Avatar billede iaskyouknow Nybegynder
23. juli 2008 - 14:42 Der er 28 kommentarer og
7 løsninger

Adware virtumonde fundet?

Da spy sweeper kørte her til morgen fandt den Adware virtumonde og den blev så fjernet, men så ville ss genstate min pc og det fik den så lov til og derfter kom den besked frem da min pc startde op igen. Jeg ved at filen ybopnghv.dll var blandt de 8 filer som ss fjernet. Hvad betyder den røde Rødt advarsel X besked?

Hver så venlig at hjælpe mig så ville jeg være meget glad.

Rødt advarsel X

Fejl under indlæsning af C:\WINDOWS\system32\ybopnghv.dll

Windows XP Home SP3 Dansk version
Web Browser Firefox 3.0.1 Dansk version
23. juli 2008 - 19:47 #1
UHA - ser ikke 'sund' ud !!!

... for en go' ordens skyld; stik os/mig en HiJackThis ->
http://www.spywareinfo.dk/index.htm#/manualer/hijackthis.htm

Bemærk at HiJackThis.exe programmet skal gemmes i en dertil oprettet mappe og IKKE køres direkte fra nettet...

PS: Brug denne version af HJT -> http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe

(Jooo - jeg har 'virus' på hjernen...)

------------------
23. juli 2008 - 19:48 #2
Velkommen til Eksperten.dk
Generelt -> http://expfaq.dk/
Avatar billede iaskyouknow Nybegynder
23. juli 2008 - 21:48 #3
Jeg har nu løst problemmet men her kommer HiJackThis logen


Logfile of Trend Micro  v2.0.2
Scan saved at 21:39:13, on 23-07-2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmer\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Programmer\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmer\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Programmer\Anonymizer\Anonymizer Software\AnonASW\AnonAswSvc.exe
C:\Programmer\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe
C:\Programmer\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Programmer\Creative\SBAudigy2\DVDAudio\CTDVDDET.EXE
C:\Program Files\svehost.exe
C:\Programmer\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmer\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Programmer\Eraser\eraser.exe
C:\Programmer\Internet Download Manager\IDMan.exe
C:\Programmer\Creative\MediaSource\RemoteControl\RcMan.exe
C:\Programmer\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe
C:\Programmer\Creative\MediaSource\Detector\CTDetect.exe
C:\Programmer\Creative\MediaSource\Go\CTCMSGo.exe
C:\Programmer\Anonymizer\Anonymizer Software\Anonymizer.exe
C:\Programmer\Anonymizer TNS\AnonTns.exe
C:\Programmer\K-Meleon\loader.exe
C:\Documents and Settings\My Computer\Dokumenter\Downloads\Compressed\trayit_4_6_5_5\TrayIt!.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\K-Meleon\k-meleon.exe
C:\Programmer\Internet Download Manager\IEMonitor.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\MSN Messenger\usnsvc.exe
C:\Programmer\Mozilla Thunderbird\thunderbird.exe
C:\Programmer\Webroot\Spy Sweeper\SSU.EXE
C:\Programmer\Mozilla Firefox\firefox.exe
C:\Documents and Settings\My Computer\Dokumenter\Downloads\Compressed\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.no
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gioogle.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [CTSysVol] "C:\Programmer\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDET] C:\Programmer\Creative\SBAudigy2\DVDAudio\CTDVDDET.EXE
O4 - HKLM\..\Run: [Dl] "C:\Program Files\svehost.exe"
O4 - HKLM\..\Run: [egui] "C:\Programmer\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [50a6c405] "rundll32.exe" "C:\WINDOWS\system32\oedhypqc.dll",b
O4 - HKLM\..\Run: [SpySweeper] "C:\Programmer\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Eraser] "C:\Programmer\Eraser\eraser.exe" -hide
O4 - HKCU\..\Run: [IDMan] "C:\Programmer\Internet Download Manager\IDMan.exe" /onboot
O4 - HKCU\..\Run: [RemoteCenter] C:\Programmer\Creative\MediaSource\RemoteControl\RcMan.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe"
O4 - HKCU\..\Run: [Simp] "C:\Programmer\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe"
O4 - HKCU\..\Run: [Creative Detector] "C:\Programmer\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [Creative MediaSource Go] "C:\Programmer\Creative\MediaSource\Go\CTCMSGo.exe" /SCB
O4 - HKCU\..\Run: [Anonymizer] "C:\Programmer\Anonymizer\Anonymizer Software\Anonymizer.exe" -nogui
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Anonymizer Total Net Shield.lnk = C:\Programmer\Anonymizer TNS\AnonTns.exe
O4 - Startup: K-Meleon Loader.lnk = C:\Programmer\K-Meleon\loader.exe
O4 - Startup: TrayIt!.lnk = C:\Documents and Settings\My Computer\Dokumenter\Downloads\Compressed\trayit_4_6_5_5\TrayIt!.exe
O8 - Extra context menu item: Download all links with IDM - C:\Programmer\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Programmer\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Programmer\Internet Download Manager\IEExt.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Programmer\Bonjour\ExplorerPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://prerelease.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1216574213625
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su/ocx/15102/CTPID.cab
O23 - Service: Anonymizer Anti-Spyware Service (AnonAswSvc) - Anonymizer - C:\Programmer\Anonymizer\Anonymizer Software\AnonASW\AnonAswSvc.exe
O23 - Service: Anonymizer Management Service (AnonMgmtSvc) - Anonymizer - C:\Programmer\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Programmer\Bonjour\mDNSResponder.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Programmer\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Programmer\ESET\ESET Smart Security\ekrn.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Programmer\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 9479 bytes
Avatar billede iaskyouknow Nybegynder
23. juli 2008 - 21:52 #4
Her er min løsning:

I brugte disse 3 programmer for at scanner og slette filer registerdatabasen men inden det lavet jeg et backup RDB. Jeg slettede en fil i RDB og rettede mange andre Glary Registry Repair, Reg Organizer: System Registry og til sidste fandt CCleaner 280MB overskydende rester.

Reg Organizer: System Registry

CCleaner

Glary Registry Repair
23. juli 2008 - 22:23 #5
Så du mener at ovenstående log fra HiJackThis viser at PC'en en REN ? *KMPLAG*
NEJ - den er IKKE REN !!!

Vil du vide mere ???
Avatar billede iaskyouknow Nybegynder
23. juli 2008 - 22:46 #6
Ja jeg vil vide mere hvad det der ikke er rent?
Avatar billede iaskyouknow Nybegynder
23. juli 2008 - 22:50 #7
Kan det ha noget med at gøre at xp har slådet automatic update fra og at jeg ikke kan slå det til igen?
23. juli 2008 - 23:28 #8
Jeg ka' godt 'se' snavset; men der er tit mere 'snavs' med så du bliver nødt til at gennemføre proceduren herfra ->
http://www.eksperten.dk/artikler/1123
PS: Brug stadig denne version af HJT -> http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe

PS: Det er sansynligvis 'snavset' der har dræbt "automatic update" - typisk. Det skal nok bliver godt igen...
Avatar billede iaskyouknow Nybegynder
24. juli 2008 - 00:34 #9
Så er jeg klar hvor starter vi?
24. juli 2008 - 00:51 #10
Loggen fra ComboFix, SAS, HiJackThis som beskrevet i nævnte http://www.eksperten.dk/artikler/1123

(Dette er gennemført 1.000 vis af gange før; ikke kun her på E. ...)

Så skal jeg nok fortælle den videre procedure...
Avatar billede iaskyouknow Nybegynder
24. juli 2008 - 16:10 #11
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/24/2008 at 01:39 PM

Application Version : 4.0.1154

Core Rules Database Version : 3513
Trace Rules Database Version: 1504

Scan type      : Complete Scan
Total Scan Time : 00:38:38

Memory items scanned      : 180
Memory threats detected  : 1
Registry items scanned    : 4269
Registry threats detected : 8
File items scanned        : 17606
File threats detected    : 2

Adware.Vundo Variant/Resident
    C:\WINDOWS\SYSTEM32\NNNOLDTK.DLL
    C:\WINDOWS\SYSTEM32\NNNOLDTK.DLL

Trojan.Vundo-Variant/Small-GEN
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6BF32C7C-8300-4FF5-96F9-A5FA212340E2}
    HKCR\CLSID\{6BF32C7C-8300-4FF5-96F9-A5FA212340E2}
    HKCR\CLSID\{6BF32C7C-8300-4FF5-96F9-A5FA212340E2}\InprocServer32
    HKCR\CLSID\{6BF32C7C-8300-4FF5-96F9-A5FA212340E2}\InprocServer32#ThreadingModel

Adware.Vundo Variant
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EBA0F461-D69F-4BE7-9F08-467E81EF96F3}
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{EBA0F461-D69F-4BE7-9F08-467E81EF96F3}

Adware.Vundo Variant/Rel
    HKLM\SOFTWARE\Microsoft\FCOVM
    HKU\S-1-5-21-1644491937-308236825-839522115-1004\Software\Microsoft\rdfa

Trojan.Vundo-Variant/Small
    C:\WINDOWS\SYSTEM32\BYXOFFYR.DLL
Avatar billede iaskyouknow Nybegynder
24. juli 2008 - 16:11 #12
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:42:31, on 24-07-2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmer\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Programmer\Anonymizer\Anonymizer Software\AnonASW\AnonAswSvc.exe
C:\Programmer\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe
C:\Programmer\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Programmer\Creative\SBAudigy2\DVDAudio\CTDVDDET.EXE
C:\Programmer\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Programmer\Eraser\eraser.exe
C:\Programmer\Internet Download Manager\IDMan.exe
C:\Programmer\Creative\MediaSource\RemoteControl\RcMan.exe
C:\Programmer\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe
C:\Programmer\Creative\MediaSource\Detector\CTDetect.exe
C:\Programmer\Creative\MediaSource\Go\CTCMSGo.exe
C:\Programmer\Anonymizer\Anonymizer Software\Anonymizer.exe
C:\Programmer\Anonymizer TNS\AnonTns.exe
C:\Programmer\K-Meleon\loader.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\My Computer\Dokumenter\Downloads\Compressed\trayit_4_6_5_5\TrayIt!.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\K-Meleon\k-meleon.exe
C:\Programmer\Internet Download Manager\IEMonitor.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\MSN Messenger\usnsvc.exe
C:\Programmer\Webroot\Spy Sweeper\SSU.EXE
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\Mozilla Thunderbird\thunderbird.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\Documents and Settings\My Computer\Dokumenter\Downloads\Programs\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.no
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gioogle.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Programmer\Internet Download Manager\IDMIECC.dll
O2 - BHO: {755f47d4-bdcc-2c68-6f14-07015d7c2342} - {2432c7d5-1070-41f6-86c2-ccdb4d74f557} - C:\WINDOWS\system32\hcucfv.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {E3122821-62D7-4DD4-A0A6-09FB5AFA8705} - C:\WINDOWS\system32\atmf.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [CTSysVol] "C:\Programmer\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDET] C:\Programmer\Creative\SBAudigy2\DVDAudio\CTDVDDET.EXE
O4 - HKLM\..\Run: [SpySweeper] C:\Programmer\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Eraser] "C:\Programmer\Eraser\eraser.exe" -hide
O4 - HKCU\..\Run: [IDMan] "C:\Programmer\Internet Download Manager\IDMan.exe" /onboot
O4 - HKCU\..\Run: [RemoteCenter] C:\Programmer\Creative\MediaSource\RemoteControl\RcMan.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe"
O4 - HKCU\..\Run: [Simp] "C:\Programmer\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe"
O4 - HKCU\..\Run: [Creative Detector] "C:\Programmer\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [Creative MediaSource Go] "C:\Programmer\Creative\MediaSource\Go\CTCMSGo.exe" /SCB
O4 - HKCU\..\Run: [Anonymizer] "C:\Programmer\Anonymizer\Anonymizer Software\Anonymizer.exe" -nogui
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Anonymizer Total Net Shield.lnk = C:\Programmer\Anonymizer TNS\AnonTns.exe
O4 - Startup: K-Meleon Loader.lnk = C:\Programmer\K-Meleon\loader.exe
O4 - Startup: TrayIt!.lnk = C:\Documents and Settings\My Computer\Dokumenter\Downloads\Compressed\trayit_4_6_5_5\TrayIt!.exe
O8 - Extra context menu item: Download all links with IDM - C:\Programmer\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Programmer\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Programmer\Internet Download Manager\IEExt.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Programmer\Bonjour\ExplorerPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://prerelease.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1216574213625
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su/ocx/15102/CTPID.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: vtUkifcA - vtUkifcA.dll (file missing)
O23 - Service: Anonymizer Anti-Spyware Service (AnonAswSvc) - Anonymizer - C:\Programmer\Anonymizer\Anonymizer Software\AnonASW\AnonAswSvc.exe
O23 - Service: Anonymizer Management Service (AnonMgmtSvc) - Anonymizer - C:\Programmer\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Programmer\Bonjour\mDNSResponder.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Programmer\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 9416 bytes
Avatar billede iaskyouknow Nybegynder
24. juli 2008 - 16:11 #13
ComboFix 08-07-23.2 - My Computer 2008-07-24 15:45:21.1 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1030.18.524 [GMT 2:00]
Running from: C:\Documents and Settings\My Computer\Dokumenter\Downloads\Programs\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
    /wow section - STAGE 40
pv: No matching processes found
Forkert syntaks for kommandoen.


(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\BM5395f799.txt
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\atmf.dll
C:\WINDOWS\system32\awmnappo.dll
C:\WINDOWS\system32\bielyytk.dll
C:\WINDOWS\system32\bksbajeq.dll
C:\WINDOWS\system32\cnamovcg.dll
C:\WINDOWS\system32\ffyktbht.ini
C:\WINDOWS\system32\gcvomanc.ini
C:\WINDOWS\system32\gdppxkng.dll
C:\WINDOWS\system32\hcucfv.dll
C:\WINDOWS\system32\KTDLonnn.ini
C:\WINDOWS\system32\KTDLonnn.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\ozerss.dll
C:\WINDOWS\system32\thbtkyff.dll

.
(((((((((((((((((((((((((  Files Created from 2008-06-24 to 2008-07-24  )))))))))))))))))))))))))))))))
.

2008-07-24 11:24 . 2008-07-24 15:44    4,958,588    --a------    C:\WINDOWS\{00000002-00000000-00000000-00001102-00000004-10021102}.BAK
2008-07-24 11:01 . 2008-07-24 15:37    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2008-07-24 11:01 . 2008-07-24 11:01    <DIR>    d--------    C:\Documents and Settings\My Computer\Application Data\SUPERAntiSpyware.com
2008-07-24 11:01 . 2008-07-24 11:01    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-24 11:00 .     <DIR>        C:\Programmer\Fælles filer\Wise Installation Wizard
2008-07-23 18:10 . 2008-07-23 18:11    <DIR>    d--------    C:\Programmer\CCleaner
2008-07-23 17:46 . 2008-07-23 17:46    <DIR>    d--------    C:\Documents and Settings\My Computer\Application Data\GlarySoft
2008-07-23 17:28 . 2008-07-23 17:28    <DIR>    d--------    C:\Documents and Settings\My Computer\Application Data\ChemTable Software
2008-07-23 17:04 . 2008-07-23 17:09    <DIR>    d--------    C:\WINDOWS\system32\NtmsData
2008-07-23 16:29 . 2008-07-23 16:32    <DIR>    d--------    C:\Documents and Settings\My Computer\Application Data\HouseCall 6.6
2008-07-23 16:28 . 2008-07-23 16:29    <DIR>    d--------    C:\WINDOWS\system32\HouseCall 6.6
2008-07-23 16:16 . 2008-07-23 16:15    102,664    --a------    C:\WINDOWS\system32\drivers\tmcomm.sys
2008-07-23 16:15 . 2008-07-23 16:16    <DIR>    d--------    C:\Documents and Settings\My Computer\.housecall6.6
2008-07-23 16:14 . 2008-07-23 16:14    <DIR>    d--------    C:\WINDOWS\Sun
2008-07-23 14:59 . 2008-07-23 14:59    <DIR>    d--------    C:\Documents and Settings\NetworkService\Application Data\Webroot
2008-07-23 13:32 . 2008-07-23 13:35    <DIR>    d--------    C:\Programmer\IObit
2008-07-23 07:45 . 2008-07-23 13:35    <DIR>    d--------    C:\Programmer\Opera
2008-07-23 07:33 . 2008-07-23 07:33    <DIR>    d--------    C:\Documents and Settings\My Computer\Application Data\K-Meleon
2008-07-23 07:30 . 2008-07-23 07:30    <DIR>    d--------    C:\Programmer\K-Meleon
2008-07-23 07:28 . 2008-07-23 07:28    <DIR>    d--------    C:\Documents and Settings\My Computer\Application Data\Flock
2008-07-23 07:27 . 2008-07-23 07:28    <DIR>    d--------    C:\Programmer\Flock
2008-07-22 23:51 . 2008-07-23 23:52    44,721    ---hs----    C:\WINDOWS\system32\cqpyhdeo.ini
2008-07-22 11:48 . 2008-07-22 23:39    43,701    ---hs----    C:\WINDOWS\system32\chcvrcng.ini
2008-07-22 11:46 . 2008-07-24 12:12    110,419    --a------    C:\WINDOWS\BM5395f799.xml
2008-07-22 03:13 . 2008-07-22 03:14    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\WinZip
2008-07-22 00:59 . 2008-07-22 01:00    <DIR>    d--h-----    C:\Documents and Settings\All Users\Application Data\{478433EB-0AFA-4B69-A2DB-9C4DA4A73909}
2008-07-22 00:57 . 2008-07-22 00:57    <DIR>    d--------    C:\Documents and Settings\My Computer\Application Data\Anonymizer
2008-07-22 00:57 . 2008-07-22 00:57    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Anonymizer
2008-07-21 20:56 . 2008-07-23 02:50    118,784    --a------    C:\WINDOWS\SeaMonkeyUninstall.exe
2008-07-21 20:56 . 2008-07-23 02:49    118,784    --a------    C:\WINDOWS\GREUninstall.exe
2008-07-21 20:56 . 2008-07-24 00:28    11,477    --a------    C:\WINDOWS\mozver.dat
2008-07-21 20:55 . 2008-07-21 20:55    <DIR>    d--------    C:\Programmer\mozilla.org
2008-07-21 20:13 . 2008-07-21 20:13    <DIR>    d--------    C:\Documents and Settings\LocalService\Application Data\Webroot
2008-07-21 20:13 . 2008-01-04 20:34    163,696    --a------    C:\WINDOWS\system32\drivers\ssidrv.sys
2008-07-21 20:13 . 2008-01-04 20:34    23,920    --a------    C:\WINDOWS\system32\drivers\sskbfd.sys
2008-07-21 20:13 . 2008-01-04 20:34    21,872    --a------    C:\WINDOWS\system32\drivers\sshrmd.sys
2008-07-21 20:13 . 2008-01-04 20:34    20,336    --a------    C:\WINDOWS\system32\drivers\SSFS0BB9.sys
2008-07-21 20:12 . 2008-07-21 20:12    <DIR>    d--------    C:\Programmer\Webroot
2008-07-21 20:12 . 2008-07-21 20:12    <DIR>    d--------    C:\Documents and Settings\My Computer\Application Data\Webroot
2008-07-21 20:12 . 2008-07-21 20:12    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Webroot
2008-07-21 20:12 . 2008-01-04 20:56    1,526,640    --a------    C:\WINDOWS\WRSetup.dll
2008-07-21 20:11 . 2008-07-22 00:59    <DIR>    d--------    C:\Programmer\Anonymizer
2008-07-21 19:17 . 2008-07-21 19:17    <DIR>    d--------    C:\temp
2008-07-21 19:10 . 2008-07-21 19:10    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\ESET
2008-07-21 19:09 . 2008-07-23 16:51    <DIR>    d--------    C:\Programmer\%temp&
2008-07-21 19:08 . 2008-07-24 11:26    <DIR>    d--------    C:\Program Files
2008-07-21 19:04 . 2008-07-21 19:04    <DIR>    d--------    C:\Programmer\Brownie
2008-07-21 19:04 . 2008-07-21 19:04    <DIR>    d--------    C:\Programmer\Brother
2008-07-21 19:03 . 2008-07-21 19:03    <DIR>    d--------    C:\Documents and Settings\My Computer\WINDOWS
2008-07-21 19:03 . 1998-01-23 12:19    304,128    --a------    C:\WINDOWS\IsUn0406.exe
2008-07-21 18:55 . 2008-07-21 18:55    <DIR>    d--------    C:\Programmer\VideoLAN
2008-07-21 18:55 . 2008-07-21 18:55    <DIR>    d--------    C:\Documents and Settings\My Computer\Application Data\vlc
2008-07-21 18:30 . 2008-04-13 20:45    26,368    --a--c---    C:\WINDOWS\system32\dllcache\usbstor.sys
2008-07-21 18:26 . 2008-07-24 15:56    11,564    --a------    C:\WINDOWS\system32\DVCState-{00000002-00000000-00000000-00001102-00000004-10021102}.rfx
2008-07-21 18:01 . 2003-11-11 11:08    77,824    ---------    C:\WINDOWS\system32\ctdvda32.dll
2008-07-21 17:36 . 2008-07-21 17:36    <DIR>    d--------    C:\Programmer\Secway
2008-07-21 17:34 . 2008-07-21 17:34    <DIR>    d--------    C:\Documents and Settings\My Computer\Contacts
2008-07-21 17:32 . 2008-07-21 17:32    <DIR>    d--------    C:\Programmer\MSN Messenger
2008-07-21 17:28 . 2008-07-24 15:44    4,958,588    --a------    C:\WINDOWS\{00000002-00000000-00000000-00001102-00000004-10021102}.CDF
2008-07-21 17:27 . 2008-07-24 15:56    30,528    --a------    C:\WINDOWS\system32\BMXBkpCtrlState-{00000002-00000000-00000000-00001102-00000004-10021102}.rfx
2008-07-21 17:27 . 2008-07-21 17:27    1,080    --a------    C:\WINDOWS\system32\settingsbkup.sfm
2008-07-21 17:27 . 2008-07-21 17:27    1,080    --a------    C:\WINDOWS\system32\settings.sfm
2008-07-21 17:27 . 2008-07-21 17:27    288    --a------    C:\WINDOWS\system32\DVCState-{00000002-00000000-00000000-00001102-00000004-10021102}.dat
2008-07-21 17:21 . 2008-07-21 17:21    444,952    --a------    C:\WINDOWS\system32\wrap_oal.dll
2008-07-21 16:09 .     <DIR>        C:\Programmer\Fælles filer\Creative
2008-07-21 16:09 . 2008-07-21 16:09    <DIR>    d--h-----    C:\Programmer\Creative Installation Information
2008-07-21 15:34 . 2003-06-12 23:25    7,062    --a------    C:\WINDOWS\system32\audiopid.vxd
2008-07-21 15:29 . 2008-07-24 15:56    31,056    --a------    C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-00000000-00001102-00000004-10021102}.rfx
2008-07-21 15:29 . 2008-07-24 15:56    31,056    --a------    C:\WINDOWS\system32\BMXState-{00000002-00000000-00000000-00001102-00000004-10021102}.rfx
2008-07-21 15:29 . 2008-07-21 17:27    288    --a------    C:\WINDOWS\system32\DVCStateBkp-{00000002-00000000-00000000-00001102-00000004-10021102}.dat
2008-07-21 15:28 . 2008-07-22 12:24    <DIR>    d--------    C:\Programmer\Startup Manager
2008-07-21 15:28 . 2008-07-21 15:28    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Startup Manager
2008-07-21 15:24 . 1999-10-11 03:00    41,984    ---------    C:\WINDOWS\Ctregrun.exe
2008-07-21 15:24 . 2008-07-24 15:56    30,528    --a------    C:\WINDOWS\system32\BMXCtrlState-{00000002-00000000-00000000-00001102-00000004-10021102}.rfx
2008-07-21 14:45 . 2008-07-21 17:21    <DIR>    d--------    C:\Documents and Settings\My Computer\Application Data\Creative
2008-07-21 14:11 . 2008-07-21 17:20    <DIR>    d--------    C:\WINDOWS\system32\Data
2008-07-21 14:10 . 2000-12-05 09:11    4,174,814    ---------    C:\WINDOWS\system32\CT4MGM.SF2
2008-07-21 14:10 . 2002-09-05 16:32    277,200    --a------    C:\WINDOWS\system32\CTAA1.DAT
2008-07-21 14:10 . 2001-05-28 13:47    32,768    --a------    C:\WINDOWS\system32\AudioHQU.cpl
2008-07-21 14:10 . 2001-05-28 13:47    12,288    --a------    C:\WINDOWS\system32\AHQCpURes.dll
2008-07-21 14:10 . 2008-07-21 14:10    184    --a------    C:\WINDOWS\system32\e000001.dat
2008-07-21 14:09 . 2008-07-21 14:12    136    --a------    C:\WINDOWS\SBWIN.INI
2008-07-21 14:08 . 2008-07-21 17:21    <DIR>    d--------    C:\Programmer\Creative
2008-07-21 14:08 . 2002-02-20 05:00    331,776    ---------    C:\WINDOWS\system32\CTMEDENG.DLL
2008-07-21 14:08 . 2001-09-18 03:00    139,264    --a------    C:\WINDOWS\system32\Video.skn
2008-07-21 14:08 . 2001-03-30 02:00    62,976    --a------    C:\WINDOWS\system32\CTDetres.dll
2008-07-21 14:08 . 1999-12-13 03:01    44,032    --a------    C:\WINDOWS\system32\CTSVCCDA.EXE
2008-07-21 14:08 . 1999-11-18 03:00    25,088    ---------    C:\WINDOWS\system32\CTSVCCTL.EXE
2008-07-21 14:08 . 2000-04-20 01:00    24,576    --a------    C:\WINDOWS\system32\CTMERes.DLL
2008-07-21 14:08 . 1998-09-17 01:52    17,350    --a------    C:\WINDOWS\system32\CTDetect.hlp
2008-07-21 14:08 . 1998-09-17 01:52    641    --a------    C:\WINDOWS\system32\CTDetect.cnt
2008-07-21 12:46 .     <DIR>        C:\Programmer\Fælles filer\Adobe AIR
2008-07-21 12:15 . 2008-07-21 12:15    <DIR>    d--------    C:\WINDOWS\system32\da
2008-07-21 12:15 . 2008-07-21 12:15    <DIR>    d--------    C:\WINDOWS\system32\bits
2008-07-21 12:15 . 2008-07-21 12:15    <DIR>    d--------    C:\WINDOWS\l2schemas
2008-07-21 12:14 . 2008-07-21 12:14    <DIR>    d--------    C:\WINDOWS\ServicePackFiles
2008-07-21 12:09 . 2008-07-21 12:09    <DIR>    d--------    C:\WINDOWS\EHome
2008-07-21 12:04 . 2004-08-26 17:48    701,440    ---------    C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-07-21 10:46 . 2007-07-30 19:19    271,224    --a------    C:\WINDOWS\system32\mucltui.dll
2008-07-21 10:46 . 2007-07-30 19:18    30,072    --a------    C:\WINDOWS\system32\mucltui.dll.mui
2008-07-21 02:46 . 2008-07-21 02:46    <DIR>    d--------    C:\Programmer\Windows Media Connect 2
2008-07-21 02:46 . 2004-08-27 14:00    221,184    --a------    C:\WINDOWS\system32\wmpns.dll
2008-07-21 02:45 . 2008-07-23 18:27    <DIR>    d--------    C:\WINDOWS\system32\LogFiles
2008-07-21 02:45 . 2008-07-21 02:45    <DIR>    d--------    C:\WINDOWS\system32\drivers\UMDF
2008-07-21 02:25 . 2008-07-21 19:20    <DIR>    d--------    C:\Programmer\Internet Download Manager
2008-07-21 02:25 . 2008-07-21 22:18    <DIR>    d--------    C:\Documents and Settings\My Computer\Application Data\IDM
2008-07-21 02:25 . 2008-07-24 15:57    <DIR>    d--------    C:\Documents and Settings\My Computer\Application Data\DMCache
2008-07-21 02:23 . 2008-07-21 02:23    <DIR>    d--------    C:\Documents and Settings\My Computer\dwhelper
2008-07-21 01:46 . 2008-07-21 01:46    <DIR>    d--------    C:\Documents and Settings\My Computer\.rssowl2
2008-07-21 01:44 . 2008-07-21 01:44    <DIR>    d--------    C:\Programmer\Java
2008-07-21 01:44 .     <DIR>        C:\Programmer\Fælles filer\Java
2008-07-21 01:44 . 2008-06-10 02:32    73,728    --a------    C:\WINDOWS\system32\javacpl.cpl
2008-07-21 01:41 . 2008-07-21 01:41    <DIR>    d--------    C:\Programmer\7-Zip
2008-07-21 01:36 . 2008-07-21 01:36    <DIR>    d--------    C:\Documents and Settings\My Computer\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2008-07-21 00:58 .     <DIR>        C:\Programmer\Fælles filer\Adobe
2008-07-21 00:36 . 2008-07-21 00:36    <DIR>    d--------    C:\Programmer\iTunes
2008-07-21 00:36 . 2008-07-21 00:36    <DIR>    d--------    C:\Programmer\iPod
2008-07-21 00:35 . 2008-07-21 17:33    <DIR>    d----c---    C:\WINDOWS\system32\DRVSTORE
2008-07-21 00:35 .     <DIR>        C:\Programmer\Fælles filer\Apple
2008-07-21 00:29 . 2008-07-21 00:29    <DIR>    d--------    C:\Programmer\QuickTime
2008-07-21 00:29 . 2008-07-21 00:36    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-07-21 00:28 . 2008-07-21 20:01    9,084    --ah-----    C:\WINDOWS\system32\mlfcache.dat
2008-07-21 00:22 . 2008-07-21 00:36    <DIR>    d--------    C:\Documents and Settings\My Computer\Application Data\Apple Computer
2008-07-21 00:21 . 2008-07-21 00:22    <DIR>    d--------    C:\Programmer\Safari
2008-07-21 00:21 . 2008-07-21 00:21    <DIR>    d--------    C:\Programmer\Bonjour

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-20 12:59    ---------    d-----w    C:\Programmer\Onlinetjenester
2008-07-20 12:59    ---------    d-----w    C:\Programmer\Fælles filer\Tjenester
2008-06-27 15:24    9,216    ----a-w    C:\WINDOWS\CTPRES.DLL
2008-06-27 15:24    10,240    ----a-w    C:\WINDOWS\CTDCRES.DLL
2008-06-20 11:51    361,600    ----a-w    C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40    138,496    ----a-w    C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08    225,856    ----a-w    C:\WINDOWS\system32\drivers\tcpip6.sys
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 18:05 15360]
"Eraser"="C:\Programmer\Eraser\eraser.exe" [2007-12-23 01:03 916240]
"IDMan"="C:\Programmer\Internet Download Manager\IDMan.exe" [2008-07-14 16:42 2606512]
"RemoteCenter"="C:\Programmer\Creative\MediaSource\RemoteControl\RcMan.exe" [2004-08-17 15:07 143360]
"MsnMsgr"="C:\Programmer\MSN Messenger\MsnMsgr.Exe" [2007-01-19 12:55 5674352]
"Simp"="C:\Programmer\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe" [2007-08-28 19:29 2150400]
"Creative Detector"="C:\Programmer\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 18:23 102400]
"Creative MediaSource Go"="C:\Programmer\Creative\MediaSource\Go\CTCMSGo.exe" [2004-11-30 11:00 135168]
"Anonymizer"="C:\Programmer\Anonymizer\Anonymizer Software\Anonymizer.exe" [2008-07-22 01:00 1557176]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-07-24 15:37 1506544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-03 05:46 13529088]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-03 05:46 86016]
"QuickTime Task"="C:\Programmer\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Programmer\iTunes\iTunesHelper.exe" [2008-07-10 10:51 289064]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 02:38 34672]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"CTSysVol"="C:\Programmer\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [2002-10-29 09:18 49152]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00 90112]
"CTDVDDET"="C:\Programmer\Creative\SBAudigy2\DVDAudio\CTDVDDET.EXE" [2003-06-18 01:00 45056]
"SpySweeper"="C:\Programmer\Webroot\Spy Sweeper\SpySweeperUI.exe" [2008-01-04 20:56 5367664]
"nwiz"="nwiz.exe" [2008-05-03 05:46 1630208 C:\WINDOWS\system32\nwiz.exe]
"CTHelper"="CTHELPER.EXE" [2008-06-27 17:24 19456 C:\WINDOWS\system32\CtHelper.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 18:05 15360]

C:\Documents and Settings\My Computer\Menuen Start\Programmer\Start\
Anonymizer Total Net Shield.lnk - C:\Programmer\Anonymizer TNS\AnonTns.exe [2008-07-20 15:18:42 1630944]
K-Meleon Loader.lnk - C:\Programmer\K-Meleon\loader.exe [2007-04-16 02:41:00 32768]
TrayIt!.lnk - C:\Documents and Settings\My Computer\Dokumenter\Downloads\Compressed\trayit_4_6_5_5\TrayIt!.exe [2008-07-21 23:03:27 204800]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Programmer\SUPERAntiSpyware\SASSEH.DLL" [2008-07-24 15:37 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmer\\MSN Messenger\\msnmsgr.exe"=
"C:\\Programmer\\MSN Messenger\\livecall.exe"=

R2 AnonAswSvc;Anonymizer Anti-Spyware Service;C:\Programmer\Anonymizer\Anonymizer Software\AnonASW\AnonAswSvc.exe  [2007-10-22 11:14]
R2 AnonMgmtSvc;Anonymizer Management Service;C:\Programmer\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe  [2007-10-22 11:14]
R3 COMMONFX.SYS;COMMONFX.SYS;C:\WINDOWS\system32\drivers\COMMONFX.SYS [2008-06-27 19:21]
R3 CTAUDFX.SYS;CTAUDFX.SYS;C:\WINDOWS\system32\drivers\CTAUDFX.SYS [2008-06-27 19:21]
R3 ctgame;Game Port;C:\WINDOWS\system32\DRIVERS\ctgame.sys [2008-07-07 10:32]
R3 CTSBLFX.SYS;CTSBLFX.SYS;C:\WINDOWS\system32\drivers\CTSBLFX.SYS [2008-06-27 19:21]
S3 COMMONFX;COMMONFX;C:\WINDOWS\system32\drivers\COMMONFX.SYS [2008-06-27 19:21]
S3 CTAUDFX;CTAUDFX;C:\WINDOWS\system32\drivers\CTAUDFX.SYS [2008-06-27 19:21]
S3 CTERFXFX.SYS;CTERFXFX.SYS;C:\WINDOWS\system32\drivers\CTERFXFX.SYS [2008-06-27 19:21]
S3 CTERFXFX;CTERFXFX;C:\WINDOWS\system32\drivers\CTERFXFX.SYS [2008-06-27 19:21]
S3 CTSBLFX;CTSBLFX;C:\WINDOWS\system32\drivers\CTSBLFX.SYS [2008-06-27 19:21]

*Newly Created Service* - SASDIFSV
.
Contents of the 'Scheduled Tasks' folder
"2008-07-24 05:00:02 C:\WINDOWS\Tasks\Anonymizer scan for spyware.job"
- C:\Programmer\Anonymizer\Anonymizer Software\Anonymizer.exe
"2008-07-23 16:20:13 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Programmer\Apple Software Update\SoftwareUpdate.exe
"2008-07-24 07:00:09 C:\WINDOWS\Tasks\wrSpySweeper_LA096D5D7C9AE4F7D8AEB9209A151C4ED.job"
- C:\Programmer\Webroot\Spy Sweeper\SpySweeperUI.exe>/ScheduleSweep=wrSpySweeper_LA096D5D7C9AE4F7D8AEB9209A151C4ED
- C:\Programmer\Webroot\Spy Sweeper\SpySweeperUI.ex
- A:\
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-AppleSyncNotifier - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
Notify-vtUkifcA - vtUkifcA.dll


.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.dk
R0 -: HKCU-Main,Search Page = hxxp://www.google.com
R0 -: HKCU-Main,Search Bar = hxxp://www.google.no
R0 -: HKLM-Main,Default_Page_URL = hxxp://www.gioogle.co.uk
R1 -: HKCU-Internet Settings,ProxyServer = 127.0.0.1:80
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: Download all links with IDM - C:\Programmer\Internet Download Manager\IEGetAll.htm
O8 -: Download FLV video content with IDM - C:\Programmer\Internet Download Manager\IEGetVL.htm
O8 -: Download with IDM - C:\Programmer\Internet Download Manager\IEExt.htm

O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
C:\WINDOWS\Downloaded Program Files\SysReqLab3.osd
C:\WINDOWS\Downloaded Program Files\sysreqlab3.dll

O16 -: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://prerelease.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
C:\WINDOWS\Downloaded Program Files\hcImpl.inf

O16 -: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
C:\WINDOWS\Downloaded Program Files\CTSUEng.inf
C:\WINDOWS\Downloaded Program Files\CTSUEng.ocx
C:\WINDOWS\Downloaded Program Files\CTSUEngn.ocx


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-24 15:57:56
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\BRSS01A.EXE
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmer\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmer\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmer\Internet Download Manager\IEMonitor.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\K-Meleon\k-meleon.exe
C:\Programmer\Webroot\Spy Sweeper\ssu.exe
.
**************************************************************************
.
Completion time: 2008-07-24 16:01:00 - machine was rebooted
ComboFix-quarantined-files.txt  2008-07-24 14:00:50

Pre-Run: 10,845,806,592 byte ledig
Post-Run: 10,779,779,072 byte ledig

292    --- E O F ---    2008-07-20 20:28:08
Avatar billede iaskyouknow Nybegynder
24. juli 2008 - 16:15 #14
Her er de så karise_larry hvad skal jeg slette?
Avatar billede iaskyouknow Nybegynder
24. juli 2008 - 16:22 #15
Der sikkert en del programmer du ikke kenner i min HijackThis  Log  med som der ikke er noget med snavs at gøre.
25. juli 2008 - 00:35 #16
"Google Er Din Ven *S*"

------------------------------------------------------------------------

SAS + ComboFix har nappet dem jeg havde i sigte + lidt mere 'snavs'.
Der er lidt tilbage ->

Kør en scanning med Hijackthis,
Du får herunder nogle filer, som du skal fixe. Det, du skal gøre, er at sætte et flueben ud for disse filer. Når du har gjort det, så lukker du alle andre vinduer ned. Det er meget vigtigt at det eneste vindue, som er åbent er HijackThis vinduet. Husk også at lukke dette vindue, når du har markeret filerne. Nu må du fixe. Klik på Fix checked.

Det er disse, som skal fixes:

O2 - BHO: (no name) - {E3122821-62D7-4DD4-A0A6-09FB5AFA8705} - C:\WINDOWS\system32\atmf.dll
O2 - BHO: {755f47d4-bdcc-2c68-6f14-07015d7c2342} - {2432c7d5-1070-41f6-86c2-ccdb4d74f557} - C:\WINDOWS\system32\hcucfv.dll
O20 - Winlogon Notify: vtUkifcA - vtUkifcA.dll (file missing)

(Mest for oprydning:)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe"
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe

Genstart normalt, kør en ny scanning med hijackthis, og kopier en frisk log herind til tjek.

------------------------------------------------------------------------

Registreringsdatabase oprydning kan anbefales ->
RegCleaner http://www.ccleaner.com/ + http://www.spywarefri.dk/manualer/ccleaner-manual.htm (Specielt punktet [Register]...)
Under installationen får du tilbudt [Yahoo Toolbar]. Du kan sige ja eller *NEJ* til den.
Avatar billede iaskyouknow Nybegynder
25. juli 2008 - 15:32 #17
I valge ikke at slette de sidste 5 da jeg bruge flere af dem.
Avatar billede iaskyouknow Nybegynder
25. juli 2008 - 15:32 #18
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:26:00, on 25-07-2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmer\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Programmer\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmer\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Programmer\Anonymizer\Anonymizer Software\AnonASW\AnonAswSvc.exe
C:\Programmer\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe
C:\Programmer\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Programmer\Creative\SBAudigy2\DVDAudio\CTDVDDET.EXE
C:\Programmer\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Programmer\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Programmer\Eraser\eraser.exe
C:\Programmer\Internet Download Manager\IDMan.exe
C:\Programmer\Creative\MediaSource\RemoteControl\RcMan.exe
C:\Programmer\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe
C:\Programmer\Creative\MediaSource\Detector\CTDetect.exe
C:\Programmer\Creative\MediaSource\Go\CTCMSGo.exe
C:\Programmer\Anonymizer\Anonymizer Software\Anonymizer.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\Anonymizer TNS\AnonTns.exe
C:\Programmer\K-Meleon\loader.exe
C:\Documents and Settings\My Computer\Dokumenter\Downloads\Compressed\trayit_4_6_5_5\TrayIt!.exe
C:\Programmer\K-Meleon\k-meleon.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\Internet Download Manager\IEMonitor.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\MSN Messenger\usnsvc.exe
C:\Programmer\Webroot\Spy Sweeper\SSU.EXE
C:\Documents and Settings\My Computer\Dokumenter\Downloads\Programs\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.no
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gioogle.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Programmer\Internet Download Manager\IDMIECC.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [CTSysVol] "C:\Programmer\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDET] C:\Programmer\Creative\SBAudigy2\DVDAudio\CTDVDDET.EXE
O4 - HKLM\..\Run: [AVP] "C:\Programmer\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Programmer\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKLM\..\RunOnce: [EraserRestartErase (1)] "Eraserl.exe" -rl "C:\WINDOWS\system32\1216991390.(null)" -method Random 1
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Eraser] "C:\Programmer\Eraser\eraser.exe" -hide
O4 - HKCU\..\Run: [IDMan] "C:\Programmer\Internet Download Manager\IDMan.exe" /onboot
O4 - HKCU\..\Run: [RemoteCenter] C:\Programmer\Creative\MediaSource\RemoteControl\RcMan.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe"
O4 - HKCU\..\Run: [Simp] "C:\Programmer\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe"
O4 - HKCU\..\Run: [Creative Detector] "C:\Programmer\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [Creative MediaSource Go] "C:\Programmer\Creative\MediaSource\Go\CTCMSGo.exe" /SCB
O4 - HKCU\..\Run: [Anonymizer] "C:\Programmer\Anonymizer\Anonymizer Software\Anonymizer.exe" -nogui
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Anonymizer Total Net Shield.lnk = C:\Programmer\Anonymizer TNS\AnonTns.exe
O4 - Startup: K-Meleon Loader.lnk = C:\Programmer\K-Meleon\loader.exe
O4 - Startup: TrayIt!.lnk = C:\Documents and Settings\My Computer\Dokumenter\Downloads\Compressed\trayit_4_6_5_5\TrayIt!.exe
O8 - Extra context menu item: Download all links with IDM - C:\Programmer\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Programmer\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Programmer\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Tilføj til Anti-Banner - C:\Programmer\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Web Anti-Virus-statistik - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programmer\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Programmer\Bonjour\ExplorerPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://prerelease.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1216574213625
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su/ocx/15102/CTPID.cab
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Anonymizer Anti-Spyware Service (AnonAswSvc) - Anonymizer - C:\Programmer\Anonymizer\Anonymizer Software\AnonASW\AnonAswSvc.exe
O23 - Service: Anonymizer Management Service (AnonMgmtSvc) - Anonymizer - C:\Programmer\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Programmer\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Programmer\Bonjour\mDNSResponder.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Programmer\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 9888 bytes
25. juli 2008 - 16:20 #19
Bingo - hvordan kører PC'en så nu ?

------
Sletter ikke programmerne ...

[QuickTime Task] - forudindlæser QuickTime player (=Ram/Resourse forbrug!) så hvis den skal bruges starte _lidt_ hurtigere op...
[iTunesHelper]  - forudindlæser iTunesHelper (=Ram/Resourse forbrug!) så hvis den skal bruges starte _lidt_ hurtigere op... Men du ved vel godt hvordan det skal bruges *S*
[Adobe Reader Speed Launcher] - forudindlæser Adobe Reader (=Ram/Resourse forbrug!) så hvis den skal bruges starte _lidt_ hurtigere op...
[SunJavaUpdateSched] - Checker løbende om der er opdateringer til din Java (=Ram/Resourse forbrug!)
Avatar billede iaskyouknow Nybegynder
25. juli 2008 - 20:30 #20
Nu har jeg sletede de 5 filer og min pc kører fint igen.
25. juli 2008 - 22:32 #21
Der er ikke mere 'snavs' ifølge din Log...

Du er velkommen en anden gang...

Du bør rense temp med denne fil, det tager kun få sek.
http://www.spywareinfo.dk/download/cleantempxp2k.bat

Efter sådan en tur er det altid en god ide og rydde op i systemgendannelsesfilerne.
Deaktiver systemgendannelse -> http://www.spywareinfo.dk/#/tip-og-tricks/deaktiver_systemgendannelse.htm
Genstart din computer - aktiver systemgendannelse. Dette gøres samme sted, hvor du deaktiverede, denne gang skal du blot aktivere.
Det vil også være en god idé manuelt at oprette et nyt punkt, som du kan navngive, og vende tilbage til, hvis du skulle få problemer af nogen art.

Safe Surfing...

--------------

Registreringsdatabase oprydning kan anbefales ->
RegCleaner http://www.ccleaner.com/ + http://www.spywarefri.dk/manualer/ccleaner-manual.htm (Specielt punktet [Register]...)
Under installationen får du tilbudt [Yahoo Toolbar]. Du kan sige ja eller NEJ til den.
25. juli 2008 - 22:34 #22
Generelt - det var dog ikke meningen at du skulle 'ta' point selv ?
http://expfaq.dk/behandling_af_svar#behandling_af_svar

(La' gå denne gang *S*)
Avatar billede iaskyouknow Nybegynder
26. juli 2008 - 15:35 #23
I troede at jeg gav dig de 50 point, da jeg medlem af et andet forum der skal man give point til den person de personer der givet de beste råd.
26. juli 2008 - 21:27 #24
(Du havde makeret dig selv i boxen venstre og klasket [Accepter] for at "Acceptere" (=point) til ... dig selv... Sådan er principet her på E.)
Avatar billede johnstigers Seniormester
10. oktober 2008 - 20:24 #25
Lidt feedback...
Avatar billede iaskyouknow Nybegynder
10. oktober 2008 - 22:40 #26
Hvad mener du John?
Avatar billede johnstigers Seniormester
11. oktober 2008 - 11:50 #27
Forklar venligst hvorfor du tager point selv.
Du har fået kvalificeret hjælp...
Avatar billede iaskyouknow Nybegynder
11. oktober 2008 - 21:39 #28
Det var min første tråd, og jeg kunne ikke rigtig finde ud af det der for.
Avatar billede jbz Novice
17. oktober 2008 - 01:04 #29
Hej!

Håber en af Jer kloge eksperter kan kigge på mine logs og se om alt er OK nu!
Jeg har også haft Virtumonde på min maskine startende med standard symptomerne med pop-ups af forskellig art (vinduer, indlejret reklame mv.).
Ved reelt ikke hvordan den har sneget sig ind, da jeg ikke bruger cracks/torrent, men iøvrigt er aktiv på nettet, så jeg kan være kommet forbi en page med sådan noget snavs undervejs. Klikker ellers aldrig på tilbud om free scanning osv, men har hørt at nogen faktisk har fundet en metode hvor man kan få ting aktiveret blot musen føres henover en reklame?
Nå men til sagen: Det der virkeligt gjorde mig nervøs var andre symptomer, idet maskinen fik mere og mere besvær med at virke: Tilsyneladende var alle min restore-punkter forsvundet, antivirus sat ud af kraft, Windows update stoppet og kunne ikke genstartes pga. manglende referencer? og til sidst virkede intet på skrivebordet, hverken shortcuts el. start/proceslinien iconer. Eneste mulighed var Ctrl-Alt-Del og herfra starte et program ad gangen (Faneblad programmer - Nyt Job). Internet Explorer startet ved at åbne et program, der havde et internet link og rette i adressefelt for at finde oplysninger. Fik kørt en scan med en online scanner fra nettet og den fandt så at det var Virtumonde, hvorefter jeg fik fat i denne artikel.
Heldigt, for det virker, dvs. jeg fulgte anbefalingerne her og i artikel 1123 og alt ser ud til at være på plads igen incl. windows update og antivirus. Please giv blot mine log en kig, så jeg kan sove roligt. Enhver anbefaling er naturligvis velkommen, da dette alt i alt har taget over et halvt døgn.
PS! Nogle af pop-up reklamerne var faktisk på dansk, selvom det sikkert er en automatisk landespecifik valg af side, så må der være nogen som har oversat og altså samarbejder med et firma, der måske ikke holder sig for gode til at bruge denne type distribution. Føj-si'r jeg!
Avatar billede jbz Novice
17. oktober 2008 - 01:07 #30
ComboFix 08-10-16.01 - jbz 2008-10-17  0:16:34.1 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1030.18.1118 [GMT 2:00]
Running from: C:\Vundofix\ComboFix.exe
* Created a new restore point

[COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR]
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\efPXHRqr.ini
C:\WINDOWS\system32\efPXHRqr.ini2

.
(((((((((((((((((((((((((  Files Created from 2008-09-16 to 2008-10-16  )))))))))))))))))))))))))))))))
.

2008-10-16 23:11 . 2008-10-16 23:13    1,393    --a------    C:\WINDOWS\imsins.BAK
2008-10-16 22:22 . 2008-10-16 23:54    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2008-10-16 22:22 . 2008-10-16 22:22    <DIR>    d--------    C:\Documents and Settings\jbz\Application Data\SUPERAntiSpyware.com
2008-10-16 22:22 . 2008-10-16 22:22    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-10-16 22:14 . 2008-10-16 22:14    <DIR>    d--------    C:\Programmer\CCleaner
2008-10-16 21:45 . 2008-10-16 21:45    <DIR>    d--------    C:\VundoFix Backups
2008-10-16 21:44 . 2008-10-17 00:13    <DIR>    d--------    C:\Vundofix
2008-10-16 18:42 . 2008-10-16 20:09    <DIR>    d--------    C:\Documents and Settings\Administrator\.housecall6.6
2008-10-16 13:38 . 2005-03-24 23:33    <DIR>    d--------    C:\Documents and Settings\Administrator\Skrivebord
2008-10-16 13:38 . 2005-03-24 23:33    <DIR>    d--h-----    C:\Documents and Settings\Administrator\Skabeloner
2008-10-16 13:38 . 2005-03-24 23:33    <DIR>    d--h-----    C:\Documents and Settings\Administrator\Printere
2008-10-16 13:38 . 2005-03-24 23:33    <DIR>    dr-------    C:\Documents and Settings\Administrator\Menuen Start
2008-10-16 13:38 . 2005-03-24 23:33    <DIR>    d--h-----    C:\Documents and Settings\Administrator\Lokale indstillinger
2008-10-16 13:38 . 2005-03-24 23:42    <DIR>    dr-------    C:\Documents and Settings\Administrator\Foretrukne
2008-10-16 13:38 . 2005-03-24 23:42    <DIR>    dr-------    C:\Documents and Settings\Administrator\Dokumenter
2008-10-16 13:38 . 2005-03-24 23:45    <DIR>    d--------    C:\Documents and Settings\Administrator\Application Data\Symantec
2008-10-16 13:38 . 2005-03-24 23:33    <DIR>    d--h-----    C:\Documents and Settings\Administrator\Andre computere
2008-10-16 13:38 . 2008-10-16 18:42    <DIR>    d--------    C:\Documents and Settings\Administrator
2008-10-16 02:31 . 2008-10-16 02:31    31,232    --a------    C:\WINDOWS\system32\rqRHxuvV.dll.vir
2008-10-15 15:08 . 2008-08-14 15:25    2,191,744    ---------    C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 15:08 . 2008-08-14 15:25    2,147,840    ---------    C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 15:08 . 2008-08-14 15:25    2,068,608    ---------    C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 15:08 . 2008-08-14 15:25    2,026,496    ---------    C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 15:08 . 2008-09-15 17:27    1,846,400    ---------    C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 15:08 . 2008-09-08 12:41    333,824    ---------    C:\WINDOWS\system32\dllcache\srv.sys
2008-10-06 01:36 . 2008-10-06 11:03    <DIR>    d--------    C:\Documents and Settings\jbz\.housecall6.6
2008-10-05 21:58 . 2008-08-14 20:59    1,923,024    --a------    C:\Jørn på spejderlejr.jpg
2008-10-01 09:29 . 2008-08-08 14:47    227,840    --a------    C:\WINDOWS\system32\bzFlRdr.dll
2008-10-01 09:29 . 2008-09-05 06:29    193,024    --a------    C:\WINDOWS\system32\bzpdf.dll
2008-10-01 09:29 . 2008-09-26 20:44    126,976    --a------    C:\WINDOWS\system32\bzpdfc.dll
2008-10-01 09:29 . 2008-07-10 00:19    103,424    --a------    C:\WINDOWS\system32\bzDCT.dll
2008-10-01 09:28 . 2008-10-01 09:28    <DIR>    d--------    C:\Programmer\Bullzip
2008-09-24 13:33 . 2008-10-17 00:13    <DIR>    d--------    C:\WINDOWS\CAVTemp
2008-09-24 13:22 . 2008-09-24 13:22    <DIR>    d--------    C:\Programmer\CA
2008-09-24 13:22 . 2008-09-24 13:22    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\CA
2008-09-24 13:22 . 2008-09-24 13:33    880,560    --a------    C:\WINDOWS\system32\drivers\vetefile.sys
2008-09-24 13:22 . 2008-09-24 13:33    108,368    --a------    C:\WINDOWS\system32\drivers\veteboot.sys
2008-09-24 13:22 . 2008-01-11 21:30    99,592    --a------    C:\WINDOWS\system32\isafeif.dll
2008-09-24 13:22 . 2008-09-24 13:33    91,376    --a------    C:\WINDOWS\system32\isafprod.dll
2008-09-24 13:22 . 2008-01-11 21:30    83,256    --a------    C:\WINDOWS\system32\vetredir.dll
2008-09-24 13:22 . 2008-09-24 13:33    32,240    --a------    C:\WINDOWS\system32\drivers\vetmonnt.sys
2008-09-24 13:22 . 2008-09-24 13:33    26,352    --a------    C:\WINDOWS\system32\drivers\vet-filt.sys
2008-09-24 13:22 . 2008-09-24 13:33    21,488    --a------    C:\WINDOWS\system32\drivers\vetfddnt.sys
2008-09-24 13:22 . 2008-09-24 13:33    21,104    --a------    C:\WINDOWS\system32\drivers\vet-rec.sys
2008-09-23 10:57 . 2008-09-23 10:57    44,504    --a------    C:\Documents and Settings\jbz\Application Data\GDIPFONTCACHEV1.DAT
2008-09-23 10:41 . 2008-09-23 10:41    <DIR>    d--------    C:\Documents and Settings\jbz\Application Data\Canon
2008-09-23 10:17 . 2008-04-13 20:47    25,856    --a------    C:\WINDOWS\system32\drivers\usbprint.sys
2008-09-23 10:17 . 2008-04-13 20:47    25,856    --a------    C:\WINDOWS\system32\dllcache\usbprint.sys
2008-09-23 10:17 . 2008-04-13 20:45    15,104    --a------    C:\WINDOWS\system32\drivers\usbscan.sys
2008-09-23 10:17 . 2008-04-13 20:45    15,104    --a------    C:\WINDOWS\system32\dllcache\usbscan.sys
2008-09-23 10:08 . 2008-09-23 10:09    <DIR>    d--h-----    C:\Documents and Settings\All Users\Application Data\CanonBJ
2008-09-23 10:06 . 2006-04-30 21:00    161,792    --a------    C:\WINDOWS\system32\CNMLM87.DLL
2008-09-23 10:05 . 2008-09-23 10:05    <DIR>    d--h-----    C:\WINDOWS\system32\CanonIJ Uninstaller Information
2008-09-23 10:05 . 2008-09-23 10:05    <DIR>    d--h-----    C:\Programmer\CanonBJ
2008-09-23 10:05 . 2006-04-13 09:23    1,134,592    --a------    C:\WINDOWS\system32\CNCC600.DLL
2008-09-23 10:05 . 2006-05-29 01:39    135,168    --a------    C:\WINDOWS\system32\CNCL600.DLL
2008-09-23 10:05 . 2006-02-17 07:44    106,496    --a------    C:\WINDOWS\system32\cnco600.dll
2008-09-23 10:05 . 2006-04-13 09:23    57,344    --a------    C:\WINDOWS\system32\CNCI600.DLL
2008-09-21 21:50 . 2008-10-04 08:18    <DIR>    d--------    C:\Documents and Settings\jbz\Application Data\DivX
2008-09-21 21:48 . 2008-09-21 21:48    <DIR>    d--------    C:\Programmer\DivX

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-16 20:21    ---------    d-----w    C:\Programmer\Fælles filer\Wise Installation Wizard
2008-10-09 21:11    ---------    d-----w    C:\Documents and Settings\jbz\Application Data\AdobeUM
2008-10-03 17:12    6,066,176    ----a-w    C:\WINDOWS\system32\dllcache\ieframe.dll
2008-09-15 15:27    1,846,400    ----a-w    C:\WINDOWS\system32\win32k.sys
2008-09-08 10:41    333,824    ----a-w    C:\WINDOWS\system32\drivers\srv.sys
2008-09-03 15:09    ---------    d-----w    C:\Programmer\Cribbage
2008-08-27 09:27    3,593,216    ----a-w    C:\WINDOWS\system32\dllcache\mshtml.dll
2008-08-25 08:38    13,824    ----a-w    C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-08-25 08:36    70,656    ----a-w    C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-08-23 05:56    635,848    ----a-w    C:\WINDOWS\system32\dllcache\iexplore.exe
2008-08-23 05:54    161,792    ----a-w    C:\WINDOWS\system32\dllcache\ieakui.dll
2008-08-21 16:04    ---------    d-----w    C:\Programmer\Microsoft CAPICOM 2.1.0.2
2008-08-21 07:35    ---------    d-sh--w    C:\Programmer\Fælles filer\WindowsLiveInstaller
2008-08-21 07:35    ---------    d-----w    C:\Programmer\Windows Live
2008-08-21 07:35    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-14 13:25    2,147,840    ----a-w    C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:25    2,026,496    ----a-w    C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-14 10:04    138,496    ----a-w    C:\WINDOWS\system32\dllcache\afd.sys
2008-07-25 08:36    524,288    ----a-w    C:\WINDOWS\system32\DivXsm.exe
2008-07-23 16:50    3,596,288    ----a-w    C:\WINDOWS\system32\qt-dx331.dll
2008-07-23 16:50    129,784    ----a-w    C:\WINDOWS\system32\pxafs.dll
2008-07-23 16:50    120,056    ----a-w    C:\WINDOWS\system32\pxcpyi64.exe
2008-07-23 16:50    118,520    ----a-w    C:\WINDOWS\system32\pxinsi64.exe
2008-07-23 16:48    200,704    ----a-w    C:\WINDOWS\system32\ssldivx.dll
2008-07-23 16:48    1,044,480    ----a-w    C:\WINDOWS\system32\libdivx.dll
2008-07-23 16:46    12,288    ----a-w    C:\WINDOWS\system32\DivXWMPExtType.dll
2008-07-18 20:10    94,920    ----a-w    C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 20:10    94,920    ----a-w    C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10    53,448    ----a-w    C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10    53,448    ----a-w    C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 20:10    45,768    ----a-w    C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10    36,552    ----a-w    C:\WINDOWS\system32\wups.dll
2008-07-18 20:10    36,552    ----a-w    C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 20:09    563,912    ----a-w    C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09    563,912    ----a-w    C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 20:09    325,832    ----a-w    C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09    325,832    ----a-w    C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 20:09    205,000    ----a-w    C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09    205,000    ----a-w    C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 20:09    1,811,656    ----a-w    C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:09    1,811,656    ----a-w    C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-18 20:07    270,880    ----a-w    C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07    210,976    ----a-w    C:\WINDOWS\system32\muweb.dll
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"RemoteControl"="C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-21 40960]
"MPS"="C:\ACER\PSM.EXE" [2004-03-04 372736]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-27 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-27 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-27 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-27 455168]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"AspireService"="C:\Programmer\Acer\Acer eMode Management\AspireService.exe" [2005-06-21 110592]
"MediaSync"="C:\Programmer\Acer\Acer eConsole\MediaSync.exe" [2005-06-21 425984]
"DT HWP"="C:\Programmer\Portrait Displays\HP Display Assistant\DTHtml.exe" [2007-03-27 278016]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-16 13529088]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-16 86016]
"cctray"="C:\Programmer\CA\CA Internet Security Suite\cctray\cctray.exe" [2008-10-10 247024]
"CAVRID"="C:\Programmer\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2008-09-24 234736]
"VetStart"="C:\Programmer\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe" [2008-09-24 255216]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-08-12 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-01-14 C:\WINDOWS\RTHDCPL.EXE]
"nwiz"="nwiz.exe" [2008-05-16 C:\WINDOWS\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]

C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
Adobe Reader Speed Launch.lnk - C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Microsoft Office.lnk - C:\Programmer\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmer\\Windows Live\\Messenger\\livecall.exe"=

R0 m5287;m5287;C:\WINDOWS\system32\drivers\m5287.sys [2004-12-15 76544]
S3 int15.sys;int15.sys;C:\Programmer\acer\erecovery\int15.sys [ ]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{96598859-9cbc-11d9-9184-806d6172696f}]
\Shell\AutoRun\command - I:\Autorun.exe HowToUse\HowToUse.html
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-eRecoveryService - (no file)
HKLM-Run-eRecoveryService - (no file)
ShellExecuteHooks-{9AD7FC7F-1FE1-4414-9AC5-EC51457528E4} - (no file)


.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://tdconline.dk/
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://global.acer.com/
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O16 -: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} - hxxps://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe

O16 -: {D8575CE3-3432-4540-88A9-85A1325D3375} - hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
C:\WINDOWS\Downloaded Program Files\e-Safekey.inf
C:\WINDOWS\Downloaded Program Files\e-Safekey.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-17 00:29:16
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Programmer\Lavasoft\Ad-Aware\aawservice.exe
C:\Programmer\acer\Acer eConsole\MediaServerService.exe
C:\Programmer\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe
C:\Programmer\Fælles filer\Portrait Displays\Shared\DTSRVC.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmer\Fælles filer\Portrait Displays\Shared\HookManager.exe
C:\Programmer\CA\CA Internet Security Suite\ccprovsp.exe
C:\Programmer\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-10-17  0:32:17 - machine was rebooted
ComboFix-quarantined-files.txt  2008-10-16 22:31:44

Pre-Run: 84.547.883.008 byte ledig
Post-Run: 84,642,189,312 byte ledig

211    --- E O F ---    2008-10-16 21:14:09
Avatar billede jbz Novice
17. oktober 2008 - 01:12 #31
ogfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:08:14, on 17-10-2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\acer\Acer eConsole\MediaServerService.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Programmer\Fælles filer\Portrait Displays\Shared\DTSRVC.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
C:\ACER\PSM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe
C:\Programmer\Acer\Acer eMode Management\AspireService.exe
C:\Programmer\Acer\Acer eConsole\MediaSync.exe
C:\Programmer\Portrait Displays\HP Display Assistant\DTHtml.exe
C:\Programmer\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Programmer\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe
C:\Programmer\Fælles filer\Portrait Displays\Shared\HookManager.exe
C:\Programmer\CA\CA Internet Security Suite\ccprovsp.exe
C:\Programmer\Windows Live\Messenger\usnsvc.exe
C:\Vundofix\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://tdconline.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [MPS] C:\ACER\PSM.EXE
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [AspireService] C:\Programmer\Acer\Acer eMode Management\AspireService.exe
O4 - HKLM\..\Run: [MediaSync] C:\Programmer\Acer\Acer eConsole\MediaSync.exe
O4 - HKLM\..\Run: [DT HWP] C:\Programmer\Portrait Displays\HP Display Assistant\DTHtml.exe -startup_folder
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [cctray] "C:\Programmer\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Programmer\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [VetStart] "C:\Programmer\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe" -r
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\DOCUME~1\jbz\LOKALE~1\Temp\SSUPDATE.EXE Software\SUPERAntiSpyware.com\SUPERAntiSpyware
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Programmer\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acer Media Server - Acer Inc. - C:\Programmer\acer\Acer eConsole\MediaServerService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Programmer\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Programmer\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Programmer\Fælles filer\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Programmer\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

--
End of file - 7544 bytes
Avatar billede jbz Novice
17. oktober 2008 - 01:42 #32
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 10/16/2008 at 10:45 PM

Application Version : 4.0.1154

Core Rules Database Version : 3599
Trace Rules Database Version: 1585

Scan type      : Complete Scan
Total Scan Time : 00:12:38

Memory items scanned      : 212
Memory threats detected  : 1
Registry items scanned    : 4853
Registry threats detected : 6
File items scanned        : 14806
File threats detected    : 2

Adware.Vundo Variant/Resident
    C:\WINDOWS\SYSTEM32\RQRHXPFE.DLL
    C:\WINDOWS\SYSTEM32\RQRHXPFE.DLL

Trojan.Vundo-Variant/Small-GEN
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDC1E410-C174-4E54-B787-8C2CEC55D030}
    HKCR\CLSID\{BDC1E410-C174-4E54-B787-8C2CEC55D030}
    HKCR\CLSID\{BDC1E410-C174-4E54-B787-8C2CEC55D030}\InprocServer32
    HKCR\CLSID\{BDC1E410-C174-4E54-B787-8C2CEC55D030}\InprocServer32#ThreadingModel

Adware.Vundo Variant/Rel
    HKLM\SOFTWARE\Microsoft\FCOVM
    HKLM\SOFTWARE\Microsoft\RemoveRP

Adware.Tracking Cookie
    C:\Documents and Settings\Administrator\Cookies\administrator@statse.webtrendslive[1].txt
Avatar billede iaskyouknow Nybegynder
17. oktober 2008 - 02:17 #33
Du for ikke nogen hjælp her da du selv skal oprette et sprøgsmål. Desuden har jeg ikke forstand på at se om dine logs er rene. Nu jeg er i gang hent den nyeste version of superantispyware der 4.20.1004 din er gammel version 4.0.1154. Da jeg bruger pro version er jeg ikke sikker på at du kan opdatere programmet til den nyeste versdion inde i selve programmet men måske kan du gøre også selv om du bruger superantispyware Free version? hvis ikke så hent det her http://www.superantispyware.com/

Held og lykke med få det snavs af din pc du har nok været ude og male byen rød.

lol lol lol...
17. oktober 2008 - 06:19 #34
<jbz>: Som sagt/skrevet bør (=skal) du oprette din egen tråd; ellers bliver det noget rod !!!
Avatar billede jbz Novice
17. oktober 2008 - 08:44 #35
Tak for instruktion begge to.
Er nu sket
http://www.eksperten.dk/spm/849325
mvh
J ;-)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester