Avatar billede codemanager Nybegynder
14. juni 2008 - 23:36 Der er 1 kommentar

nogle der ville tjekke disse log filer.

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 06/14/2008 at 10:36 PM

Application Version : 4.15.1000

Core Rules Database Version : 3482
Trace Rules Database Version: 1473

Scan type      : Complete Scan
Total Scan Time : 00:35:37

Memory items scanned      : 376
Memory threats detected  : 0
Registry items scanned    : 6584
Registry threats detected : 0
File items scanned        : 23156
File threats detected    : 23

Adware.Tracking Cookie
    C:\Documents and Settings\Windows XP\Cookies\windows_xp@adtech[1].txt
    C:\Documents and Settings\Windows XP\Cookies\windows_xp@advertising[2].txt
    C:\Documents and Settings\Windows XP\Cookies\windows_xp@eas.apm.emediate[2].txt
    C:\Documents and Settings\Windows XP\Cookies\windows_xp@track.adform[2].txt
    C:\Documents and Settings\Windows XP\Cookies\windows xp@insightexpressai[1].txt
    C:\Documents and Settings\Windows XP\Cookies\windows_xp@www.canadiandiscountmed[2].txt
    C:\Documents and Settings\Windows XP\Cookies\windows xp@accounts[1].txt
    C:\Documents and Settings\Windows XP\Cookies\windows_xp@engine.statcount[1].txt
    C:\Documents and Settings\Windows XP\Cookies\windows xp@www.statcount[1].txt
    C:\Documents and Settings\Windows XP\Cookies\windows xp@adnetserver[1].txt
    C:\Documents and Settings\Windows XP\Cookies\windows xp@hitcount[1].txt

Malware.LocusSoftware Inc/Gen
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{300778C3-5EB9-4FC4-817D-D002F7AAFE79}\RP278\A0120682.DLL

Trojan.Unclassified/MRT-Fake
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{300778C3-5EB9-4FC4-817D-D002F7AAFE79}\RP278\A0121716.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{300778C3-5EB9-4FC4-817D-D002F7AAFE79}\RP278\A0121717.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{300778C3-5EB9-4FC4-817D-D002F7AAFE79}\RP278\A0121718.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{300778C3-5EB9-4FC4-817D-D002F7AAFE79}\RP278\A0121719.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{300778C3-5EB9-4FC4-817D-D002F7AAFE79}\RP278\A0121720.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{300778C3-5EB9-4FC4-817D-D002F7AAFE79}\RP278\A0121721.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{300778C3-5EB9-4FC4-817D-D002F7AAFE79}\RP278\A0121722.DLL

Adware.Vundo-Variant/H
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{300778C3-5EB9-4FC4-817D-D002F7AAFE79}\RP279\A0122745.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{300778C3-5EB9-4FC4-817D-D002F7AAFE79}\RP315\A0125440.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{300778C3-5EB9-4FC4-817D-D002F7AAFE79}\RP315\A0125443.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{300778C3-5EB9-4FC4-817D-D002F7AAFE79}\RP315\A0125445.DLL

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:35:14, on 14-06-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\taskswitch.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Programmer\Fælles filer\ACD Systems\EN\DevDetect.exe
C:\Programmer\McAfee.com\VSO\mcvsshld.exe
c:\programmer\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Programmer\ScanSoft\PaperPort\pptd40nt.exe
C:\Programmer\Brother\ControlCenter2\brctrcen.exe
C:\WINDOWS\VM_STI.EXE
C:\Programmer\Java\jre1.6.0_05\bin\jusched.exe
C:\Programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Programmer\McAfee.com\VSO\oasclnt.exe
C:\progra~1\mcafee\MCAFEE~1\masalert.exe
C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\System32\svchost.exe
c:\progra~1\mcafee\mcafee antispyware\massrv.exe
c:\programmer\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Windows XP\Skrivebord\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.forum.dk/Default.aspx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {BCAF4391-7922-44FB-B17D-8DA89BBD2EA1} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Toolbar Suite\TB\02.05.0000.1105\da-dk\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [Device Detector] DevDetect.exe -autorun
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Programmer\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programmer\Fælles filer\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Programmer\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Programmer\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Programmer\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Programmer\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera 301x
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [OASClnt] C:\Programmer\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\masalert.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Shell] "C:\WINDOWS\system32\Rundll32.exe" "C:\WINDOWS\system32\shell32.dll",Control_RunDLL "C:\DOCUME~1\WINDOW~1\LOKALE~1\Temp\dat4.tmp"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Status Monitor.lnk = C:\Programmer\Brother\Brmfcmon\BrMfcWnd.exe
O8 - Extra context menu item: &MSN Search - res://C:\Programmer\MSN Toolbar Suite\TB\02.05.0000.1105\da-dk\msntb.dll/search.htm
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Åbn på ny baggrundsfane - res://C:\Programmer\MSN Toolbar Suite\TAB\02.05.0000.1105\da-dk\msntabres.dll/229?f6533eb64f604151aa1969e3c8d22a8
O8 - Extra context menu item: Åbn på ny forgrundsfane - res://C:\Programmer\MSN Toolbar Suite\TAB\02.05.0000.1105\da-dk\msntabres.dll/230?f6533eb64f604151aa1969e3c8d22a8
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmer\Fælles filer\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmer\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/resources/MSNPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MI1933~1\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: khfGyxWn - khfGyxWn.dll (file missing)
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\programmer\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Print Spooler (Spooler) - Unknown owner - C:\WINDOWS\system32\spoolsv.exe (file missing)

--
End of file - 10797 bytes


ComboFix 08-06-12.2 - Windows XP 2008-06-14 21:53:59.2 - NTFSx86
Running from: C:\Documents and Settings\Windows XP\Skrivebord\ComboFix.exe
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Windows XP\ResErrors.log
C:\WINDOWS\Tasks\0x01xx8p.exe
.
---- Previous Run -------
.
C:\Documents and Settings\All Users\Application Data\HotbarSA
C:\Documents and Settings\All Users\Application Data\HotbarSA\HotbarSA.dat
C:\Documents and Settings\All Users\Application Data\HotbarSA\HotbarSA_kyf.dat
C:\Documents and Settings\All Users\Application Data\HotbarSA\HotbarSAEULA.mht
C:\Documents and Settings\All Users\Application Data\HotbarSA\HotbarSAAbout.mht
C:\Documents and Settings\All Users\Application Data\HotbarSA\HotbarSAau.dat
C:\Documents and Settings\All Users\Menuen Start\Programmer\Hotbar
C:\Documents and Settings\Windows XP\Application Data\Hotbar_Icons
C:\Documents and Settings\Windows XP\Application Data\Hotbar_Icons\games2.ico
C:\Documents and Settings\Windows XP\Application Data\Hotbar_Icons\Registryrepair.ico
C:\Documents and Settings\Windows XP\Application Data\Hotbar_Icons\wallpapere1.ico
C:\Documents and Settings\Windows XP\Application Data\WeatherDPA
C:\Programmer\AntiSpywareMaster
C:\WINDOWS\BM578ece61.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\Fonts\CALIBRIB.TTF
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aogcgrga.exe
C:\WINDOWS\system32\aqxaxxwt.ini
C:\WINDOWS\system32\brnynvmj.ini
C:\WINDOWS\system32\bsiskcvg.exe
C:\WINDOWS\system32\dlbmajww.ini
C:\WINDOWS\system32\dtrkbfmk.ini
C:\WINDOWS\system32\dviarnoi.ini
C:\WINDOWS\system32\fmxfiitd.ini
C:\WINDOWS\system32\gqowxglr.ini
C:\WINDOWS\system32\hchhwdij.ini
C:\WINDOWS\system32\hvqdfkbv.exe
C:\WINDOWS\system32\jmkddovw.exe
C:\WINDOWS\system32\jodnrbjb.ini
C:\WINDOWS\system32\kgqlxhxd.exe
C:\WINDOWS\system32\lflgjmqe.ini
C:\WINDOWS\system32\LSvybJlm.ini
C:\WINDOWS\system32\LSvybJlm.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nrjncxhl.ini
C:\WINDOWS\system32\nwgaffsg.exe
C:\WINDOWS\system32\oirkpcwj.ini
C:\WINDOWS\system32\oowxuuec.exe
C:\WINDOWS\system32\pdooqphn.ini
C:\WINDOWS\system32\pmnMGxYR.dll
C:\WINDOWS\system32\qckdumms.exe
C:\WINDOWS\system32\qcxqnfox.ini
C:\WINDOWS\system32\qhljbutx.ini
C:\WINDOWS\system32\qydrsjbn.ini
C:\WINDOWS\system32\sdwctqnv.ini
C:\WINDOWS\system32\tcmymrdt.ini
C:\WINDOWS\system32\uchqwess.exe
C:\WINDOWS\system32\virmcodt.ini
C:\WINDOWS\system32\vnvscgyq.ini
C:\WINDOWS\system32\windows.txt
C:\WINDOWS\system32\wvUmmKDS.dll
C:\WINDOWS\system32\wwjambld.dll
C:\WINDOWS\system32\xofvtcxb.ini
C:\WINDOWS\system32\xxyayASm.dll
C:\WINDOWS\system32\ylhivymi.ini
C:\WINDOWS\system32\yynmhihq.ini
C:\WINDOWS\Tasks\SysFile.brk

.
(((((((((((((((((((((((((((((((((((((((  Drivers/Services  )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_DHLP


(((((((((((((((((((((((((  Files Created from 2008-05-14 to 2008-06-14  )))))))))))))))))))))))))))))))
.

2008-06-14 20:01 . 2008-06-14 20:01    <DIR>    d--------    C:\Programmer\Fælles filer\Wise Installation Wizard
2008-06-01 18:54 . 2008-06-01 20:27    1,308    --a------    C:\WINDOWS\system32\bing.ext
2008-06-01 18:54 . 2008-06-01 20:27    1,308    --a------    C:\WINDOWS\system32\bak222.ext
2008-06-01 18:54 . 2008-06-01 20:27    1,308    --a------    C:\WINDOWS\system32\3.ext
2008-05-18 18:26 . 2008-05-18 18:26    127    --a------    C:\WINDOWS\system32\MRT.INI
2008-05-18 13:39 . 2008-05-18 13:39    <DIR>    d--------    C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-05-18 13:38 . 2004-10-14 14:34    <DIR>    d--------    C:\Documents and Settings\Administrator\Skrivebord
2008-05-18 13:38 . 2004-10-14 14:11    <DIR>    d--h-----    C:\Documents and Settings\Administrator\Skabeloner
2008-05-18 13:38 . 2004-10-14 14:34    <DIR>    d--h-----    C:\Documents and Settings\Administrator\Printere
2008-05-18 13:38 . 2004-10-14 14:34    <DIR>    dr-------    C:\Documents and Settings\Administrator\Menuen Start
2008-05-18 13:38 . 2008-06-14 21:55    <DIR>    d--h-----    C:\Documents and Settings\Administrator\Lokale indstillinger
2008-05-18 13:38 . 2004-10-14 14:34    <DIR>    d--------    C:\Documents and Settings\Administrator\Foretrukne
2008-05-18 13:38 . 2004-10-14 14:34    <DIR>    d--------    C:\Documents and Settings\Administrator\Dokumenter
2008-05-18 13:38 . 2004-10-14 14:34    <DIR>    d--h-----    C:\Documents and Settings\Administrator\Andre computere
2008-05-18 13:38 . 2008-05-18 13:38    <DIR>    d--------    C:\Documents and Settings\Administrator
2008-05-18 13:34 . 2008-06-14 20:03    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2008-05-18 13:34 . 2008-06-14 20:03    <DIR>    d--------    C:\Documents and Settings\Windows XP\Application Data\SUPERAntiSpyware.com
2008-05-18 13:34 . 2008-05-18 13:34    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-18 13:30 . 2008-05-18 13:30    <DIR>    d--------    C:\Programmer\Yahoo!
2008-05-18 13:29 . 2008-05-18 13:30    <DIR>    d--------    C:\Programmer\CCleaner
2008-05-18 02:25 . 2008-05-18 12:40    <DIR>    d--------    C:\WINDOWS\BDOSCAN8
2008-05-18 01:03 . 2008-05-18 01:04    <DIR>    d--------    C:\Documents and Settings\Windows XP\.housecall6.6
2008-05-18 01:03 . 2008-05-18 01:03    102,664    --a------    C:\WINDOWS\system32\drivers\tmcomm.sys
2008-05-18 00:59 . 2008-05-18 00:59    100,928    ---------    C:\WINDOWS\system32\fgbdcqmc.dll_old
2008-05-17 23:26 . 2008-05-17 23:26    100,928    ---------    C:\WINDOWS\system32\pftsswon.dll_old
2008-05-17 23:26 . 2008-05-17 23:26    100,928    ---------    C:\WINDOWS\system32\ltkttjhn.dll_old
2008-05-17 17:56 . 2008-05-17 17:56    100,928    ---------    C:\WINDOWS\system32\vicfkvbm.dll_old
2008-05-17 17:55 . 2008-05-17 17:55    0    --a------    C:\WINDOWS\system32\dviarnoi.tmp
2008-05-15 20:03 . 2008-05-15 20:03    0    --a------    C:\WINDOWS\system32\virmcodt.tmp
2008-05-14 15:59 . 2008-05-14 15:59    100,928    ---------    C:\WINDOWS\system32\qrxidkbu.dll_old
2008-05-14 15:10 . 2008-05-14 15:10    100,928    ---------    C:\WINDOWS\system32\mhmhtheu.dll_old

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-14 16:15    34,562    ----a-w    C:\Documents and Settings\Windows XP\Application Data\wklnhst.dat
2008-05-18 16:28    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-18 11:37    ---------    d-----w    C:\Programmer\Spybot - Search & Destroy
2008-05-18 11:24    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-18 00:08    ---------    d-----w    C:\Programmer\Fælles filer\PCRengoringsmaskine
2008-05-18 00:06    ---------    d-----w    C:\Programmer\Fælles filer\G38307037
2008-05-13 11:52    ---------    d-----w    C:\Documents and Settings\Windows XP\Application Data\TrusselOvervagning
2008-05-13 10:32    ---------    d-----w    C:\Documents and Settings\Windows XP\Application Data\SPAMfighter
2008-05-08 15:47    ---------    d-----w    C:\Programmer\Fælles filer\SletingenVirus
2008-05-08 13:56    ---------    d-----w    C:\Programmer\SletingenVirus
2008-05-08 12:28    202,752    ----a-w    C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 17:36    ---------    d-----w    C:\Documents and Settings\Windows XP\Application Data\PCRengoringsmaskine
2008-05-07 08:57    ---------    d-----w    C:\Documents and Settings\Windows XP\Application Data\AdobeUM
2008-05-07 08:30    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\PCRengoringsmaskine
2008-05-07 05:16    1,291,776    ----a-w    C:\WINDOWS\system32\quartz.dll
2008-04-23 07:20    826,368    ----a-w    C:\WINDOWS\system32\wininet.dll
2008-04-23 07:11    ---------    d-----w    C:\Documents and Settings\Windows XP\Application Data\G38307037
2008-04-23 07:08    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\G38307037
2008-04-23 07:08    ---------    d-----r    C:\Documents and Settings\All Users\Application Data\SalesMon
2008-04-21 05:33    261,664    ----a-w    C:\Documents and Settings\Windows XP\Application Data\setup_dk[1].exe
2008-04-20 14:21    ---------    d-----w    C:\Documents and Settings\Windows XP\Application Data\sikkerpcvaerktoj
2008-04-20 14:16    ---------    d-----r    C:\Documents and Settings\All Users\Application Data\sikkerpcvaerktoj
2008-04-14 15:53    272,256    ------w    C:\WINDOWS\system32\drivers\bthport.sys
2008-04-14 10:53    ---------    d-----w    C:\Documents and Settings\Windows XP\Application Data\Skype
2008-03-20 08:09    1,845,248    ----a-w    C:\WINDOWS\system32\win32k.sys
2006-11-27 21:09    76,288    -c--a-w    C:\Documents and Settings\Windows XP\Application Data\GDIPFONTCACHEV1.DAT
2001-11-23 04:08    712,704    -c--a-w    C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.

(((((((((((((((((((((((((((((  snapshot@2008-06-14_21.44.52.67  )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-14 19:41:54    2,048    --s-a-w    C:\WINDOWS\bootstat.dat
+ 2008-06-14 19:50:58    2,048    --s-a-w    C:\WINDOWS\bootstat.dat
.
(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-26 17:53 15360]
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-05 21:23 68856]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2004-05-14 07:41 81920]
"CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [2002-03-19 17:30 45632]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2004-10-14 15:53 77824]
"VTTimer"="VTTimer.exe" [2004-10-22 05:53 53248 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-01-11 01:33 143360 C:\WINDOWS\system32\VTTrayp.exe]
"Device Detector"="DevDetect.exe" []
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-05-14 07:41 3784704]
"nwiz"="nwiz.exe" [2004-05-14 07:41 831488 C:\WINDOWS\system32\nwiz.exe]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 18:18 151552]
"VirusScan Online"="C:\Programmer\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 12:49 163840]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 19:29 303104]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 13:05 212992]
"SSBkgdUpdate"="C:\Programmer\Fælles filer\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 10:22 155648]
"PaperPort PTD"="C:\Programmer\ScanSoft\PaperPort\pptd40nt.exe" [2004-03-17 09:32 57393]
"IndexSearch"="C:\Programmer\ScanSoft\PaperPort\IndexSearch.exe" [2004-03-17 09:48 40960]
"SetDefPrt"="C:\Programmer\Brother\Brmfl04a\BrStDvPt.exe" [2004-05-25 09:16 49152]
"ControlCenter2.0"="C:\Programmer\Brother\ControlCenter2\brctrcen.exe" [2004-07-20 09:34 851968]
"BigDogPath"="C:\WINDOWS\VM_STI.exe" [2003-01-21 15:19 40960]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Adobe Photo Downloader"="C:\Programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 00:46 57344]
"OASClnt"="C:\Programmer\McAfee.com\VSO\oasclnt.exe" [2005-08-11 22:02 53248]
"_AntiSpyware"="c:\progra~1\mcafee\MCAFEE~1\masalert.exe" [2006-01-06 15:14 327680]
"GrooveMonitor"="C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 01:47 31016]
"McRegWiz"="c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe" [2003-09-02 18:41 135168]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-26 17:53 15360]

C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
Adobe Reader Hurtigstart.lnk - C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]
Status Monitor.lnk - C:\Programmer\Brother\Brmfcmon\BrMfcWnd.exe [2005-07-18 12:21:55 819200]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 10:13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\khfGyxWn]
khfGyxWn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\MP3POW~1\CLMP3Enc.ACM

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Windows-pc-søgning.lnk]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Windows-pc-søgning.lnk
backup=C:\WINDOWS\pss\Windows-pc-søgning.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Blondes]
C:\Program Files\hbt\Dialers\Blondes\Blondes.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
--a------ 2007-01-22 16:23 25368104 C:\Programmer\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmer\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programmer\\Skype\\Phone\\Skype.exe"=

R2 CX88XBAR;MSI 8606 Crossbar;C:\WINDOWS\system32\drivers\CX88XBar.SYS [2003-03-19 07:50]
R2 Pctspk;PCTEL Speaker Phone;C:\WINDOWS\system32\pctspk.exe [2001-10-04 17:07]
S3 MPCSYS;MPCSYS;C:\WINDOWS\system32\DRIVERS\mpcsys.sys [2005-07-25 00:06]
S3 Ptserlp;PCTEL Serial Device Driver for PCI;C:\WINDOWS\system32\DRIVERS\ptserlp.sys [2001-08-17 21:28]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{969B3B70-8765-11D5-9809-0050BACBF861}]
rundll32.exe advpack.dll,LaunchINFSection C:\Programmer\CyberLink\MP3PowerEncoder\Cyber.inf,PerUserStub
.
Contents of the 'Scheduled Tasks' folder
"2008-06-13 19:44:42 C:\WINDOWS\Tasks\mcafee antispyware.job"
- c:\progra~1\mcafee\MCAFEE~1\MASCon.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-14 21:55:43
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-14 21:56:42
ComboFix-quarantined-files.txt  2008-06-14 19:56:39

Pre-Run: 185,525,780,480 byte ledig
Post-Run: 185,514,668,032 byte ledig

234    --- E O F ---    2008-06-14 16:16:34
15. juni 2008 - 12:04 #1
Puha - der er allerede blever ædt en del Uønskede elementer - her er resten ->

---------------------------------------

Afinstaller
* YahooToolbar
via
[Start][Indstilninger][Kontrolpanel][Tilføj/fjern programmer]

Genstart for at fuldføre afinstalationen...

---------------------------------------

-- Hent Avenger her:
http://swandog46.geekstogo.com/avenger.zip

-- Pak Avenger-programmet ud og dobbeltklik på avenger.exe

-- Der dukker et vindue op, hvor du skal kopiere indholdet mellem ~~~ skrift ind:

~~~~~~~~~~~~~~~~~~
Files to delete:
C:\WINDOWS\system32\fgbdcqmc.dll_old
C:\WINDOWS\system32\pftsswon.dll_old
C:\WINDOWS\system32\ltkttjhn.dll_old
C:\WINDOWS\system32\vicfkvbm.dll_old
C:\WINDOWS\system32\dviarnoi.tmp
C:\WINDOWS\system32\virmcodt.tmp
C:\WINDOWS\system32\qrxidkbu.dll_old
C:\WINDOWS\system32\mhmhtheu.dll_old
C:\DOCUME~1\WINDOW~1\LOKALE~1\Temp\dat4.tmp

Folders to delete:
C:\Programmer\Yahoo!
C:\Program Files\hbt\
C:\Programmer\Fælles filer\SletingenVirus
C:\Programmer\SletingenVirus
C:\Documents and Settings\All Users\Application Data\PCRengoringsmaskine
C:\Documents and Settings\Windows XP\Application Data\PCRengoringsmaskine
C:\Programmer\Fælles filer\PCRengoringsmaskine
C:\Documents and Settings\All Users\Application Data\PCRengoringsmaskine
C:\Documents and Settings\Windows XP\Application Data\G38307037
C:\Documents and Settings\All Users\Application Data\G38307037
C:\Documents and Settings\All Users\Application Data\SalesMon
C:\Documents and Settings\Windows XP\Application Data\TrusselOvervagning
C:\Documents and Settings\Windows XP\Application Data\setup_dk[1].exe
C:\Documents and Settings\Windows XP\Application Data\sikkerpcvaerktoj
C:\Documents and Settings\All Users\Application Data\sikkerpcvaerktoj

~~~~~~~~~~~~~~~~~~

-- Klik på EXECUTE - og la' PC'en selv genstarte.

-- Efter genstarten vil der dukke et notepad-vindue op, med en log for Avengers handlinger. Den må du gerne lægge ind i dit næste svar.

-- Kør Hijackthis, vælg "Do a system scan only", sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked.

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {BCAF4391-7922-44FB-B17D-8DA89BBD2EA1} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKCU\..\Run: [Shell] "C:\WINDOWS\system32\Rundll32.exe" "C:\WINDOWS\system32\shell32.dll",Control_RunDLL "C:\DOCUME~1\WINDOW~1\LOKALE~1\Temp\dat4.tmp"
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmer\Fælles filer\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL

O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmer\Yahoo!\Common\yinsthelper.dll

O20 - Winlogon Notify: khfGyxWn - khfGyxWn.dll (file missing)

O23 - Service: Print Spooler (Spooler) - Unknown owner - C:\WINDOWS\system32\spoolsv.exe (file missing)

Genstart computeren, og lav en ny log med Hijackthis, som du lægger herind sammen med loggen fra Avenger.

---------------------------------------

Registreringsdatabase oprydning ->
RegCleaner http://www.ccleaner.com/ + http://www.spywarefri.dk/manualer/ccleaner-manual.htm (Specielt punktet [Register]...)
Under installationen får du tilbudt [Yahoo Toolbar]. Du kan sige ja eller *NEJ* til den.
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester