Avatar billede sharder Nybegynder
24. marts 2008 - 19:12 Der er 2 kommentarer

IEDEFENDER - Hvordan kommer jeg af med det

Hej
Jeg har nu i et par dage kæmpet med at komme af med dette IEdefender problem, men uden held. Jeg har både prøvet omtalte fremgangsmåder fra her på eksperten og diverse andre sider, men selvom jeg har fjernet alt det jeg kan finde vedbliver problemet -jeg har både prøvet at fjerne manuelt og med programmer som jeg har læst skulle virke (adaware, superantispyware, xoftSPY og spyhunter)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:01:57, on 24-03-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Sikkerhed\AdAware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\Java\jre1.6.0_01\bin\jusched.exe
C:\SIKKER~1\AVG\avgcc.exe
C:\Sikkerhed\Startup Mechanic\StartupMonitor.exe
C:\Documents and Settings\SHJ\Menuen Start\Programmer\Start\iexplore.exe
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Sikkerhed\Trend HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Media Player Classic - {D2A8552D-4340-413E-B94E-245827FBC269} - C:\WINDOWS\ausctv32a.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [AVG7_CC] C:\SIKKER~1\AVG\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Startup Manager Scanner] C:\Sikkerhed\Startup Mechanic\StartupMonitor.exe
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\SIKKER~1\AVG\avgw.exe /RUNONCE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\SIKKER~1\AVG\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\SIKKER~1\AVG\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: iexplore.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Opret Foretrukken på den mobile enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O20 - Winlogon Notify: !SASWinLogon - C:\Sikkerhed\SuperAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Sikkerhed\AdAware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\SIKKER~1\AVG\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\SIKKER~1\AVG\avgupsvc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Programmer\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Programmer\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programmer\Fælles filer\Sony Shared\AVLib\SPTISRV.exe

--
End of file - 5823 bytes

Jeg er ved at gå i spåner, hvad gør jeg?
Avatar billede johnstigers Seniormester
24. marts 2008 - 20:13 #1
Hent dette program: http://www.ctrlaltdel.dk/SWF_hent.exe og gem det på skrivebordet. Herefter dobbeltklikker du på det (SWF_hent.exe). Du skal måske tillade programmet at hente filer fra nettet!

Programmet henter nødvendige rense-programmer. Når programmerne er hentet, vil der være en mappe på skrivebordet med navnet "Spywarefri". Heri ligger programmerne sammen med en kort vejledning - hvis vejledningen ikke åbner automatisk så dobbeltklik på "SWF_vejledning.html".

Venligst følg vejledningen og kopier logfilerne herind.

(Lånt af http://www.spywarefri.dk/forum/links/hjtanv.htm)
Avatar billede sharder Nybegynder
24. marts 2008 - 23:48 #2
Således, der er dog et problem, når jeg går i fejlsikret tilstand kan jeg ikke gøre noget - systemet starter bare op med sort skærm som musen kan bevæges rundt over, så scanningen er foretaget i normal tilstand.

Tak for den foreløbige hjælp! :)


---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at:    23:31:26 24-03-2008

+ Scan result:   



C:\System Volume Information\_restore{BA609036-0027-4825-A132-F434590B8E0F}\RP287\A0736313.dll -> Adware.BHO : Cleaned.
C:\System Volume Information\_restore{BA609036-0027-4825-A132-F434590B8E0F}\RP288\A0736494.dll -> Adware.BHO : Cleaned.
C:\System Volume Information\_restore{BA609036-0027-4825-A132-F434590B8E0F}\RP289\A0739630.dll -> Adware.BHO : Cleaned.
C:\System Volume Information\_restore{BA609036-0027-4825-A132-F434590B8E0F}\RP256\A0652217.dll -> Adware.Casino : Cleaned.
C:\System Volume Information\_restore{BA609036-0027-4825-A132-F434590B8E0F}\RP287\A0736314.dll -> Adware.VB : Cleaned.
C:\System Volume Information\_restore{BA609036-0027-4825-A132-F434590B8E0F}\RP287\A0736315.exe -> Adware.VB : Cleaned.
C:\System Volume Information\_restore{BA609036-0027-4825-A132-F434590B8E0F}\RP288\A0736495.dll -> Adware.VB : Cleaned.
C:\System Volume Information\_restore{BA609036-0027-4825-A132-F434590B8E0F}\RP288\A0736496.exe -> Adware.VB : Cleaned.
C:\System Volume Information\_restore{BA609036-0027-4825-A132-F434590B8E0F}\RP288\A0736638.exe -> Adware.VB : Cleaned.
C:\WINDOWS\system32\wmidext.dll -> Adware.VB : Cleaned.
C:\Programmer\StartUp Organizer\so.exe -> Backdoor.Huai : Cleaned.
C:\Documents and Settings\SHJ\Lokale indstillinger\Temp\G09GAUBJ.dll -> Logger.Agent.aan : Cleaned.
C:\Entertainment\Incoming\activation code for spyhunter new.zip/setup.exe -> Not-A-Virus.Adware.BHO : Cleaned.
C:\System Volume Information\_restore{BA609036-0027-4825-A132-F434590B8E0F}\RP285\A0736189.exe -> Not-A-Virus.Adware.BHO : Cleaned.
C:\System Volume Information\_restore{BA609036-0027-4825-A132-F434590B8E0F}\RP287\A0736332.exe -> Not-A-Virus.Adware.BHO : Cleaned.
C:\System Volume Information\_restore{BA609036-0027-4825-A132-F434590B8E0F}\RP288\A0736513.exe -> Not-A-Virus.Adware.BHO : Cleaned.
C:\Documents and Settings\SHJ\Cookies\shj@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\SHJ\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-24-2008 - 13-58-26\{0DE37436-9FA0-41E3-B0B2-4A6B39A40C67} -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\SHJ\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-24-2008 - 13-58-26\{A5C55539-6F7A-4818-A4D7-FE68309A78D3} -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\SHJ\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-24-2008 - 13-58-26\{ECEEEABD-F29D-4344-96FB-92879A96B1F6} -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\SHJ\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-24-2008 - 13-58-26\{555E6C18-AF9C-4348-8658-E002DCE04CEB} -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\SHJ\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-24-2008 - 13-58-26\{796149D1-C51A-4929-9E79-A7067223EDC0} -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\SHJ\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-24-2008 - 13-58-26\{1F40ECD1-AEA9-4F12-B77E-EA85B5660CE2} -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\SHJ\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-24-2008 - 13-58-26\{D368B12E-B547-4E5F-A064-7CED14E661F2} -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\SHJ\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-24-2008 - 13-58-26\{8665B755-3AF6-4C76-9241-FB54903149F1} -> TrackingCookie.Clickbank : Cleaned.
C:\Documents and Settings\SHJ\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-24-2008 - 13-58-26\{065696C9-3061-47AE-9348-66C1324AD60D} -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\SHJ\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-24-2008 - 13-58-26\{DA0054CE-4E2E-4821-933F-B98A913ACB36} -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\SHJ\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-24-2008 - 13-58-26\{1DFD1E1F-DF53-4D05-86E3-906FB2A2BA76} -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\SHJ\Cookies\shj@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\SHJ\Cookies\shj@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\SHJ\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-24-2008 - 13-58-26\{AD0FCB5A-8BBD-44E1-916D-BF1D1D6D435F} -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\SHJ\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-24-2008 - 13-58-26\{33D477E9-08CC-43ED-8F95-BDE90C3D0241} -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\SHJ\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-24-2008 - 13-58-26\{A4B19DCB-1C7E-4E17-8677-B8C9EBC3E488} -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\SHJ\Cookies\shj@statistik-gallup[1].txt -> TrackingCookie.Statistik-gallup : Cleaned.
C:\Documents and Settings\Public.HARDER\Cookies\public@m.webtrends[1].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\SHJ\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-24-2008 - 13-58-26\{3464BB72-3969-489D-B58F-9F04E6775001} -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\SHJ\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-24-2008 - 13-58-26\{C9743673-B429-4BC6-B184-7E2227F910E0} -> TrackingCookie.Yadro : Cleaned.
C:\Entertainment\Incoming\SpyHunter Keygen.zip/Crack.exe -> Trojan.Agent.cmn : Cleaned.
C:\System Volume Information\_restore{BA609036-0027-4825-A132-F434590B8E0F}\RP287\A0736333.exe -> Trojan.Agent.cmn : Cleaned.


::Report end


                         
ComboFix 08-03-22.3 - SHJ 2008-03-24 23:38:12.1 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1030.18.1103 [GMT 1:00]
Running from: C:\Documents and Settings\SHJ\Skrivebord\Spywarefri\SWF_CF.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
-- Other TimeOuts --
Findstr -MIF:/ "\\TTC\.pdb InsertAdvertisement" 
GREP -i "C:\\Programmer\\[^\\]*\\[^\\]*$" 
VFind -tf -s282624 "C:\Programmer\????????*[0-9].dll" 
CF23400.exe /c " VFind.exe -ltf -s-1000000 -d+2007-12-24 "C:\Programmer\*" >progfile.dat"
VFind.exe -ltf -s-1000000 -d+2007-12-24 "C:\Programmer\*" 
CF23400.exe /c " dir /a/s/b C:\_desktop.ini C:\desktop_.ini C:\cnsmin* C:\_install.exe >DirRoot"

(((((((((((((((((((((((((  Files Created from 2008-02-24 to 2008-03-24  )))))))))))))))))))))))))))))))
.

2008-03-24 21:24 . 2008-03-24 21:24    <DIR>    d--------    C:\Documents and Settings\SHJ\Application Data\Grisoft
2008-03-24 21:24 . 2007-05-30 13:10    10,872    --a------    C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-24 18:26 . 2008-03-24 18:26    <DIR>    d--------    C:\Programmer\Fælles filer\Wise Installation Wizard
2008-03-24 18:26 . 2008-03-24 18:26    <DIR>    d--------    C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2008-03-24 13:31 . 2008-03-24 13:31    <DIR>    d--------    C:\Documents and Settings\SHJ\Application Data\SUPERAntiSpyware.com
2008-03-24 13:02 . 2008-03-24 18:26    <DIR>    d--------    C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2008-03-24 01:44 . 2008-03-24 17:48    <DIR>    d--------    C:\Programmer\Enigma Software Group
2008-03-23 20:29 . 2008-03-23 20:29    219,648    --a------    C:\WINDOWS\ausctv32a.dll
2008-03-13 22:10 . 2008-03-24 17:16    54,156    --ah-----    C:\WINDOWS\QTFont.qfn
2008-03-13 22:10 . 2008-03-13 22:10    1,409    --a------    C:\WINDOWS\QTFont.for
2008-03-13 22:08 . 2008-03-13 22:08    <DIR>    d--------    C:\Programmer\iPod
2008-03-13 22:07 . 2008-03-13 22:08    <DIR>    d--------    C:\Programmer\iTunes
2008-03-13 22:07 . 2008-03-23 20:21    <DIR>    d--------    C:\Programmer\Bonjour
2008-03-13 22:04 . 2008-03-13 22:04    <DIR>    d----c---    C:\WINDOWS\system32\DRVSTORE
2008-03-13 22:04 . 2008-03-13 22:04    <DIR>    d--------    C:\Programmer\Fælles filer\Apple
2008-03-13 22:04 . 2008-03-13 22:04    <DIR>    d--------    C:\Programmer\Apple Software Update
2008-03-13 22:04 . 2008-03-13 22:04    <DIR>    d--------    C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple
2008-03-13 19:16 . 2008-03-13 19:16    <DIR>    d--------    C:\Documents and Settings\SHJ\Application Data\AdobeUM
2008-02-24 19:16 . 2008-02-24 19:16    <DIR>    d--------    C:\Programmer\eRightSoft

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-24 20:24    ---------    d-----w    C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
2008-03-24 19:53    ---------    d-----w    C:\Documents and Settings\SHJ\Application Data\BitTorrent
2008-03-24 17:26    ---------    d-----w    C:\Documents and Settings\SHJ\Application Data\Lavasoft
2008-03-23 19:41    ---------    d-----w    C:\Documents and Settings\All Users.WINDOWS\Application Data\avg7
2008-03-13 21:08    ---------    d-----w    C:\Documents and Settings\SHJ\Application Data\Apple Computer
2008-03-13 21:07    ---------    d-----w    C:\Programmer\QuickTime
2008-03-13 21:07    ---------    d-----w    C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple Computer
2008-02-27 14:11    ---------    d---a-w    C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-02-14 18:13    ---------    d-----w    C:\Programmer\Red Kawa
2008-02-04 19:26    151,040    --sh--w    C:\WINDOWS\system32\VistaUltm.dll
2008-01-25 22:04    ---------    d-----w    C:\Documents and Settings\SHJ\Application Data\AVG7
2008-01-09 11:18    524,288    ----a-w    C:\WINDOWS\system32\DivXsm.exe
2008-01-09 11:18    3,596,288    ----a-w    C:\WINDOWS\system32\qt-dx331.dll
2008-01-09 11:18    200,704    ----a-w    C:\WINDOWS\system32\ssldivx.dll
2008-01-09 11:18    1,044,480    ----a-w    C:\WINDOWS\system32\libdivx.dll
2008-01-09 11:16    823,296    ----a-w    C:\WINDOWS\system32\divx_xx0c.dll
2008-01-09 11:16    823,296    ----a-w    C:\WINDOWS\system32\divx_xx07.dll
2008-01-09 11:16    81,920    ----a-w    C:\WINDOWS\system32\dpl100.dll
2008-01-09 11:16    802,816    ----a-w    C:\WINDOWS\system32\divx_xx11.dll
2008-01-09 11:16    682,496    ----a-w    C:\WINDOWS\system32\DivX.dll
2008-01-09 11:16    196,608    ----a-w    C:\WINDOWS\system32\dtu100.dll
2005-09-09 17:55    35    ----a-w    C:\Programmer\SCSSDist.ini
2006-05-03 10:06    163,328    --sh--r    C:\WINDOWS\system32\flvDX.dll
2007-02-21 11:47    31,232    --sh--r    C:\WINDOWS\system32\msfDX.dll
2007-12-17 13:43    27,648    --sh--w    C:\WINDOWS\system32\Smab0.dll
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D2A8552D-4340-413E-B94E-245827FBC269}]
2008-03-23 20:29    219648    --a------    C:\WINDOWS\ausctv32a.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ZipFile]
@={2D7E38A6-A604-45AE-9A87-4F5F25760650}

[HKEY_CLASSES_ROOT\CLSID\{2D7E38A6-A604-45AE-9A87-4F5F25760650}]
            C:\WINDOWS\System32\winsdrv.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-18 14:56 68856]
"H/PC Connection Agent"="C:\Programmer\Microsoft ActiveSync\wcescomm.exe" [2006-06-27 18:39 1211176]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 13:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-01-10 15:04 4263936]
"nwiz"="nwiz.exe" [2003-01-10 15:04 315392 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2003-01-10 15:04 49152]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43 83608]
"nForce Tray Options"="sstray.exe" [2002-12-05 05:23 73728 C:\WINDOWS\system32\sstray.exe]
"AVG7_CC"="C:\SIKKER~1\AVG\avgcc.exe" [2007-12-24 11:04 579072]
"Startup Manager Scanner"="C:\Sikkerhed\Startup Mechanic\StartupMonitor.exe" [2004-09-05 19:01 86016]
"!AVG Anti-Spyware"="C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\SIKKER~1\AVG\avgw.exe" [2007-10-22 17:18 219136]

C:\Documents and Settings\SHJ\Menuen Start\Programmer\Start\
iexplore.exe [2007-04-24 10:58:48 625152]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Sikkerhed\SuperAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Sikkerhed\SuperAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Sikkerhed\SuperAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmer\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"C:\\Programmer\\Sony\\Station\\LaunchPad\\_aunchPad.exe"=
"C:\\Programmer\\BitTorrent\\bittorrent.exe"=
"C:\Programmer\Microsoft ActiveSync\rapimgr.exe"= C:\Programmer\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Programmer\Microsoft ActiveSync\wcescomm.exe"= C:\Programmer\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Programmer\Microsoft ActiveSync\WCESMgr.exe"= C:\Programmer\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Programmer\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Sikkerhed\\AVG\\avginet.exe"=
"C:\\Sikkerhed\\AVG\\avgamsvr.exe"=
"C:\\Sikkerhed\\AVG\\avgcc.exe"=
"C:\\Programmer\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Programmer\\Bonjour\\mDNSResponder.exe"=
"C:\\Programmer\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

S3 VMCUSB;Sony MusicClip PERSONAL NETWORK PLAYER;C:\WINDOWS\system32\Drivers\VMCUSB.sys [2001-10-17 20:09]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{776f8037-645d-11db-9553-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-03-13 21:04:51 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Programmer\Apple Software Update\SoftwareUpdate.exe
"2008-03-24 22:35:16 C:\WINDOWS\Tasks\XoftSpySE 2.job"
- C:\Sikkerhed\XoftSpySE\XoftSpy.exe
"2008-03-24 11:47:11 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Sikkerhed\XoftSpySE\XoftSpy.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-24 23:41:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-03-24 23:42:21
ComboFix-quarantined-files.txt  2008-03-24 22:42:13
.
2008-03-13 05:49:47    --- E O F --- 



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:44:17, on 24-03-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Programmer\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\Java\jre1.6.0_01\bin\jusched.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\explorer.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Sikkerhed\Trend HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Media Player Classic - {D2A8552D-4340-413E-B94E-245827FBC269} - C:\WINDOWS\ausctv32a.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [AVG7_CC] C:\SIKKER~1\AVG\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Startup Manager Scanner] C:\Sikkerhed\Startup Mechanic\StartupMonitor.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\SIKKER~1\AVG\avgw.exe /RUNONCE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\SIKKER~1\AVG\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\SIKKER~1\AVG\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: iexplore.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Opret Foretrukken på den mobile enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O20 - Winlogon Notify: !SASWinLogon - C:\Sikkerhed\SuperAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Sikkerhed\AdAware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\SIKKER~1\AVG\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\SIKKER~1\AVG\avgupsvc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Programmer\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Programmer\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programmer\Fælles filer\Sony Shared\AVLib\SPTISRV.exe

--
End of file - 6311 bytes
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester