Avatar billede simzone Nybegynder
25. august 2008 - 16:19 Der er 2 kommentarer

Jeres guide:SuperAntiSpyware kombineret med Dr.Web tilbage svar

Jeg brugte guiden:SuperAntiSpyware (kombineret med Dr.Web) http://www.eksperten.dk/artikler/954

Og så ville jeg bare læsse resultaterne af og håbe på svar :)

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 08/24/2008 at 09:01 PM

Application Version : 4.0.1154

Core Rules Database Version : 3545
Trace Rules Database Version: 1534

Scan type : Complete Scan
Total Scan Time : 00:55:50

Memory items scanned : 520
Memory threats detected : 0
Registry items scanned : 6367
Registry threats detected : 129
File items scanned : 25024
File threats detected : 81

Adware.Tracking Cookie
C:\Documents and Settings\Simzone\Cookies\simzone@adfair[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@mediaprovider.adservinginternational[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@media.adrevolver[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@koreanfriendfinder[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@ilead.itrack[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@adbrite[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@ad.yieldmanager[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@eas.apm.emediate[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@atdmt[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@mediamac.comon[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@tripod[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@casalemedia[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@track.adform[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@www7.addfreestats[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@ad.zanox[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@ad1.emediate[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@revsci[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@server.cpmstar[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@ia.adserving[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@msnportal.112.2o7[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@www.googleadservices[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@partypoker[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@bs.serving-sys[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@serving-sys[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@teliasonera.112.2o7[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@insightexpressai[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@tradedoubler[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@banner.gratis-ting[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@adtech[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@fastclick[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@2o7[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@apmebf[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@media.bmgonline[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@adultfriendfinder[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@ads.ontecnia[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@hitbox[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@media.adrevolver[3].txt
C:\Documents and Settings\Simzone\Cookies\simzone@partygaming.122.2o7[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@ads.yoyogames[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@metacafe.122.2o7[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@statcounter[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@ehg-foxsports.hitbox[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@ads.pointroll[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@mediaplex[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@adrevolver[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@xiti[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@doubleclick[1].txt
C:\Documents and Settings\Simzone\Cookies\simzone@specificclick[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@adserver.adservinginternational[2].txt
C:\Documents and Settings\Simzone\Cookies\simzone@ads.gamers-globe[2].txt
C:\Documents and Settings\De andre\Cookies\de_andre@fastclick[1].txt
C:\Documents and Settings\De andre\Cookies\de_andre@sonofon.112.2o7[1].txt
C:\Documents and Settings\De andre\Cookies\de_andre@adtech[1].txt
C:\Documents and Settings\De andre\Cookies\de_andre@apmebf[1].txt
C:\Documents and Settings\De andre\Cookies\de_andre@ads.dk-kogebogen[2].txt
C:\Documents and Settings\De andre\Cookies\de_andre@banners.mechquest[1].txt
C:\Documents and Settings\De andre\Cookies\de_andre@server.cpmstar[2].txt
C:\Documents and Settings\De andre\Cookies\de_andre@advertising[1].txt
C:\Documents and Settings\De andre\Cookies\de_andre@doubleclick[1].txt
C:\Documents and Settings\De andre\Cookies\de_andre@statcounter[1].txt
C:\Documents and Settings\x\Cookies\x@atdmt[1].txt
C:\Documents and Settings\x\Cookies\x@doubleclick[1].txt
C:\Documents and Settings\x\Cookies\x@lenovo.112.2o7[1].txt
C:\Documents and Settings\x\Cookies\x@msnportal.112.2o7[1].txt
C:\Documents and Settings\x\Cookies\x@track.adform[2].txt

Adware.180solutions/ZangoSearch
C:\Documents and Settings\All Users\Menuen Start\Programmer\Zango\Reset Cursor.lnk
C:\Documents and Settings\All Users\Menuen Start\Programmer\Zango\Weather.lnk
C:\Documents and Settings\All Users\Menuen Start\Programmer\Zango\Zango Customer Support Center.lnk
C:\Documents and Settings\All Users\Menuen Start\Programmer\Zango\Zango Games!.lnk
C:\Documents and Settings\All Users\Menuen Start\Programmer\Zango\Zango Library.lnk
C:\Documents and Settings\All Users\Menuen Start\Programmer\Zango\Zango Screensavers!.lnk
C:\Documents and Settings\All Users\Menuen Start\Programmer\Zango\Zango Uninstall Instructions.lnk
C:\Documents and Settings\All Users\Menuen Start\Programmer\Zango\Zango Videos!.lnk
C:\Documents and Settings\All Users\Menuen Start\Programmer\Zango
HKU\S-1-5-21-1715567821-2077806209-839522115-1003\Software\Zango
HKLM\Software\Zango
HKLM\Software\Zango\Install
HKLM\Software\Zango\Install#Install_Dir
HKLM\Software\Zango\Install#Installed_From
HKLM\Software\Zango\Install#IE
HKLM\Software\Zango\Install#OL
HKLM\Software\Zango\Install#OI
HKLM\Software\Zango\Install#WP
HKLM\Software\Zango\Install#SA
HKLM\Software\Zango\Install\CmpMap
HKLM\Software\Zango\Install\CmpMap#IE
HKLM\Software\Zango\Install\CmpMap#OL
HKLM\Software\Zango\Install\CmpMap#OI
HKLM\Software\Zango\Install\CmpMap#WP
HKLM\Software\Zango\Install\CmpMap#SA
HKLM\Software\Zango\Zango
HKLM\Software\Zango\Zango\Install
HKLM\Software\Zango\Zango\Install#StartInstall
HKLM\Software\Zango\Zango\Install#cookies_flag
HKLM\Software\Zango\Zango\Install#IID
HKLM\Software\Zango\Zango\Install#IID_prv
HKLM\Software\Zango\Zango\Install#PrevVer
HKLM\Software\Zango\Zango\Install#CurrentVer
HKLM\Software\Zango\Zango\Install#HbHostOEPath
HKLM\Software\Zango\Zango\MachineInfo
HKLM\Software\Zango\Zango\MachineInfo#CID
HKLM\Software\Zango\Zango\MachineInfo#CID_prv
HKLM\Software\Zango\Zango\PI
HKLM\Software\Zango\Zango\PI\3.2
HKLM\Software\Zango\Zango\PI\3.2#PID00

Adware.Zango Toolbar/Hb
HKCR\Srv.CoreServices
HKCR\Srv.CoreServices\CLSID
HKCR\Srv.CoreServices\CurVer
HKCR\Srv.CoreServices.1
HKCR\Srv.CoreServices.1\CLSID
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA#DisplayIcon
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA#DisplayVersion
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA#HelpLink
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA#Publisher
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA#URLInfoAbout
C:\Documents and Settings\Simzone\Application Data\Zango

Adware.Zango/ShoppingReport
HKCR\WeatherDPA.WeatherController
HKCR\WeatherDPA.WeatherController\CLSID
HKCR\WeatherDPA.WeatherController\CurVer
HKCR\WeatherDPA.WeatherController.1
HKCR\WeatherDPA.WeatherController.1\CLSID
HKCR\CLSID\{70880CE6-308C-4204-A89E-B266C3F7B7FA}
HKCR\CLSID\{70880CE6-308C-4204-A89E-B266C3F7B7FA}\LocalServer32
HKCR\CLSID\{70880CE6-308C-4204-A89E-B266C3F7B7FA}\ProgID
HKCR\CLSID\{70880CE6-308C-4204-A89E-B266C3F7B7FA}\Programmable
HKCR\CLSID\{70880CE6-308C-4204-A89E-B266C3F7B7FA}\TypeLib
HKCR\CLSID\{70880CE6-308C-4204-A89E-B266C3F7B7FA}\VersionIndependentProgID
HKCR\CLSID\{9473559B-50FC-4A8A-829B-E152E8D6A307}
HKCR\CLSID\{9473559B-50FC-4A8A-829B-E152E8D6A307}\LocalServer32
HKCR\CLSID\{9473559B-50FC-4A8A-829B-E152E8D6A307}\ProgID
HKCR\CLSID\{9473559B-50FC-4A8A-829B-E152E8D6A307}\Programmable
HKCR\CLSID\{9473559B-50FC-4A8A-829B-E152E8D6A307}\TypeLib
HKCR\CLSID\{9473559B-50FC-4A8A-829B-E152E8D6A307}\VersionIndependentProgID
HKCR\TypeLib\{03D7FF6E-9781-40B5-BB7F-94291A361604}
HKCR\TypeLib\{03D7FF6E-9781-40B5-BB7F-94291A361604}\1.0
HKCR\TypeLib\{03D7FF6E-9781-40B5-BB7F-94291A361604}\1.0\0
HKCR\TypeLib\{03D7FF6E-9781-40B5-BB7F-94291A361604}\1.0\0\win32
HKCR\TypeLib\{03D7FF6E-9781-40B5-BB7F-94291A361604}\1.0\FLAGS
HKCR\TypeLib\{03D7FF6E-9781-40B5-BB7F-94291A361604}\1.0\HELPDIR
HKCR\TypeLib\{A56FE01C-77C4-4F5E-8198-E4B72207890A}
HKCR\TypeLib\{A56FE01C-77C4-4F5E-8198-E4B72207890A}\1.0
HKCR\TypeLib\{A56FE01C-77C4-4F5E-8198-E4B72207890A}\1.0\0
HKCR\TypeLib\{A56FE01C-77C4-4F5E-8198-E4B72207890A}\1.0\0\win32
HKCR\TypeLib\{A56FE01C-77C4-4F5E-8198-E4B72207890A}\1.0\FLAGS
HKCR\TypeLib\{A56FE01C-77C4-4F5E-8198-E4B72207890A}\1.0\HELPDIR
HKCR\Interface\{0AF9A087-0CBF-46B2-9DC9-52D0D16B5AB6}
HKCR\Interface\{0AF9A087-0CBF-46B2-9DC9-52D0D16B5AB6}\ProxyStubClsid
HKCR\Interface\{0AF9A087-0CBF-46B2-9DC9-52D0D16B5AB6}\ProxyStubClsid32
HKCR\Interface\{0AF9A087-0CBF-46B2-9DC9-52D0D16B5AB6}\TypeLib
HKCR\Interface\{0AF9A087-0CBF-46B2-9DC9-52D0D16B5AB6}\TypeLib#Version
HKCR\Interface\{15B13E59-924A-4938-AE3C-C4F625F0B1D0}
HKCR\Interface\{15B13E59-924A-4938-AE3C-C4F625F0B1D0}\ProxyStubClsid
HKCR\Interface\{15B13E59-924A-4938-AE3C-C4F625F0B1D0}\ProxyStubClsid32
HKCR\Interface\{15B13E59-924A-4938-AE3C-C4F625F0B1D0}\TypeLib
HKCR\Interface\{15B13E59-924A-4938-AE3C-C4F625F0B1D0}\TypeLib#Version
HKCR\Interface\{15FD8424-D12A-4C51-8C6C-D5D57B80F781}
HKCR\Interface\{15FD8424-D12A-4C51-8C6C-D5D57B80F781}\ProxyStubClsid
HKCR\Interface\{15FD8424-D12A-4C51-8C6C-D5D57B80F781}\ProxyStubClsid32
HKCR\Interface\{15FD8424-D12A-4C51-8C6C-D5D57B80F781}\TypeLib
HKCR\Interface\{15FD8424-D12A-4C51-8C6C-D5D57B80F781}\TypeLib#Version
HKCR\Interface\{3CEB04AB-08AF-45F4-81B4-70D13C1F7B85}
HKCR\Interface\{3CEB04AB-08AF-45F4-81B4-70D13C1F7B85}\ProxyStubClsid
HKCR\Interface\{3CEB04AB-08AF-45F4-81B4-70D13C1F7B85}\ProxyStubClsid32
HKCR\Interface\{3CEB04AB-08AF-45F4-81B4-70D13C1F7B85}\TypeLib
HKCR\Interface\{3CEB04AB-08AF-45F4-81B4-70D13C1F7B85}\TypeLib#Version
HKCR\Interface\{67B3BECF-7B6F-42B2-99F0-F7656F89CFFA}
HKCR\Interface\{67B3BECF-7B6F-42B2-99F0-F7656F89CFFA}\ProxyStubClsid
HKCR\Interface\{67B3BECF-7B6F-42B2-99F0-F7656F89CFFA}\ProxyStubClsid32
HKCR\Interface\{67B3BECF-7B6F-42B2-99F0-F7656F89CFFA}\TypeLib
HKCR\Interface\{67B3BECF-7B6F-42B2-99F0-F7656F89CFFA}\TypeLib#Version
HKCR\Interface\{715FFD42-4E05-4EAB-9513-C8DAA5395AE2}
HKCR\Interface\{715FFD42-4E05-4EAB-9513-C8DAA5395AE2}\ProxyStubClsid
HKCR\Interface\{715FFD42-4E05-4EAB-9513-C8DAA5395AE2}\ProxyStubClsid32
HKCR\Interface\{715FFD42-4E05-4EAB-9513-C8DAA5395AE2}\TypeLib
HKCR\Interface\{715FFD42-4E05-4EAB-9513-C8DAA5395AE2}\TypeLib#Version
HKCR\Interface\{759D6F7C-8D30-45B6-ABEA-FA51C190EED5}
HKCR\Interface\{759D6F7C-8D30-45B6-ABEA-FA51C190EED5}\ProxyStubClsid
HKCR\Interface\{759D6F7C-8D30-45B6-ABEA-FA51C190EED5}\ProxyStubClsid32
HKCR\Interface\{759D6F7C-8D30-45B6-ABEA-FA51C190EED5}\TypeLib
HKCR\Interface\{759D6F7C-8D30-45B6-ABEA-FA51C190EED5}\TypeLib#Version
HKCR\Interface\{9A4A64A4-A2FB-48FA-9BBA-1AC50267695D}
HKCR\Interface\{9A4A64A4-A2FB-48FA-9BBA-1AC50267695D}\ProxyStubClsid
HKCR\Interface\{9A4A64A4-A2FB-48FA-9BBA-1AC50267695D}\ProxyStubClsid32
HKCR\Interface\{9A4A64A4-A2FB-48FA-9BBA-1AC50267695D}\TypeLib
HKCR\Interface\{9A4A64A4-A2FB-48FA-9BBA-1AC50267695D}\TypeLib#Version
HKCR\Interface\{A7213D71-47E1-4832-92D7-D61DFE9F231F}
HKCR\Interface\{A7213D71-47E1-4832-92D7-D61DFE9F231F}\ProxyStubClsid
HKCR\Interface\{A7213D71-47E1-4832-92D7-D61DFE9F231F}\ProxyStubClsid32
HKCR\Interface\{A7213D71-47E1-4832-92D7-D61DFE9F231F}\TypeLib
HKCR\Interface\{A7213D71-47E1-4832-92D7-D61DFE9F231F}\TypeLib#Version
HKCR\Interface\{AF55160D-CDE1-4A8B-8001-66DA06BEE740}
HKCR\Interface\{AF55160D-CDE1-4A8B-8001-66DA06BEE740}\ProxyStubClsid
HKCR\Interface\{AF55160D-CDE1-4A8B-8001-66DA06BEE740}\ProxyStubClsid32
HKCR\Interface\{AF55160D-CDE1-4A8B-8001-66DA06BEE740}\TypeLib
HKCR\Interface\{AF55160D-CDE1-4A8B-8001-66DA06BEE740}\TypeLib#Version
HKCR\Interface\{CF82F350-E1C4-4916-AC12-BA73DB60AFB7}
HKCR\Interface\{CF82F350-E1C4-4916-AC12-BA73DB60AFB7}\ProxyStubClsid
HKCR\Interface\{CF82F350-E1C4-4916-AC12-BA73DB60AFB7}\ProxyStubClsid32
HKCR\Interface\{CF82F350-E1C4-4916-AC12-BA73DB60AFB7}\TypeLib
HKCR\Interface\{CF82F350-E1C4-4916-AC12-BA73DB60AFB7}\TypeLib#Version
HKU\S-1-5-21-1715567821-2077806209-839522115-1003\Software\ShoppingReport
C:\Documents and Settings\Simzone\Application Data\WeatherDPA\Weather\WeatherDPA\Weather_XML
C:\Documents and Settings\Simzone\Application Data\WeatherDPA\Weather\WeatherDPA
C:\Documents and Settings\Simzone\Application Data\WeatherDPA\Weather\WeatherStartup.xml
C:\Documents and Settings\Simzone\Application Data\WeatherDPA\Weather
C:\Documents and Settings\Simzone\Application Data\WeatherDPA

Trojan.Dropper/BHONew-D
C:\SYSTEM VOLUME INFORMATION\_RESTORE{2443E918-05BF-447E-8D20-F5AAAF5B36E2}\RP271\A0088778.DLL





DrWeb:
saswinlo.dll c:\programmer\superantispyware Trojan.Fakealert.1239 Deleted.
sysera.dll c:\windows\system32 Trojan.BhoStorage.1 Deleted.
mirc631.exe\data015 C:\Documents and Settings\Simzone\Lokale indstillinger\Temp\mirc631.exe Program.mIRC.623
mirc631.exe C:\Documents and Settings\Simzone\Lokale indstillinger\Temp Archive contains infected objects Moved.
data007\yhelper.dll C:\Documents and Settings\Simzone\Lokale indstillinger\Temp\DivF.tmp\DivXInstaller.exe\data013\data007 Adware.Yassist.21
data007 C:\Documents and Settings\Simzone\Lokale indstillinger\Temp\DivF.tmp\DivXInstaller.exe\data013 Archive contains infected objects
data016\sremove.exe C:\Documents and Settings\Simzone\Lokale indstillinger\Temp\DivF.tmp\DivXInstaller.exe\data013\data016 Adware.Yassist.origin
data016 C:\Documents and Settings\Simzone\Lokale indstillinger\Temp\DivF.tmp\DivXInstaller.exe\data013 Archive contains infected objects
data002\data001 C:\Documents and Settings\Simzone\Lokale indstillinger\Temp\DivF.tmp\DivXInstaller.exe\data013\data045\data002 Adware.Cdn
data002\data002 C:\Documents and Settings\Simzone\Lokale indstillinger\Temp\DivF.tmp\DivXInstaller.exe\data013\data045\data002 Adware.Cdn
data002 C:\Documents and Settings\Simzone\Lokale indstillinger\Temp\DivF.tmp\DivXInstaller.exe\data013\data045 Archive contains infected objects
data045 C:\Documents and Settings\Simzone\Lokale indstillinger\Temp\DivF.tmp\DivXInstaller.exe\data013 Archive contains infected objects
data013\data049 C:\Documents and Settings\Simzone\Lokale indstillinger\Temp\DivF.tmp\DivXInstaller.exe\data013 Adware.Cdn
data013 C:\Documents and Settings\Simzone\Lokale indstillinger\Temp\DivF.tmp\DivXInstaller.exe Archive contains infected objects
DivXInstaller.exe C:\Documents and Settings\Simzone\Lokale indstillinger\Temp\DivF.tmp Archive contains infected objects Moved.
data002\data015 C:\Documents and Settings\Simzone\Skrivebord\Hackede maps og alt muligt\other\mirc631.exe\data002 Program.mIRC.623
data002 C:\Documents and Settings\Simzone\Skrivebord\Hackede maps og alt muligt\other\mirc631.exe Archive contains infected objects
mirc631.exe C:\Documents and Settings\Simzone\Skrivebord\Hackede maps og alt muligt\other Archive contains infected objects Moved.
stream000\SASWINLO.dll C:\Programmer\Fælles filer\Wise Installation Wizard\WISCDDCBBF1270346BC938BBCC81A1EEAAA_4_0_0_1154.MSI\stream000 Trojan.Fakealert.1239
stream000 C:\Programmer\Fælles filer\Wise Installation Wizard\WISCDDCBBF1270346BC938BBCC81A1EEAAA_4_0_0_1154.MSI Archive contains infected objects
WISCDDCBBF1270346BC938BBCC81A1EEAAA_4_0_0_1154.MSI C:\Programmer\Fælles filer\Wise Installation Wizard Archive contains infected objects Moved.
mirc.exe C:\Programmer\mIRC Program.mIRC.623 Moved.
mirc.exe C:\Programmer\mIRC\backups Program.mIRC.623 Moved.
stream000\SASWINLO.dll C:\System Volume Information\_restore{2443E918-05BF-447E-8D20-F5AAAF5B36E2}\RP271\A0088682.msi\stream000 Trojan.Fakealert.1239
stream000 C:\System Volume Information\_restore{2443E918-05BF-447E-8D20-F5AAAF5B36E2}\RP271\A0088682.msi Archive contains infected objects
A0088682.msi C:\System Volume Information\_restore{2443E918-05BF-447E-8D20-F5AAAF5B36E2}\RP271 Archive contains infected objects Moved.
A0088683.dll C:\System Volume Information\_restore{2443E918-05BF-447E-8D20-F5AAAF5B36E2}\RP271 Trojan.BhoStorage.1 Deleted.
data002\data015 C:\System Volume Information\_restore{2443E918-05BF-447E-8D20-F5AAAF5B36E2}\RP271\A0088686.exe\data002 Program.mIRC.623
data002 C:\System Volume Information\_restore{2443E918-05BF-447E-8D20-F5AAAF5B36E2}\RP271\A0088686.exe Archive contains infected objects
A0088686.exe C:\System Volume Information\_restore{2443E918-05BF-447E-8D20-F5AAAF5B36E2}\RP271 Archive contains infected objects Moved.
stream000\SASWINLO.dll C:\System Volume Information\_restore{2443E918-05BF-447E-8D20-F5AAAF5B36E2}\RP271\A0088690.MSI\stream000 Trojan.Fakealert.1239
stream000 C:\System Volume Information\_restore{2443E918-05BF-447E-8D20-F5AAAF5B36E2}\RP271\A0088690.MSI Archive contains infected objects
A0088690.MSI C:\System Volume Information\_restore{2443E918-05BF-447E-8D20-F5AAAF5B36E2}\RP271 Archive contains infected objects Moved.
A0088748.exe C:\System Volume Information\_restore{2443E918-05BF-447E-8D20-F5AAAF5B36E2}\RP271 Program.mIRC.623 Moved.
A0088749.exe C:\System Volume Information\_restore{2443E918-05BF-447E-8D20-F5AAAF5B36E2}\RP271 Program.mIRC.623 Moved.
smsani.dll C:\WINDOWS\system32 Trojan.BhoStorage.1 Deleted.





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:34:25, on 24-08-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Programmer\McAfee\Common Framework\UdaterUI.exe
C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe
C:\Programmer\Logitech\QuickCam\Quickcam.exe
C:\Programmer\McAfee\Common Framework\McTray.exe
C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe
C:\Programmer\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Programmer\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\Programmer\Echovoice\Gamer Statistics\G15 Echovoice Gamer Statistics.exe
C:\Programmer\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe
C:\Programmer\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe
C:\Programmer\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe
C:\Programmer\Electronic Arts\EADM\Core.exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\programmer\steam\steam.exe
C:\Programmer\Arto\Notifier\ArtoNotifier.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\Logitech\SetPoint II\SetpointII.exe
C:\Programmer\Fælles filer\Logishrd\KHAL2\KHALMNPR.EXE
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmer\Bonjour\mDNSResponder.exe
C:\Programmer\Fælles filer\LogiShrd\LVCOMSER\LVComSer.exe
C:\Programmer\McAfee\Common Framework\FrameworkService.exe
C:\Programmer\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Programmer\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Fælles filer\LogiShrd\LVCOMSER\LVComSer.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Fælles filer\Logishrd\LQCVFX\COCIManager.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\Programmer\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programmer\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Simon ting\rpbrowserrecordplugin.dll
O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Programmer\Dealio\kb124\Dealio.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Programmer\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Programmer\Dealio\kb124\Dealio.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\Programmer\ImageShackToolbar\ImageShackToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ShStatEXE] "C:\Programmer\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Programmer\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [au] C:\Programmer\Dealio\DealioAU.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Programmer\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Programmer\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Programmer\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Echovoice Gamer Statistics] C:\Programmer\Echovoice\Gamer Statistics\G15 Echovoice Gamer Statistics.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [EA Core] "C:\Programmer\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Steam] "c:\programmer\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ArtoNotifier] C:\Programmer\Arto\Notifier\ArtoNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: SetPointII.lnk = ?
O8 - Extra context menu item: Compare Prices with &Dealio - C:\Documents and Settings\Simzone\Application Data\Dealio\kb124\res\DealioSearch.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Post Image to Blog - res://C:\Programmer\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Tag This Image - res://C:\Programmer\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Transload Image to ImageShack - res://C:\Programmer\ImageShackToolbar\ImageShackToolbar.dll/5004
O8 - Extra context menu item: Upload All Images to ImageShack - res://C:\Programmer\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://C:\Programmer\ImageShackToolbar\ImageShackToolbar.dll/5001
O8 - Extra context menu item: Åbn billede i &Microsoft PhotoDraw - res://C:\PROGRA~1\MICROS~2\Office\1030\phdintl.dll/phdContext.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmer\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmer\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmer\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Programmer\Dealio\kb124\Dealio.dll (file missing)
O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Programmer\Dealio\kb124\Dealio.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - http://www-307.ibm.com/pc/support/acpir.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager-kontrol) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmer\Fælles filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Programmer\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Programmer\Fælles filer\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Programmer\Fælles filer\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Programmer\Fælles filer\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Programmer\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Programmer\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Programmer\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Ventrilo - Unknown owner - C:\Programmer\VentSrv\ventrilo_svc.exe (file missing)

--
End of file - 13084 bytes





Tak for den hjælp jeg håber at få :) men ellers tak for den gode guide :D
25. august 2008 - 18:30 #1
Joooo - der blev jo nappet en del 'snavs'...
Oplever du nogle problemer derefter ?

Du kunne jo lige ta' denne pakke også ->

Hent og instalér CCleaner http://www.ccleaner.com/ + http://www.spywarefri.dk/manualer/ccleaner-manual.htm
Under installationen får du tilbudt [Yahoo Toolbar]. Du kan sige ja eller *NEJ* til den.
Lad programmet foretage en oprydning...

--------

Hent Malwarebytes Anti-Malware herfra:
http://www.besttechie.net/tools/mbam-setup.exe
Eller herfra ->
http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html

Installer programmet - når det er gjort skal du lade programmet opdatere sig. Herefter åbner et vindue, hvor du skal flytte prikken til "Kør et fuldstændigt systemscan" - klik på Skan Knappen - lad programmet arbejde. Når det er færdig (det tager lidt tid afhængig af hvor meget du har på computeren).
Derefter - Tryk på "Vis resultater" knappen efter scanningen - og herefter tryk på "Fjern det valgte" - nu åbnes log'en og du skal gemme den et sted, hvor du kan finde den igen.
Kopier indholdet herind sammen med en frisk log fra HiJackThis...
25. august 2008 - 18:31 #2
Velkommen til eksperten.dk
Generelt -> http://expfaq.dk/
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester