Avatar billede sezam Nybegynder
23. september 2007 - 18:38 Der er 31 kommentarer og
1 løsning

Vira og en trojan horse. Please kig min Hijack igennem.

Min PC er inficeret med ét eller andet halløj - deriblandt en fil med navnet vtr.dll som ikke kan slettes.

Her er en hijackthis-log: Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 18:18:14, on 23-09-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccProxy.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\Programmer\Norton Internet Security\ISSVC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\printer.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Programmer\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\WkUFind.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programmer\iTunes 6\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Documents and Settings\John Doe\Skrivebord\HiJackThis_v2.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\printer.exe
O2 - BHO: IEHlprObj Class - {ABCDECF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\system32\vtr.dll (file missing)
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programmer\Fælles filer\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Programmer\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Zone Labs Client] C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes 6\iTunesHelper.exe"
O4 - HKLM\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe
O4 - HKLM\..\Run: [mav_startupmon] "C:\Programmer\Fælles filer\WinAntiVirus Pro 2007\mav_startupmon.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: system.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = ?
O4 - Global Startup: autorun.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.bgbank.dk/html/activex/e-Safekey/BG/e-Safekey.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\systems.txt
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Programmer\Norton Internet Security\ISSVC.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Programmer\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Programmer\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FLLESF~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SmartLinkService (SLService) -  - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 8609 bytes
Avatar billede arlet Juniormester
23. september 2007 - 18:41 #1
kigger nu
Avatar billede arlet Juniormester
23. september 2007 - 18:44 #2
Ja, du har et par kedelige nogen..

Kør trin 1 og 2 her http://www.malwarecheck.dk/forum/viewtopic.php?t=11
Genstart og hijackthis log samt log´ne fra SuperAntiSpyware scanneren og Avg/Ewido
Avatar billede sezam Nybegynder
23. september 2007 - 18:46 #3
ok - går igang nu...
Avatar billede arlet Juniormester
23. september 2007 - 18:49 #4
Den nye hijackthis log, som jeg får vil jeg gerne have at du følger denne vejledning: http://www.malwarecheck.dk/forum/viewtopic.php?t=9 , så er det nemlig nyeste version
Avatar billede fromsej Praktikant
23. september 2007 - 19:08 #5
Arlet >> Undskyld jeg bliver ved, men seneste udvikling er at nu kan vi sq ikke engang stole på "File missing" i O2 linierne mere, MØGDYR!!!(Altså ikke dig*G*)
Avatar billede pbj_dk Nybegynder
23. september 2007 - 19:22 #6
Prøv http://dk.trendmicro-europe.com/consumer/housecall/housecall_launch.php - den kan vidt nok æde dem der on-line. Samtidig skal du opdatere din HiJackThis. Den du har er for gammel, da den ikke har handles med. Du kan hente den her http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php?page=download

Post så en ny log :-)
Avatar billede arlet Juniormester
23. september 2007 - 19:33 #7
fromsej-> Jeg ved du gør det i en god mening, så jeg suger til mig, men denne her vtr.dll lyder som en grim banan..
Avatar billede pbj_dk Nybegynder
23. september 2007 - 19:45 #8
-> Arlet. Jeps, og det er en af dem der ved genstart automatisk omdøber sig selv. vtr"xxx".dll f.eks vtr001.dll
Der skal scannes i fejlsikret tilstand. Prøv http://www.trendmicro.com/download/dcs.asp . TSC clean up ( kører rent "dos" i startup )
- og ja- jeg er TrendMicro fan, ligesom Microsoft ( MSN HotMail) ;-)
Avatar billede fromsej Praktikant
23. september 2007 - 20:01 #9
TrendMicro online snupper ikke det her:
WinAntiVirus Pro 2007, WinAvXX.exe, printer.exe bl.a
Jeg vil sige Combofix.
Avatar billede pbj_dk Nybegynder
23. september 2007 - 20:05 #10
Lyder fornuftigt. De er også ganske sej-livede, normalt fjerner jeg dem manuelt - jeg "trækker" mig ;-)
Avatar billede arlet Juniormester
23. september 2007 - 20:07 #11
Fromsej, du skal nok få din combofix bagefter*G*
Avatar billede sezam Nybegynder
25. september 2007 - 21:00 #12
Jeg har fulgt dine anvisninger Arlet + forsøgt mig med onlinescanner på http://dk.trendmicro-europe.com/consumer/housecall/housecall_launch.php

Nedenfor følger 3 logs fra SUPERAntiSpyware, EWIDO og HiJackThis...

NB: Rootchk.exe fik IKKE lov at køre
Avatar billede sezam Nybegynder
25. september 2007 - 21:01 #13
LOG FRA SUPERAntiSpyware:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/23/2007 at 07:01 PM

Application Version : 3.9.1008

Core Rules Database Version : 3311
Trace Rules Database Version: 1315

Scan type      : Quick Scan
Total Scan Time : 00:09:53

Memory items scanned      : 396
Memory threats detected  : 1
Registry items scanned    : 888
Registry threats detected : 45
File items scanned        : 11190
File threats detected    : 28

Trojan.Net-AVP/AVT
    C:\WINDOWS\SYSTEM32\PRINTER.EXE
    C:\WINDOWS\SYSTEM32\PRINTER.EXE
    [WinAVX] C:\WINDOWS\SYSTEM32\WINAVXX.EXE
    C:\WINDOWS\SYSTEM32\WINAVXX.EXE
    [WinAVX] C:\WINDOWS\SYSTEM32\WINAVXX.EXE
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run#WinAVX [ C:\WINDOWS\system32\WinAvXX.exe ]
    HKU\S-1-5-21-2631753031-1854951905-1770227178-1007\Software\Microsoft\Windows\CurrentVersion\Run#WinAVX [ C:\WINDOWS\system32\WinAvXX.exe ]
    C:\DOCUMENTS AND SETTINGS\ALL USERS\MENUEN START\PROGRAMMER\START\AUTORUN.EXE
    C:\DOCUMENTS AND SETTINGS\John Doe\MENUEN START\PROGRAMMER\START\SYSTEM.EXE
    C:\WINDOWS\Prefetch\PRINTER.EXE-0E099EB1.pf
    C:\WINDOWS\Prefetch\SYSTEM.EXE-1090BD69.pf
    C:\WINDOWS\Prefetch\WINAVXX.EXE-050EF48B.pf

Trojan.Net-VTROLL
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ABCDECF0-4B15-11D1-ABED-709549C10000}
    HKCR\CLSID\{ABCDECF0-4B15-11D1-ABED-709549C10000}
    HKCR\CLSID\{ABCDECF0-4B15-11D1-ABED-709549C10000}
    HKCR\CLSID\{ABCDECF0-4B15-11D1-ABED-709549C10000}\InprocServer32
    HKCR\CLSID\{ABCDECF0-4B15-11D1-ABED-709549C10000}\InprocServer32#ThreadingModel
    HKCR\CLSID\{ABCDECF0-4B15-11D1-ABED-709549C10000}\InprocServer32#Enable Browser Extensions
    HKCR\CLSID\{ABCDECF0-4B15-11D1-ABED-709549C10000}\ProgID
    HKCR\CLSID\{ABCDECF0-4B15-11D1-ABED-709549C10000}\Programmable
    HKCR\CLSID\{ABCDECF0-4B15-11D1-ABED-709549C10000}\VersionIndependentProgID
    C:\WINDOWS\SYSTEM32\VTR.DLL

Adware.Tracking Cookie
    C:\Documents and Settings\John Doe\Cookies\John_Doe@tribalfusion[1].txt
    C:\Documents and Settings\John Doe\Cookies\John_Doe@adtech[2].txt
    C:\Documents and Settings\John Doe\Cookies\John_Doe@doubleclick[2].txt
    C:\Documents and Settings\John Doe\Cookies\John_Doe@mediaplex[1].txt
    C:\Documents and Settings\John Doe\Cookies\John_Doe@track.adform[1].txt
    C:\Documents and Settings\John Doe\Cookies\John_Doe@statse.webtrendslive[2].txt

Trojan.WinAntiSpyware/WinAntiVirus 2006/2007
    HKCR\IEFWBHO.IEFW
    HKCR\IEFWBHO.IEFW\CLSID
    HKCR\IEFWBHO.IEFW\CurVer
    HKCR\IEFWBHO.IEFW.2
    HKCR\IEFWBHO.IEFW.2\CLSID
    HKCR\TypeLib\{2BC32EF8-BB73-4099-BB2E-0F2951B3E276}
    HKCR\TypeLib\{2BC32EF8-BB73-4099-BB2E-0F2951B3E276}\1.0
    HKCR\TypeLib\{2BC32EF8-BB73-4099-BB2E-0F2951B3E276}\1.0\0
    HKCR\TypeLib\{2BC32EF8-BB73-4099-BB2E-0F2951B3E276}\1.0\0\win32
    HKCR\TypeLib\{2BC32EF8-BB73-4099-BB2E-0F2951B3E276}\1.0\FLAGS
    HKCR\TypeLib\{2BC32EF8-BB73-4099-BB2E-0F2951B3E276}\1.0\HELPDIR
    HKU\S-1-5-21-2631753031-1854951905-1770227178-1007\Software\WinAntiVirus Pro 2007
    HKCR\UWAP7.PCheck.1
    HKCR\UWAP7.PCheck.1\CurVer
    HKCR\CLSID\{2A5C2E6D-864B-4f2c-9542-8B272741D78B}
    HKCR\CLSID\{2A5C2E6D-864B-4f2c-9542-8B272741D78B}\InprocServer32
    HKCR\CLSID\{2A5C2E6D-864B-4f2c-9542-8B272741D78B}\InprocServer32#ThreadingModel
    HKCR\CLSID\{2A5C2E6D-864B-4f2c-9542-8B272741D78B}\ProgID
    HKCR\CLSID\{2A5C2E6D-864B-4f2c-9542-8B272741D78B}\Programmable
    HKCR\CLSID\{2A5C2E6D-864B-4f2c-9542-8B272741D78B}\VersionIndependentProgID
    HKCR\TypeLib\{6F520BE0-9B54-4558-816F-224E67997DF3}
    HKCR\TypeLib\{6F520BE0-9B54-4558-816F-224E67997DF3}\1.0
    HKCR\TypeLib\{6F520BE0-9B54-4558-816F-224E67997DF3}\1.0\0
    HKCR\TypeLib\{6F520BE0-9B54-4558-816F-224E67997DF3}\1.0\0\win32
    HKCR\TypeLib\{6F520BE0-9B54-4558-816F-224E67997DF3}\1.0\FLAGS
    HKCR\TypeLib\{6F520BE0-9B54-4558-816F-224E67997DF3}\1.0\HELPDIR
    HKCR\Interface\{459F4226-1AAB-43B6-9DC1-B6313EF83749}
    HKCR\Interface\{459F4226-1AAB-43B6-9DC1-B6313EF83749}\ProxyStubClsid
    HKCR\Interface\{459F4226-1AAB-43B6-9DC1-B6313EF83749}\ProxyStubClsid32
    HKCR\Interface\{459F4226-1AAB-43B6-9DC1-B6313EF83749}\TypeLib
    HKCR\Interface\{459F4226-1AAB-43B6-9DC1-B6313EF83749}\TypeLib#Version
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run#mav_startupmon [ "C:\Programmer\Fælles filer\WinAntiVirus Pro 2007\mav_startupmon.exe" ]
    C:\WINDOWS\system32\stera.job
    C:\Documents and Settings\John Doe\Application Data\WinAntiVirus Pro 2007\avtasks.dat
    C:\Documents and Settings\John Doe\Application Data\WinAntiVirus Pro 2007\CookieList.dat
    C:\Documents and Settings\John Doe\Application Data\WinAntiVirus Pro 2007\Logs\update.log
    C:\Documents and Settings\John Doe\Application Data\WinAntiVirus Pro 2007\Logs\wa7Support.log
    C:\Documents and Settings\John Doe\Application Data\WinAntiVirus Pro 2007\Logs\winav.log
    C:\Documents and Settings\John Doe\Application Data\WinAntiVirus Pro 2007\Logs
    C:\Documents and Settings\John Doe\Application Data\WinAntiVirus Pro 2007\PGE.dat
    C:\Documents and Settings\John Doe\Application Data\WinAntiVirus Pro 2007
    C:\Programmer\Fælles filer\WinAntiVirus Pro 2007\err.log
    C:\Programmer\Fælles filer\WinAntiVirus Pro 2007\mfc71.dll
    C:\Programmer\Fælles filer\WinAntiVirus Pro 2007\msvcp71.dll
    C:\Programmer\Fælles filer\WinAntiVirus Pro 2007\msvcr71.dll
    C:\Programmer\Fælles filer\WinAntiVirus Pro 2007
Avatar billede sezam Nybegynder
25. september 2007 - 21:02 #14
LOG FRA EWIDO:

__________________________________________________
ewido anti-spyware online scanner
    http://www.ewido.net
__________________________________________________


Name: TrackingCookie.Adtech
Path: C:\Documents and Settings\John Doe\Cookies\John_Doe@adtech[2].txt
Risk: Medium

Name: TrackingCookie.Doubleclick
Path: C:\Documents and Settings\John Doe\Cookies\John_Doe@doubleclick[1].txt
Risk: Medium

Name: TrackingCookie.Mediaplex
Path: C:\Documents and Settings\John Doe\Cookies\John_Doe@mediaplex[1].txt
Risk: Medium

Name: TrackingCookie.Live
Path: C:\Documents and Settings\John Doe\Cookies\John_Doe@search.live[1].txt
Risk: Medium

Name: TrackingCookie.Statistik-gallup
Path: C:\Documents and Settings\John Doe\Cookies\John_Doe@statistik-gallup[1].txt
Risk: Medium

Name: TrackingCookie.Myaffiliateprogram
Path: C:\Documents and Settings\John Doe\Cookies\John_Doe@www.myaffiliateprogram[2].txt
Risk: Medium

Name: Adware.CoolWebSearch
Path: HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj
Risk: Medium

Name: Adware.CoolWebSearch
Path: HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer
Risk: Medium

Name: Adware.CoolWebSearch
Path: HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1
Risk: Medium

Name: Adware.Trymedia
Path: C:\Downloads\XingMahjonggSetup-dm[1].exe
Risk: Medium

Name: Adware.Companion
Path: C:\System Volume Information\_restore{3F430932-5C0A-4B6C-AF89-CF531FE59AE9}\RP115\A0013868.dll
Risk: Medium

Name: Adware.SystemDoctor
Path: C:\System Volume Information\_restore{3F430932-5C0A-4B6C-AF89-CF531FE59AE9}\RP115\A0013870.exe
Risk: Medium

Name: Not-A-Virus.Downloader.Win32.WinFixer.o
Path: C:\System Volume Information\_restore{3F430932-5C0A-4B6C-AF89-CF531FE59AE9}\RP115\A0013883.exe
Risk: Low

Name: Not-A-Virus.Downloader.Win32.WinFixer.x
Path: C:\System Volume Information\_restore{3F430932-5C0A-4B6C-AF89-CF531FE59AE9}\RP115\A0013886.exe
Risk: Low

Name: Not-A-Virus.Downloader.Win32.WinFixer.o
Path: C:\System Volume Information\_restore{3F430932-5C0A-4B6C-AF89-CF531FE59AE9}\RP115\A0013913.exe
Risk: Low
Avatar billede sezam Nybegynder
25. september 2007 - 21:02 #15
LOG FRA HIJACKTHIS:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:52:07, on 25-09-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programmer\Fælles filer\Symantec Shared\ccProxy.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\Programmer\Norton Internet Security\ISSVC.exe
C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Programmer\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\WkUFind.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programmer\iTunes 6\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\HJTrenamed.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
F2 - REG:system.ini: Shell=Explorer.exe
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programmer\Fælles filer\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Programmer\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Zone Labs Client] C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes 6\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.bgbank.dk/html/activex/e-Safekey/BG/e-Safekey.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\systems.txt
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Programmer\Norton Internet Security\ISSVC.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Programmer\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Programmer\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FLLESF~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SmartLinkService (SLService) -  - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 8087 bytes
Avatar billede arlet Juniormester
25. september 2007 - 21:05 #16
Det hjalp gevaldigt på det, men der er mere tilbage..

Hent Combofix, og gem den på dit skrivebord:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Kør så combofix.exe, og følg vejledningen i vinduet.

Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når combofix er færdig, og efter det har genstartet, skulle der gerne åbnes en logfil: combofix.txt som kan findes her-C:\combofix.txt

Kopier loggen her ind.
Avatar billede sezam Nybegynder
25. september 2007 - 21:09 #17
pokkers.....jeg får ikke lov at køre combofix - jeg får en eller anden kedelig meddelelse op. Konstant! Skal jeg prøve at køre programmet i fejlsikret tilstand ?
Avatar billede sezam Nybegynder
25. september 2007 - 21:11 #18
hov 2 sek...nu sker der vist noget.
Avatar billede arlet Juniormester
25. september 2007 - 21:14 #19
DEt lyder godt
Avatar billede sezam Nybegynder
25. september 2007 - 21:35 #20
Here u go!

ComboFix 07-09-21.2 - "JOHN DOE" 2007-09-25 21:23:36.1 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1030.18.627 [GMT 2:00]
* Created a new restore point
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007\Data\ActivationCode
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007\Data\ProductCode
C:\DOCUME~1\JOHNDOE~1\err.log
C:\DOCUME~1\JOHNDOE~1\ResErrors.log
C:\WINDOWS\system32\stera.log

.
(((((((((((((((((((((((((((((((((((((((  Drivers/Services  )))))))))))))))))))))))))))))))))))))))))))))))))


-------\LEGACY_FOPN


(((((((((((((((((((((((((  Files Created from 2007-08-25 to 2007-09-25  )))))))))))))))))))))))))))))))
.

2007-09-25 21:08    51,200    --a------    C:\WINDOWS\NirCmd.exe
2007-09-23 19:54    <DIR>    d--------    C:\DOCUME~1\JOHNDOE~1\.housecall6.6
2007-09-23 19:45    401,720    --a------    C:\Programmer\HJTrenamed.exe
2007-09-23 18:49    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2007-09-23 18:49    <DIR>    d--------    C:\DOCUME~1\JOHNDOE~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-23 18:49    <DIR>    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-23 18:48    <DIR>    d--------    C:\Programmer\F‘lles filer\Wise Installation Wizard
2007-09-20 07:57    15,090    --a------    C:\WINDOWS\progq.exe
2007-09-06 20:27    <DIR>    d--hs----    C:\UWA7PK
2007-09-06 18:41    8,704    --a------    C:\WINDOWS\system32\SpOrder.dll

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-25 20:52    8088    --a------    C:\Programmer\hijackthis.log
2007-09-23 17:49    ---------    d--------    C:\Programmer\Norton Internet Security
2007-09-19 22:12    ---------    d--------    C:\DOCUME~1\JOHNDOE~1\APPLIC~1\Skype
2007-09-17 19:58    ---------    d--------    C:\DOCUME~1\JOHNDOE~1\APPLIC~1\AdobeUM
    ---------        C:\Programmer\Fælles filer\Wise Installation Wizard
    ---------        C:\Programmer\Fælles filer\Symantec Shared
    ---------        C:\Programmer\Fælles filer
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-06-10 22:10]
"SynTPLpr"="C:\Programmer\Synaptics\SynTP\SynTPLpr.exe" [2004-05-07 11:49]
"SynTPEnh"="C:\Programmer\Synaptics\SynTP\SynTPEnh.exe" [2004-05-07 11:49]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 17:46]
"HP Software Update"="C:\Programmer\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-18 19:55]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"Microsoft Works Update Detection"="C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\WkUFind.exe" []
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-04-20 19:00]
"ccApp"="C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe" []
"Zone Labs Client"="C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe" [2006-02-19 18:27]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Programmer\iTunes 6\iTunesHelper.exe" [2007-07-10 09:18]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 14:00]

C:\DOCUME~1\ALLUSE~1\MENUEN~1\PROGRA~1\Start\
Adobe Gamma Loader.exe.lnk - C:\Programmer\F‘lles filer\Adobe\Calibration\Adobe Gamma Loader.exe [2005-11-20 21:15:15]
Microsoft Office.lnk - C:\Programmer\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders    msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
"C:\Programmer\HP\hpcoretech\hpcmpmgr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ImInstaller_IncrediMail]

C:\DOCUME~1\JOHNDOE~1\LOKALE~1\Temp\ImInstaller\IncrediMail\incredimail_install[1].exe -startup -product IncrediMail

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Programmer\iTunes 6\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Programmer\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Programmer\MSN Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Programmer\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Programmer\Java\j2re1.4.2_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Programmer\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe]
C:\Programmer\Norton Internet Security\UrlLstCk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XingMahjonggSetup.exe]
C:\DOWNLO~1\XINGMA~1.EXE /r

R2 Automatisk LiveUpdate-planlægning;Automatisk LiveUpdate-planlægning;"C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe"
R3 CONAN;CONAN;C:\WINDOWS\system32\drivers\o2mmb.sys
S3 camvid20;Philips ToUcam Camera; Video;C:\WINDOWS\system32\DRIVERS\camdrv21.sys
S3 MbxStby;MbxStby;C:\WINDOWS\system32\drivers\MbxStby.sys
S4 viaagp;VIA AGP-busfilter;C:\WINDOWS\system32\DRIVERS\viaagp.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-09-14 18:24:18 C:\WINDOWS\Tasks\Norton AntiVirus - Skan Denne computer - JOHN DOE.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-25 21:31:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-25 21:32:40 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-25 21:32
.
    --- E O F ---
Avatar billede arlet Juniormester
25. september 2007 - 21:44 #21
Der var ikke meget tilbage..

Kopiér indholdet mellem de stiplede linier ind i et notepad-vindue, og gem indholdet i samme mappe, som Combofix ligger med navnet CFScript.txt.
Når du gemmer, skal du sikre, at der under "filtyper" står "alle filer".

-------------------------

File::

C:\WINDOWS\progq.exe
C:\DOCUME~1\JOHNDOE~1\.housecall6.6

-------------------------

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen. - http://www.fromsej.saknet.dk/billeder/cfscript.gif
Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.

Kopier indholdet af Combofix.txt her ind.
Avatar billede sezam Nybegynder
25. september 2007 - 21:55 #22
Sådan...

ComboFix 07-09-21.2 - "JOHN DOE" 2007-09-25 21:51:58.2 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1030.18.673 [GMT 2:00]
Command switches used ::  C:\CFScript.txt
* Created a new restore point

FILE::
C:\WINDOWS\progq.exe
C:\DOCUME~1\JOHNDOE~1\.housecall6.6
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\progq.exe

.
(((((((((((((((((((((((((  Files Created from 2007-08-25 to 2007-09-25  )))))))))))))))))))))))))))))))
.

2007-09-25 21:08    51,200    --a------    C:\WINDOWS\NirCmd.exe
2007-09-23 19:54    <DIR>    d--------    C:\DOCUME~1\JOHNDOE~1\.housecall6.6
2007-09-23 19:45    401,720    --a------    C:\Programmer\HJTrenamed.exe
2007-09-23 18:49    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2007-09-23 18:49    <DIR>    d--------    C:\DOCUME~1\JOHNDOE~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-23 18:49    <DIR>    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-23 18:48    <DIR>    d--------    C:\Programmer\F‘lles filer\Wise Installation Wizard
2007-09-06 20:27    <DIR>    d--hs----    C:\UWA7PK
2007-09-06 18:41    8,704    --a------    C:\WINDOWS\system32\SpOrder.dll

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-25 20:52    8088    --a------    C:\Programmer\hijackthis.log
2007-09-23 17:49    ---------    d--------    C:\Programmer\Norton Internet Security
2007-09-19 22:12    ---------    d--------    C:\DOCUME~1\JOHNDOE~1\APPLIC~1\Skype
2007-09-17 19:58    ---------    d--------    C:\DOCUME~1\JOHNDOE~1\APPLIC~1\AdobeUM
2007-07-30 19:19    92504    --a------    C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 19:19    92504    --a------    C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19    549720    --a------    C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19    549720    --a------    C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-30 19:19    53080    --a------    C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19    53080    --a------    C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 19:19    43352    --a------    C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19    325976    --a------    C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19    325976    --a------    C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-30 19:19    203096    --a------    C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19    203096    --a------    C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-30 19:19    1712984    --a------    C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:19    1712984    --a------    C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 19:18    33624    --a------    C:\WINDOWS\system32\wups.dll
2007-07-30 19:18    33624    --a------    C:\WINDOWS\system32\dllcache\wups.dll
2007-07-19 08:58    3583488    --a------    C:\WINDOWS\system32\dllcache\mshtml.dll
2007-07-13 01:31    765952    --a------    C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-27 16:05    823808    --a------    C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-27 16:05    671232    --a------    C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-27 16:05    6058496    ---------    C:\WINDOWS\system32\dllcache\ieframe.dll
2007-06-27 16:05    52224    ---------    C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-06-27 16:05    477696    --a------    C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-27 16:05    459264    ---------    C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-06-27 16:05    44544    --a------    C:\WINDOWS\system32\dllcache\iernonce.dll
2007-06-27 16:05    27648    --a------    C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-27 16:05    267776    ---------    C:\WINDOWS\system32\dllcache\iertutil.dll
2007-06-27 16:05    232960    --a------    C:\WINDOWS\system32\dllcache\webcheck.dll
2007-06-27 16:05    193024    --a------    C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-27 16:05    1152000    --a------    C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-27 16:05    105984    --a------    C:\WINDOWS\system32\dllcache\url.dll
2007-06-27 16:05    102400    --a------    C:\WINDOWS\system32\dllcache\occache.dll
2007-06-27 16:04    384512    --a------    C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-06-27 16:04    383488    ---------    C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-06-27 16:04    230400    --a------    C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-06-27 16:04    153088    --a------    C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-06-27 16:04    132608    --a------    C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-27 16:04    124928    --a------    C:\WINDOWS\system32\dllcache\advpack.dll
2007-06-27 10:27    63488    --a------    C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-06-27 10:27    13824    ---------    C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-06-27 10:25    625152    --a------    C:\WINDOWS\system32\dllcache\iexplore.exe
2007-06-27 09:00    161792    --a------    C:\WINDOWS\system32\dllcache\ieakui.dll
2007-06-26 08:10    1104896    --a------    C:\WINDOWS\system32\msxml3.dll
2007-06-26 08:10    1104896    --a------    C:\WINDOWS\system32\dllcache\msxml3.dll
    ---------        C:\Programmer\Fælles filer\Wise Installation Wizard
    ---------        C:\Programmer\Fælles filer\Symantec Shared
    ---------        C:\Programmer\Fælles filer
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-06-10 22:10]
"SynTPLpr"="C:\Programmer\Synaptics\SynTP\SynTPLpr.exe" [2004-05-07 11:49]
"SynTPEnh"="C:\Programmer\Synaptics\SynTP\SynTPEnh.exe" [2004-05-07 11:49]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 17:46]
"HP Software Update"="C:\Programmer\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-18 19:55]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"Microsoft Works Update Detection"="C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\WkUFind.exe" []
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-04-20 19:00]
"ccApp"="C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe" []
"Zone Labs Client"="C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe" [2006-02-19 18:27]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Programmer\iTunes 6\iTunesHelper.exe" [2007-07-10 09:18]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 14:00]

C:\DOCUME~1\ALLUSE~1\MENUEN~1\PROGRA~1\Start\
Adobe Gamma Loader.exe.lnk - C:\Programmer\F‘lles filer\Adobe\Calibration\Adobe Gamma Loader.exe [2005-11-20 21:15:15]
Microsoft Office.lnk - C:\Programmer\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders    msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
"C:\Programmer\HP\hpcoretech\hpcmpmgr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ImInstaller_IncrediMail]

C:\DOCUME~1\JOHNDOE~1\LOKALE~1\Temp\ImInstaller\IncrediMail\incredimail_install[1].exe -startup -product IncrediMail

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Programmer\iTunes 6\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Programmer\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Programmer\MSN Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Programmer\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Programmer\Java\j2re1.4.2_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Programmer\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe]
C:\Programmer\Norton Internet Security\UrlLstCk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XingMahjonggSetup.exe]
C:\DOWNLO~1\XINGMA~1.EXE /r

R2 Automatisk LiveUpdate-planlægning;Automatisk LiveUpdate-planlægning;"C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe"
R3 CONAN;CONAN;C:\WINDOWS\system32\drivers\o2mmb.sys
S3 camvid20;Philips ToUcam Camera; Video;C:\WINDOWS\system32\DRIVERS\camdrv21.sys
S3 MbxStby;MbxStby;C:\WINDOWS\system32\drivers\MbxStby.sys
S4 viaagp;VIA AGP-busfilter;C:\WINDOWS\system32\DRIVERS\viaagp.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-09-14 18:24:18 C:\WINDOWS\Tasks\Norton AntiVirus - Skan Denne computer - JOHN DOE.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-25 21:53:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-25 21:53:58
C:\ComboFix-quarantined-files.txt ... 2007-09-25 21:53
C:\ComboFix2.txt ... 2007-09-25 21:32
.
    --- E O F ---
Avatar billede arlet Juniormester
25. september 2007 - 21:58 #23
Ja, den ene fil ville den ikke slette.. Vi prøver igen.

Kopiér indholdet mellem de stiplede linier ind i et notepad-vindue, og gem indholdet i samme mappe, som Combofix ligger med navnet CFScript.txt.
Når du gemmer, skal du sikre, at der under "filtyper" står "alle filer".

-------------------------

File::
C:\DOCUME~1\JOHNDOE~1\.housecall6.6

-------------------------

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen. - http://www.fromsej.saknet.dk/billeder/cfscript.gif
Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.

Kopier indholdet af Combofix.txt her ind.
Avatar billede sezam Nybegynder
25. september 2007 - 22:06 #24
Så prøver igen...

ComboFix 07-09-21.2 - "JOHN DOE" 2007-09-25 22:04:30.3 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1030.18.661 [GMT 2:00]
Command switches used ::  C:\Documents and Settings\JOHN DOE\Skrivebord\viruslort\CFScript.txt
* Created a new restore point

FILE::
C:\DOCUME~1\JOHNDOE~1\.housecall6.6
.

(((((((((((((((((((((((((  Files Created from 2007-08-25 to 2007-09-25  )))))))))))))))))))))))))))))))
.

2007-09-25 21:08    51,200    --a------    C:\WINDOWS\NirCmd.exe
2007-09-23 19:54    <DIR>    d--------    C:\DOCUME~1\JOHNDOE~1\.housecall6.6
2007-09-23 19:45    401,720    --a------    C:\Programmer\HJTrenamed.exe
2007-09-23 18:49    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2007-09-23 18:49    <DIR>    d--------    C:\DOCUME~1\JOHNDOE~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-23 18:49    <DIR>    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-23 18:48    <DIR>    d--------    C:\Programmer\F‘lles filer\Wise Installation Wizard
2007-09-06 20:27    <DIR>    d--hs----    C:\UWA7PK
2007-09-06 18:41    8,704    --a------    C:\WINDOWS\system32\SpOrder.dll

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-25 20:52    8088    --a------    C:\Programmer\hijackthis.log
2007-09-23 17:49    ---------    d--------    C:\Programmer\Norton Internet Security
2007-09-19 22:12    ---------    d--------    C:\DOCUME~1\JOHNDOE~1\APPLIC~1\Skype
2007-09-17 19:58    ---------    d--------    C:\DOCUME~1\JOHNDOE~1\APPLIC~1\AdobeUM
2007-07-30 19:19    92504    --a------    C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 19:19    92504    --a------    C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19    549720    --a------    C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19    549720    --a------    C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-30 19:19    53080    --a------    C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19    53080    --a------    C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 19:19    43352    --a------    C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19    325976    --a------    C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19    325976    --a------    C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-30 19:19    203096    --a------    C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19    203096    --a------    C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-30 19:19    1712984    --a------    C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:19    1712984    --a------    C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 19:18    33624    --a------    C:\WINDOWS\system32\wups.dll
2007-07-30 19:18    33624    --a------    C:\WINDOWS\system32\dllcache\wups.dll
2007-07-19 08:58    3583488    --a------    C:\WINDOWS\system32\dllcache\mshtml.dll
2007-07-13 01:31    765952    --a------    C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-27 16:05    823808    --a------    C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-27 16:05    671232    --a------    C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-27 16:05    6058496    ---------    C:\WINDOWS\system32\dllcache\ieframe.dll
2007-06-27 16:05    52224    ---------    C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-06-27 16:05    477696    --a------    C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-27 16:05    459264    ---------    C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-06-27 16:05    44544    --a------    C:\WINDOWS\system32\dllcache\iernonce.dll
2007-06-27 16:05    27648    --a------    C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-27 16:05    267776    ---------    C:\WINDOWS\system32\dllcache\iertutil.dll
2007-06-27 16:05    232960    --a------    C:\WINDOWS\system32\dllcache\webcheck.dll
2007-06-27 16:05    193024    --a------    C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-27 16:05    1152000    --a------    C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-27 16:05    105984    --a------    C:\WINDOWS\system32\dllcache\url.dll
2007-06-27 16:05    102400    --a------    C:\WINDOWS\system32\dllcache\occache.dll
2007-06-27 16:04    384512    --a------    C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-06-27 16:04    383488    ---------    C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-06-27 16:04    230400    --a------    C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-06-27 16:04    153088    --a------    C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-06-27 16:04    132608    --a------    C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-27 16:04    124928    --a------    C:\WINDOWS\system32\dllcache\advpack.dll
2007-06-27 10:27    63488    --a------    C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-06-27 10:27    13824    ---------    C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-06-27 10:25    625152    --a------    C:\WINDOWS\system32\dllcache\iexplore.exe
2007-06-27 09:00    161792    --a------    C:\WINDOWS\system32\dllcache\ieakui.dll
2007-06-26 08:10    1104896    --a------    C:\WINDOWS\system32\msxml3.dll
2007-06-26 08:10    1104896    --a------    C:\WINDOWS\system32\dllcache\msxml3.dll
    ---------        C:\Programmer\Fælles filer\Wise Installation Wizard
    ---------        C:\Programmer\Fælles filer\Symantec Shared
    ---------        C:\Programmer\Fælles filer
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-06-10 22:10]
"SynTPLpr"="C:\Programmer\Synaptics\SynTP\SynTPLpr.exe" [2004-05-07 11:49]
"SynTPEnh"="C:\Programmer\Synaptics\SynTP\SynTPEnh.exe" [2004-05-07 11:49]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 17:46]
"HP Software Update"="C:\Programmer\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-18 19:55]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"Microsoft Works Update Detection"="C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\WkUFind.exe" []
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-04-20 19:00]
"ccApp"="C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe" []
"Zone Labs Client"="C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe" [2006-02-19 18:27]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Programmer\iTunes 6\iTunesHelper.exe" [2007-07-10 09:18]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 14:00]

C:\DOCUME~1\ALLUSE~1\MENUEN~1\PROGRA~1\Start\
Adobe Gamma Loader.exe.lnk - C:\Programmer\F‘lles filer\Adobe\Calibration\Adobe Gamma Loader.exe [2005-11-20 21:15:15]
Microsoft Office.lnk - C:\Programmer\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders    msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
"C:\Programmer\HP\hpcoretech\hpcmpmgr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ImInstaller_IncrediMail]

C:\DOCUME~1\JOHNDOE~1\LOKALE~1\Temp\ImInstaller\IncrediMail\incredimail_install[1].exe -startup -product IncrediMail

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Programmer\iTunes 6\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Programmer\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Programmer\MSN Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Programmer\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Programmer\Java\j2re1.4.2_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Programmer\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe]
C:\Programmer\Norton Internet Security\UrlLstCk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XingMahjonggSetup.exe]
C:\DOWNLO~1\XINGMA~1.EXE /r

R2 Automatisk LiveUpdate-planlægning;Automatisk LiveUpdate-planlægning;"C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe"
R3 CONAN;CONAN;C:\WINDOWS\system32\drivers\o2mmb.sys
S3 camvid20;Philips ToUcam Camera; Video;C:\WINDOWS\system32\DRIVERS\camdrv21.sys
S3 MbxStby;MbxStby;C:\WINDOWS\system32\drivers\MbxStby.sys
S4 viaagp;VIA AGP-busfilter;C:\WINDOWS\system32\DRIVERS\viaagp.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-09-14 18:24:18 C:\WINDOWS\Tasks\Norton AntiVirus - Skan Denne computer - JOHN DOE.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-25 22:05:03
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-25 22:05:36
C:\ComboFix-quarantined-files.txt ... 2007-09-25 22:05
C:\ComboFix2.txt ... 2007-09-25 21:53
C:\ComboFix3.txt ... 2007-09-25 21:32
.
    --- E O F ---
Avatar billede fromsej Praktikant
25. september 2007 - 22:12 #25
Det er en mappe.*S*
2007-09-23 19:54  >> <DIR> <<  d--------    C:\DOCUME~1\JOHNDOE~1\.housecall6.

-------------------------

Folder::
C:\DOCUME~1\JOHNDOE~1\.housecall6.6

-------------------------
Avatar billede sezam Nybegynder
25. september 2007 - 22:26 #26
Here we go:

ComboFix 07-09-21.2 - "JOHN DOE" 2007-09-25 22:19:33.4 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1030.18.652 [GMT 2:00]
Command switches used ::  C:\Documents and Settings\JOHN DOE\Skrivebord\viruslort\CFScript.txt
* Created a new restore point
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\DOCUME~1\JOHNDOE~1\.housecall6.6
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\8ball.txt
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\AU_Log\TmuDump.txt
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\aucfg.ini
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\BPMNT.dll
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\ciussi32.dll
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\dsvout.dll
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\engine.stat
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\getMac.exe
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\GetServer.ini
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\jsapi.dll
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\jupdate.dll
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\local.conf
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\log\2007-09-23-19-53-41.infections
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\log\2007-09-25-19-46-16.infections
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\log\dsvout.log
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\log\engine0.log
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\log\engine0.log.lck
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\log\error0.log
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\log\error0.log.lck
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\log\execution0.log
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\log\execution0.log.lck
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\patch.exe
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\PATCHW32.DLL
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\Pattern\lpt$vpn.733
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\Pattern\lpt$vpn.737
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\Pattern\tmaptn.535
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\Pattern\tmvamain.ptn
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\Pattern\tsc.ptn
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\ssapi32.dll
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\ssapiptn.da5
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\tmcomm.sys
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\TmEngDrv.dll
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\TmUpdate.dll
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\tsc.exe
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\Update\AU_Cache\eu-housecall.trendmicro-europe.com\ini_xml.zip
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\Update\AU_Cache\eu-housecall.trendmicro-europe.com\ini_xml.zip.etag
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\Update\AU_Cache\eu-housecall.trendmicro-europe.com\server.ini
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\Update\AU_Cache\eu-housecall.trendmicro-europe.com\server.ini.etag
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\usrbl.dat
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\usrwl.dat
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\vsapi32.dll
C:\DOCUME~1\JOHNDOE~1\.housecall6.6\vscan.dat

.
(((((((((((((((((((((((((  Files Created from 2007-08-25 to 2007-09-25  )))))))))))))))))))))))))))))))
.

2007-09-25 21:08    51,200    --a------    C:\WINDOWS\NirCmd.exe
2007-09-23 19:45    401,720    --a------    C:\Programmer\HJTrenamed.exe
2007-09-23 18:49    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2007-09-23 18:49    <DIR>    d--------    C:\DOCUME~1\JOHNDOE~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-23 18:49    <DIR>    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-23 18:48    <DIR>    d--------    C:\Programmer\F‘lles filer\Wise Installation Wizard
2007-09-06 20:27    <DIR>    d--hs----    C:\UWA7PK
2007-09-06 18:41    8,704    --a------    C:\WINDOWS\system32\SpOrder.dll

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-25 22:09    ---------    d--------    C:\DOCUME~1\JOHNDOE~1\APPLIC~1\Skype
2007-09-25 20:52    8088    --a------    C:\Programmer\hijackthis.log
2007-09-23 17:49    ---------    d--------    C:\Programmer\Norton Internet Security
2007-09-17 19:58    ---------    d--------    C:\DOCUME~1\JOHNDOE~1\APPLIC~1\AdobeUM
    ---------        C:\Programmer\Fælles filer\Wise Installation Wizard
    ---------        C:\Programmer\Fælles filer\Symantec Shared
    ---------        C:\Programmer\Fælles filer
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-06-10 22:10]
"SynTPLpr"="C:\Programmer\Synaptics\SynTP\SynTPLpr.exe" [2004-05-07 11:49]
"SynTPEnh"="C:\Programmer\Synaptics\SynTP\SynTPEnh.exe" [2004-05-07 11:49]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 17:46]
"HP Software Update"="C:\Programmer\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-18 19:55]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"Microsoft Works Update Detection"="C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\WkUFind.exe" []
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-04-20 19:00]
"ccApp"="C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe" []
"Zone Labs Client"="C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe" [2006-02-19 18:27]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Programmer\iTunes 6\iTunesHelper.exe" [2007-07-10 09:18]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 14:00]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders    msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
"C:\Programmer\HP\hpcoretech\hpcmpmgr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ImInstaller_IncrediMail]

C:\DOCUME~1\JOHNDOE~1\LOKALE~1\Temp\ImInstaller\IncrediMail\incredimail_install[1].exe -startup -product IncrediMail

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Programmer\iTunes 6\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Programmer\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Programmer\MSN Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Programmer\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Programmer\Java\j2re1.4.2_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Programmer\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe]
C:\Programmer\Norton Internet Security\UrlLstCk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XingMahjonggSetup.exe]
C:\DOWNLO~1\XINGMA~1.EXE /r

R2 Automatisk LiveUpdate-planlægning;Automatisk LiveUpdate-planlægning;"C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe"
R3 CONAN;CONAN;C:\WINDOWS\system32\drivers\o2mmb.sys
S3 camvid20;Philips ToUcam Camera; Video;C:\WINDOWS\system32\DRIVERS\camdrv21.sys
S3 MbxStby;MbxStby;C:\WINDOWS\system32\drivers\MbxStby.sys
S4 viaagp;VIA AGP-busfilter;C:\WINDOWS\system32\DRIVERS\viaagp.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-09-14 18:24:18 C:\WINDOWS\Tasks\Norton AntiVirus - Skan Denne computer - JOHN DOE.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-25 22:22:22
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-25 22:25:58 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-25 22:25
C:\ComboFix2.txt ... 2007-09-25 22:05
C:\ComboFix3.txt ... 2007-09-25 21:53
.
    --- E O F ---
Avatar billede arlet Juniormester
26. september 2007 - 07:16 #27
SÅDAN, der nakkede vi den..

Loggen er ren.. 

Hjalp kuren??

Kør lige trin 5 og 6 herfra: http://www.malwarecheck.dk/forum/viewtopic.php?t=11

Her kan du læse om vores skudsikre sikkerhedspakke: http://www.malwarecheck.dk/forum/viewtopic.php?t=156 . Hvis du har nogle spørgsmål, så spørger du bare..
Avatar billede arlet Juniormester
26. september 2007 - 07:19 #28
Og mange tak(igen) til fromsej. Ja, det er øjnene... osv..
Avatar billede pbj_dk Nybegynder
26. september 2007 - 08:22 #29
-->> arlet. Nu ville jeg lige se, hvad den der Combo fix var for noget ( kendte den ikke) .
Ahhhm, http://download.bleepingcomputer.com/sUBs/ComboFix.exe er inficeret med FREELOADER_SMITFRAUD i filen dumphive.cfexe – se http://www.trendmicro.com/vinfo/grayware/ve_graywareDetails.asp?GNAME=FREELOADER%5FSMITFRAUD
OK, grayware men alligevel? Burde man ikke fortælle bleepingcomputer det? Eller er den bare en del af pakken, fordi den er gratis? Min TM "flejede" helt ud over den.
Avatar billede ejvindh Ekspert
26. september 2007 - 14:35 #30
@pbj_dk: Det er en falsk positiv, som vi desværre ser jævnligt. Det er ikke Bleepingcomputer, men dit antivirus-firma, der skal informeres.
Avatar billede sezam Nybegynder
26. september 2007 - 22:20 #31
Arlet - det hele spiller! Super hjælp - fedt :-)
Avatar billede arlet Juniormester
27. september 2007 - 07:02 #32
Velbekommen..

Og tak for inputtet fra Ejvindh ;-)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester