet har jeg endelig fået mit net til at virke igen.. aner seriøst ikk hvad der sker med den her comp lige pt.. :S nårh men her er de 3 logs.. håber I kan hjælpe mig viddere herfra...
Drweb scan:
Total session statistics
=============================================================================
Objects scanned: 116229
Infected objects found: 9
Objects with modifications found: 0
Suspicious objects found: 0
Adware programs found: 0
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 3
Hacktool programs found: 1
Objects cured: 0
Objects deleted: 8
Objects renamed: 4
Objects moved: 0
Objects ignored: 0
Scan speed: 284 Kb/s
Scan time: 00:56:41
---------------
---------------------------------------------------------
ewido anti-malware - Scanningsrapport
---------------------------------------------------------
+ Oprettet den: 13:29:26, 07-04-2006
+ Rapport-Checksum: D8B77F59
+ Scanningsresultat:
[1580] C:\WINDOWS\system32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
[272] C:\WINDOWS\system32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
[308] C:\WINDOWS\system32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
[320] C:\WINDOWS\system32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
[324] C:\WINDOWS\system32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
[340] C:\WINDOWS\system32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
[476] C:\WINDOWS\system32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
[608] C:\WINDOWS\system32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
[652] C:\WINDOWS\system32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
[696] C:\WINDOWS\system32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
[712] C:\WINDOWS\system32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
[1092] C:\WINDOWS\system32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
[1124] C:\WINDOWS\System32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
[1208] C:\WINDOWS\system32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
[1304] C:\WINDOWS\system32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
[1300] C:\WINDOWS\System32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
[2664] C:\WINDOWS\system32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
[2736] C:\WINDOWS\system32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
[4088] C:\WINDOWS\system32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
[436] C:\WINDOWS\system32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
[540] C:\WINDOWS\system32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
[5456] C:\WINDOWS\system32\xptptt.dll -> Backdoor.Haxdoor.hs : Fejl under renselse
::Rapport slut
-----------------
Logfile of HijackThis v1.99.1
Scan saved at 13:33:03, on 07-04-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
D:\Programmer\Virus\Avast Virus Cleaner\aswUpdSv.exe
D:\PROGRA~1\Virus\AVASTV~1\ashDisp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Svm M\Skrivebord\WindowsBlinds\Sysmetrix\SysMetrix.exe
C:\WINDOWS\system32\devldr32.exe
D:\Programmer\Virus\Avast Virus Cleaner\ashServ.exe
D:\Programmer\Motherboard Monitor 5\MBM5.EXE
C:\Programmer\TGTSoft\StyleXP\StyleXP.exe
C:\Programmer\CursorXP\CursorXP.exe
D:\Programmer\Virus\Ewido\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Programmer\Rainlendar\Rainlendar.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Svm M\Skrivebord\YahooWidgets\WidgetEngine\YahooWidgetEngine.exe
C:\WINDOWS\System32\wdfmgr.exe
D:\Programmer\Virus\Avast Virus Cleaner\ashMaiSv.exe
D:\Programmer\Virus\Avast Virus Cleaner\ashWebSv.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Svm M\Skrivebord\aiepk.exe
D:\Programmer\Speedfan\speedfan.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
D:\Programmer\Virus\Adware fix\Hijackthis\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = /4.3.10
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = /4.3.10
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = /4.3.10
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = /4.3.10
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = /4.3.10
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = /4.3.10
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = /4.3.10
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = /4.3.10
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\Virus\ADWARE~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] D:\PROGRA~1\Virus\AVASTV~1\ashDisp.exe
O4 - HKLM\..\Run: [SysMetrix] C:\Documents and Settings\Svm M\Skrivebord\WindowsBlinds\Sysmetrix\SysMetrix.exe
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\Programmer\Stardock\WinCustomize\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [MBM 5] "D:\Programmer\Motherboard Monitor 5\MBM5.EXE"
O4 - HKCU\..\Run: [STYLEXP] C:\Programmer\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [CursorXP] "C:\Programmer\CursorXP\CursorXP.exe" -s
O4 - HKCU\..\Run: [WinMedia] C:\DOCUME~1\SVMM~1\LOKALE~1\Temp\3B.tmp3584.exe
O4 - Startup: Rainlendar.lnk = C:\Programmer\Rainlendar\Rainlendar.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Documents and Settings\Svm M\Skrivebord\YahooWidgets\WidgetEngine\YahooWidgetEngine.exe
O8 - Extra context menu item: &Download with &DAP - .\dapextie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\PROGRA~1\Virus\HITMAN~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cabO16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.trendmicro.com/housecall/xscan60.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=48835O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cabO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: ,wbsys.dll
O20 - Winlogon Notify: SensSrv - C:\WINDOWS\SYSTEM32\senssrv.dll
O20 - Winlogon Notify: WBSrv - C:\DOCUME~1\SVMM~1\SKRIVE~1\WINDOW~1\WINDOW~1\wbsrv.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O20 - Winlogon Notify: xptptt - C:\WINDOWS\SYSTEM32\xptptt.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\Programmer\Virus\Avast Virus Cleaner\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - D:\Programmer\Virus\Avast Virus Cleaner\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - D:\Programmer\Virus\Avast Virus Cleaner\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - D:\Programmer\Virus\Avast Virus Cleaner\ashWebSv.exe" /service (file missing)
O23 - Service: ewido security suite control - ewido networks - D:\Programmer\Virus\Ewido\ewido anti-malware\ewidoctrl.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - D:\Programmer\Virus\Hitmanpro\Spyware Doctor\sdhelp.exe
O23 - Service: StyleXPService - Unknown owner - C:\Programmer\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Programmer\Webroot\Spy Sweeper\WRSSSDK.exe