Avatar billede mickeyz Nybegynder
16. februar 2008 - 13:23 Der er 6 kommentarer og
1 løsning

Kan nogen lige hjælpe mig med en HIJACKTHIS log

Logfile of HijackThis v1.99.1
Scan saved at 13:20:05, on 16-02-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\NetProject\scit.exe
C:\Programmer\NetProject\sbmntr.exe
C:\Programmer\D-Tools\daemon.exe
C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe
C:\Programmer\Creative\Shared Files\CamTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\NetProject\scm.exe
C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmer\NetProject\sbsm.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Documents and Settings\Dennis og Kristian\Skrivebord\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: e404 helper - {8BD4438C-2511-4B93-AD34-2BDCD0FF78D2} - C:\Programmer\Helper\1203031620.dll
O2 - BHO: (no name) - {C2A1C5CB-C0EF-4689-9436-F62CCA1C5383} - C:\Programmer\NetProject\sbmdl.dll
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmer\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Programmer\Creative\Shared Files\CamTray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [CrazyCoinsSetup.exe] C:\DOWNLO~1\CRAZYC~1.EXE /r
O4 - HKCU\..\Run: [GemShopSetup.exe] C:\DOWNLO~1\GEMSHO~1.EXE /r
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.explorertool.net/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.explorertool.net/redirect.php (file missing)
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3820FDCB-C09E-430A-8D73-5DA2A61A89D4}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{F59EB07C-E584-407D-9720-D9469CE59B40}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{FC02E7C2-22AC-4994-ACBF-BD7609C3319F}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\..\{3820FDCB-C09E-430A-8D73-5DA2A61A89D4}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
16. februar 2008 - 14:38 #1
Hvad er det du har liggende i mappen
C:\DOWNLO~1\
???

O4 - HKCU\..\Run: [CrazyCoinsSetup.exe] C:\DOWNLO~1\CRAZYC~1.EXE /r
O4 - HKCU\..\Run: [GemShopSetup.exe] C:\DOWNLO~1\GEMSHO~1.EXE /r

------------------------

... Nu er det ikke alle (u)ønskede elementer som viser sig med en HiJackThis Log; så gennemfør proceduren herfra -> http://www.eksperten.dk/artikler/1123
Avatar billede mickeyz Nybegynder
16. februar 2008 - 14:59 #2
Det var noget mærkeligt noget, små dumme spil, de er slettet nu. jeg går simpelthen i gang med proceduren...
16. februar 2008 - 15:11 #3
... det er/var nok nogle 'spil' med lidt extra Uønsket i pakken !!!
Avatar billede mickeyz Nybegynder
16. februar 2008 - 16:18 #4
Her kommer lige alle logs


--Hijackthislog--:

Logfile of HijackThis v1.99.1
Scan saved at 15:50:56, on 16-02-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\D-Tools\daemon.exe
C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe
C:\Programmer\Creative\Shared Files\CamTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Documents and Settings\Dennis og Kristian\Skrivebord\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmer\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Programmer\Creative\Shared Files\CamTray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3820FDCB-C09E-430A-8D73-5DA2A61A89D4}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{F59EB07C-E584-407D-9720-D9469CE59B40}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{FC02E7C2-22AC-4994-ACBF-BD7609C3319F}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\..\{3820FDCB-C09E-430A-8D73-5DA2A61A89D4}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe





--Rootchk--

********************************* ROOTCHK-(28-12-07)-LOG, by ejvindh
16-02-2008 15:52:37,81

NOTICE!! Rootchk is not being updated anymore, and is thus gradually getting outdated.
Last update was made 28-12-07

The rootkits that are detected by this tool were not found.

********************************* ROOTCHK-LOG-end


catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-16 15:52:55
Windows 5.1.2600 Service Pack 2
detected NTDLL code modification:
ZwQueryDirectoryFile
scanning hidden processes ...
IPC error: 2 Den angivne fil blev ikke fundet.

detected NTDLL code modification:
ZwQueryDirectoryFile
scanning hidden services & system hive ...
IPC error: 2 Den angivne fil blev ikke fundet.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d346prt\Cfg\0Jf40]

detected NTDLL code modification:
ZwQueryDirectoryFile
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{56CA5D3B-3002-4E7B-90FE-071D8FDF3814}]
"DisplayName"="DAEMON Tools"

detected NTDLL code modification:
ZwQueryDirectoryFile
scanning hidden files ...
IPC error: 2 Den angivne fil blev ikke fundet.

hidden processes: 0
hidden services: 0
hidden files: 0



--Combofix log--




ComboFix 08-02-16.2 - Dennis og Kristian 2008-02-16 15:58:38.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1030.18.408 [GMT 1:00]
Running from: C:\Documents and Settings\Dennis og Kristian\Skrivebord\ATTACK\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Programmer\Helper
C:\Programmer\Helper\1203031620.dll
C:\WINDOWS\new.exe
C:\WINDOWS\system32\info.txt
C:\WINDOWS\system32\kdkol.exe

.
(((((((((((((((((((((((((((((((((((((((  Drivers/Services  )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\nm


(((((((((((((((((((((((((  Files Created from 2008-01-16 to 2008-02-16  )))))))))))))))))))))))))))))))
.

2008-02-16 15:12 . 2008-02-16 15:23    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2008-02-16 15:12 . 2008-02-16 15:12    <DIR>    d--------    C:\Documents and Settings\Dennis og Kristian\Application Data\SUPERAntiSpyware.com
2008-02-16 15:12 . 2008-02-16 15:12    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-16 15:11 .     <DIR>        C:\Programmer\Fælles filer\Wise Installation Wizard
2008-02-16 15:03 . 2008-02-16 15:03    <DIR>    d--------    C:\Programmer\CCleaner
2008-02-15 19:56 . 2008-02-15 19:56    <DIR>    d--------    C:\Program Files
2008-02-15 18:48 . 2008-02-15 18:48    <DIR>    d--------    C:\Programmer\Spybot - Search & Destroy
2008-02-15 18:48 . 2008-02-15 19:37    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-15 17:29 . 2008-02-15 17:29    <DIR>    d--------    C:\Programmer\HP
2008-02-15 17:26 . 2004-08-03 23:01    25,856    --a------    C:\WINDOWS\system32\drivers\usbprint.sys
2008-02-15 17:26 . 2004-08-03 23:01    25,856    --a--c---    C:\WINDOWS\system32\dllcache\usbprint.sys
2008-02-15 00:26 . 2008-02-15 11:09    <DIR>    d--------    C:\Programmer\NetProject
2008-02-14 14:21 . 2008-02-14 14:21    <DIR>    d--------    C:\Documents and Settings\Dennis og Kristian\Application Data\iLike
2008-02-04 19:26 . 2007-03-08 00:51    129,784    ---------    C:\WINDOWS\system32\pxafs.dll
2008-02-04 19:26 . 2007-03-08 00:51    9,464    ---------    C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-02-04 19:26 . 2007-03-08 00:51    9,336    ---------    C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-01-30 14:11 . 2007-09-24 23:31    69,632    --a------    C:\WINDOWS\system32\javacpl.cpl
2008-01-20 21:33 . 2008-01-20 21:33    268    --ah-----    C:\sqmdata13.sqm
2008-01-20 21:33 . 2008-01-20 21:33    244    --ah-----    C:\sqmnoopt13.sqm
2008-01-20 14:52 . 2008-01-20 14:52    268    --ah-----    C:\sqmdata12.sqm
2008-01-20 14:52 . 2008-01-20 14:52    244    --ah-----    C:\sqmnoopt12.sqm

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-16 14:48    ---------    d-----w    C:\Documents and Settings\Dennis og Kristian\Application Data\Skype
2008-02-15 15:01    ---------    d-----w    C:\Programmer\Google
2008-02-15 14:59    ---------    d-----w    C:\Programmer\Windows Live Toolbar
2008-02-15 14:56    ---------    d--h--w    C:\Programmer\InstallShield Installation Information
2008-02-15 14:55    ---------    d-----w    C:\Programmer\EA Games
2008-02-15 14:52    ---------    d-----w    C:\Programmer\F1 Racing Championship - Demo
2008-02-15 14:51    ---------    d-----w    C:\Programmer\Codemasters
2008-01-30 20:07    ---------    d-----w    C:\Programmer\Fælles filer\Adobe
2008-01-30 20:02    ---------    d-----w    C:\Documents and Settings\Dennis og Kristian\Application Data\AdobeUM
2008-01-30 13:11    ---------    d-----w    C:\Programmer\Java
2008-01-16 16:15    ---------    d-----w    C:\Programmer\Fælles filer\Symantec Shared
2008-01-15 19:42    ---------    d-----w    C:\Programmer\Alwil Software
2008-01-15 19:37    ---------    d-----w    C:\Programmer\Symantec
2008-01-15 19:28    ---------    d-----w    C:\Programmer\Norton SystemWorks
2008-01-15 19:26    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-11 21:31    49    ----a-w    C:\tmp.bat
2008-01-08 14:44    ---------    d-----w    C:\Programmer\Fox
2008-01-07 14:09    ---------    d-----w    C:\Programmer\Fælles filer\InstallShield
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-26 17:53 15360]
"MsnMsgr"="C:\Programmer\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:55 5674352]
"Skype"="C:\Programmer\Skype\Phone\Skype.exe" [2006-06-26 14:53 20005928]
"SpybotSD TeaTimer"="C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-04-23 15:46 1318128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools-1033"="C:\Programmer\D-Tools\daemon.exe" [2004-03-12 22:43 81920]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Creative WebCam Tray"="C:\Programmer\Creative\Shared Files\CamTray.exe" [2003-10-13 03:04 184320]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-07-28 13:19 4841472]
"nwiz"="nwiz.exe" [2003-07-28 13:19 323584 C:\WINDOWS\system32\nwiz.exe]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-26 17:53 15360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

R0 d346bus;d346bus;C:\WINDOWS\system32\DRIVERS\d346bus.sys [2004-03-12 22:41]
R0 d346prt;d346prt;C:\WINDOWS\system32\Drivers\d346prt.sys [2004-03-12 22:41]
R3 P1120VID;Creative WebCam NX Ultra;C:\WINDOWS\system32\DRIVERS\P1120Vid.sys [2004-01-12 09:51]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-16 16:08:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
.
**************************************************************************
.
Completion time: 2008-02-16 16:11:33 - machine was rebooted
ComboFix-quarantined-files.txt  2008-02-16 15:11:14
.
2008-02-15 21:40:14    --- E O F --- 


-- Superantispy--


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/16/2008 at 03:32 PM

Application Version : 3.7.1018

Core Rules Database Version : 3404
Trace Rules Database Version: 1396

Scan type      : Complete Scan
Total Scan Time : 00:08:14

Memory items scanned      : 190
Memory threats detected  : 0
Registry items scanned    : 4902
Registry threats detected : 51
File items scanned        : 3548
File threats detected    : 59

Trojan.Media-Codec/V4
    HKLM\Software\Classes\CLSID\{C2A1C5CB-C0EF-4689-9436-F62CCA1C5383}
    HKCR\CLSID\{C2A1C5CB-C0EF-4689-9436-F62CCA1C5383}
    HKCR\CLSID\{C2A1C5CB-C0EF-4689-9436-F62CCA1C5383}#xxx
    HKCR\CLSID\{C2A1C5CB-C0EF-4689-9436-F62CCA1C5383}\InprocServer32
    HKCR\CLSID\{C2A1C5CB-C0EF-4689-9436-F62CCA1C5383}\InprocServer32#ThreadingModel
    C:\PROGRAMMER\NETPROJECT\SBMDL.DLL

Trojan.Smitfraud Variant/IE Anti-Spyware
    HKLM\Software\Microsoft\Internet Explorer\Extensions\{9034A523-D068-4BE8-A284-9DF278BE776E}

Trojan.DNSChanger-Codec
    HKCR\CLSID\E404.e404mgr
    HKCR\CLSID\E404.e404mgr#UserId

Rogue.AdvancedCleaner
    HKLM\Software\AdvancedCleaner Free
    HKLM\Software\AdvancedCleaner Free#EULA Accepted
    HKLM\Software\AdvancedCleaner Free#Installer TotalSize
    HKLM\Software\AdvancedCleaner Free#InstallDate
    HKLM\Software\AdvancedCleaner Free#ProductCode
    HKLM\Software\AdvancedCleaner Free#Abbr
    HKLM\Software\AdvancedCleaner Free#InstallPath
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UADC_is1
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UADC_is1#Inno Setup: Setup Version
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UADC_is1#Inno Setup: App Path
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UADC_is1#InstallLocation
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UADC_is1#Inno Setup: Icon Group
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UADC_is1#Inno Setup: User
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UADC_is1#Inno Setup: Selected Tasks
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UADC_is1#Inno Setup: Deselected Tasks
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UADC_is1#DisplayName
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UADC_is1#UninstallString
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UADC_is1#QuietUninstallString
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UADC_is1#Publisher
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UADC_is1#URLInfoAbout
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UADC_is1#HelpLink
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UADC_is1#URLUpdateInfo
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UADC_is1#NoModify
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UADC_is1#NoRepair
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UADC_is1#InstallDate
    C:\Programmer\AdvancedCleaner Free\acu.dat
    C:\Programmer\AdvancedCleaner Free\appAct.dat
    C:\Programmer\AdvancedCleaner Free\AppDB\AppBase.xml
    C:\Programmer\AdvancedCleaner Free\AppDB\profiles.dat
    C:\Programmer\AdvancedCleaner Free\AppDB\prowords.dat
    C:\Programmer\AdvancedCleaner Free\AppDB
    C:\Programmer\AdvancedCleaner Free\appv.dat
    C:\Programmer\AdvancedCleaner Free\atl71.dll
    C:\Programmer\AdvancedCleaner Free\img\button.gif
    C:\Programmer\AdvancedCleaner Free\img\button2.gif
    C:\Programmer\AdvancedCleaner Free\img\header.gif
    C:\Programmer\AdvancedCleaner Free\img\logo.gif
    C:\Programmer\AdvancedCleaner Free\img\spacer.gif
    C:\Programmer\AdvancedCleaner Free\img\top1.jpg
    C:\Programmer\AdvancedCleaner Free\img\top2.jpg
    C:\Programmer\AdvancedCleaner Free\img\top_line.gif
    C:\Programmer\AdvancedCleaner Free\img
    C:\Programmer\AdvancedCleaner Free\InstStat.exe
    C:\Programmer\AdvancedCleaner Free\lapv.dat
    C:\Programmer\AdvancedCleaner Free\license.rtf
    C:\Programmer\AdvancedCleaner Free\manual.url
    C:\Programmer\AdvancedCleaner Free\mfc71.dll
    C:\Programmer\AdvancedCleaner Free\msvcp71.dll
    C:\Programmer\AdvancedCleaner Free\msvcr71.dll
    C:\Programmer\AdvancedCleaner Free\naglinks.dat
    C:\Programmer\AdvancedCleaner Free\readme.rtf
    C:\Programmer\AdvancedCleaner Free\req.dat
    C:\Programmer\AdvancedCleaner Free\request.dat
    C:\Programmer\AdvancedCleaner Free\support.url
    C:\Programmer\AdvancedCleaner Free\transformer.dat
    C:\Programmer\AdvancedCleaner Free\UADC.exe
    C:\Programmer\AdvancedCleaner Free\UADC.exe.manifest
    C:\Programmer\AdvancedCleaner Free\UADC.url
    C:\Programmer\AdvancedCleaner Free\UADC.xml
    C:\Programmer\AdvancedCleaner Free\UADCcw.exe
    C:\Programmer\AdvancedCleaner Free\unins000.dat
    C:\Programmer\AdvancedCleaner Free\unins000.exe
    C:\Programmer\AdvancedCleaner Free\uninstall.ico
    C:\Programmer\AdvancedCleaner Free\UninstallPage.html
    C:\Programmer\AdvancedCleaner Free\upser.dat
    C:\Programmer\AdvancedCleaner Free
    C:\Documents and Settings\All Users\Menuen Start\Programmer\AdvancedCleaner Free\AdvancedCleaner HomePage.lnk
    C:\Documents and Settings\All Users\Menuen Start\Programmer\AdvancedCleaner Free\AdvancedCleaner Online Manual.lnk
    C:\Documents and Settings\All Users\Menuen Start\Programmer\AdvancedCleaner Free\AdvancedCleaner Online Support.lnk
    C:\Documents and Settings\All Users\Menuen Start\Programmer\AdvancedCleaner Free\AdvancedCleaner.lnk
    C:\Documents and Settings\All Users\Menuen Start\Programmer\AdvancedCleaner Free\Uninstall AdvancedCleaner.lnk
    C:\Documents and Settings\All Users\Menuen Start\Programmer\AdvancedCleaner Free
    C:\WINDOWS\Prefetch\INSTSTAT.EXE-103E5B31.pf

Adware.E404 Helper/Hij
    HKCR\E404.e404mgr
    HKCR\E404.e404mgr\CLSID
    HKCR\E404.e404mgr\CurVer
    HKCR\E404.e404mgr.1
    HKCR\E404.e404mgr.1\CLSID
    HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}
    HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}\1.0
    HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}\1.0\0
    HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}\1.0\0\win32
    HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}\1.0\FLAGS
    HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}\1.0\HELPDIR
    HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}
    HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}\ProxyStubClsid
    HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}\ProxyStubClsid32
    HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}\TypeLib
    HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}\TypeLib#Version

Rogue.Files-Secure
    HKCR\AppId\sysosa.dll
    HKCR\AppId\sysosa.dll#AppID
    C:\Programmer\Files-Secure\secure.db1
    C:\Programmer\Files-Secure\secure.db2
    C:\Programmer\Files-Secure\secure.db3
    C:\Programmer\Files-Secure\secure.db4
    C:\Programmer\Files-Secure\secure.db5
    C:\Programmer\Files-Secure\secure.exe
    C:\Programmer\Files-Secure\Uninstall.exe
    C:\Programmer\Files-Secure
    C:\Documents and Settings\Dennis og Kristian\Menuen Start\Programmer\Files Secure 2.1.lnk
    C:\WINDOWS\Prefetch\UNINSTALL.EXE-0CB01A05.pf
16. februar 2008 - 16:41 #5
... dermed fixet en del elementer af ovenstående programmer *BINGO*

Hvordan kører PC'en så nu ?

Ta' en tur med CCleaner som du allerede har (Specielt punktet [Register]...)
Avatar billede mickeyz Nybegynder
16. februar 2008 - 17:13 #6
meget bedre, men skal der ikke slettes noget i hijackthis?
17. februar 2008 - 16:04 #7
Nope ... Den har systemet klaret "automatisk"  ...

Der er ikke mere 'snavs' ifølge din Log...
Du er velkommen en anden gang...

Du bør rense temp med denne fil, det tager kun få sek.
http://www.spywareinfo.dk/download/cleantempxp2k.bat

Efter sådan en tur er det altid en god ide og rydde op i systemgendannelsesfilerne.
Deaktiver systemgendannelse -> http://www.spywareinfo.dk/#/tip-og-tricks/deaktiver_systemgendannelse.htm
Genstart din computer - aktiver systemgendannelse. Dette gøres samme sted, hvor du deaktiverede, denne gang skal du blot aktivere.
Det vil også være en god idé manuelt at oprette et nyt punkt, som du kan navngive, og vende tilbage til, hvis du skulle få problemer af nogen art.

Et par artikler om sikker surfing finder du her:
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=14414

Safe Surfing...
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester