John_stighers: Det er sgu helt okay ;)
Så har jeg fået tid til at scanne med malware, og det har da hjulpet betydeligt! Her kommer en log fra scanningen:
Malwarebytes' Anti-Malware 1.28
Database version: 1201
Windows 5.1.2600 Service Pack 2
24-09-2008 18:26:31
mbam-log-2008-09-24 (18-26-31).txt
Skan type: Fuldstændig skanning (C:\|)
Objekter skannet: 107841
Tid tilbagelagt: 53 minute(s), 35 second(s)
Inficerede Hukommelses Processer: 4
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 15
Inficerede Registeringsdatabase Værdier: 8
Inficerede Registeringsdatabase Filer: 12
Inficerede Mapper: 2
Inficerede Filer: 28
Inficerede Hukommelses Processer:
C:\WINDOWS\system32\algg.exe (Trojan.Zlob) -> Failed to unload process.
C:\Programmer\Applications\iebtm.exe (Trojan.Zlob) -> Unloaded process successfully.
C:\Programmer\Applications\iebtmm.exe (Trojan.Zlob) -> Unloaded process successfully.
C:\Programmer\Applications\wcm.exe (Trojan.Zlob) -> Unloaded process successfully.
Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)
Inficerede Registeringsdatabase Nøgler:
HKEY_CLASSES_ROOT\y456.y456mgr (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\y456.y456mgr.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f7d09218-46d7-4d3d-9b7f-315204cd0836} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{616f9ab4-a605-48b5-b7ae-b6b68e6c3cab} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{144a6b24-0ebc-4d89-bf09-a06a718e57b5} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{cfee97a3-4911-444d-8be8-e243a23d3de2} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cfee97a3-4911-444d-8be8-e243a23d3de2} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e63648f7-3933-440e-b4f6-a8584dd7b7eb} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{daed9266-8c28-4c1c-8b58-5c66eff1d302} (Search.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\e405.e405mgr (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEBrowse Tool (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IExplorer Bar (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Warning Center (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\multimediaControls.chl (Trojan.Zlob) -> Quarantined and deleted successfully.
Inficerede Registeringsdatabase Værdier:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\antivirus (Rogue.WindowsAntivirus2008) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\antivirus (Rogue.WindowsAntivirus2008) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wblogon (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\start (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securewebinfo.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.safetyincludes.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securemanaging.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\smile (Trojan.Zlob) -> Delete on reboot.
Inficerede Registeringsdatabase Filer:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Hijack.Search) -> Bad: (
http://windowsisearch.com) Good: (
http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Hijack.Search) -> Bad: (
http://windowsisearch.com) Good: (
http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Search_URL (Hijack.Search) -> Bad: (
http://windowsisearch.com) Good: (
http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Search_URL (Hijack.Search) -> Bad: (
http://windowsisearch.com) Good: (
http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Page (Hijack.Search) -> Bad: (
http://windowsisearch.com) Good: (
http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Search Page (Hijack.Search) -> Bad: (
http://windowsisearch.com) Good: (
http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar (Hijack.Search) -> Bad: (
http://windowsisearch.com/ie6.html) Good: (
http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar (Hijack.Search) -> Bad: (
http://windowsisearch.com/ie6.html) Good: (
http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -> Bad: (
http://windowsisearch.com/search?q={searchTerms}) Good: (
http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -> Bad: (
http://windowsisearch.com/search?q={searchTerms}) Good: (
http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\SearchAssistant (Hijack.Search) -> Bad: (
http://windowsisearch.com) Good: (
http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Search\SearchAssistant (Hijack.Search) -> Bad: (
http://windowsisearch.com) Good: (
http://www.google.com/) -> Quarantined and deleted successfully.
Inficerede Mapper:
C:\Programmer\WAV (Rogue.WindowsAntivirus2008) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\829275 (Trojan.BHO) -> Quarantined and deleted successfully.
Inficerede Filer:
C:\Programmer\Applications\iebt.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{278626FF-D76E-46BF-A99A-3B81FEB2E467}\RP138\A0052900.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\829275\829275.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Programmer\WAV\wav.cpl (Rogue.WindowsAntivirus2008) -> Quarantined and deleted successfully.
C:\Programmer\WAV\wav.exe (Rogue.WindowsAntivirus2008) -> Quarantined and deleted successfully.
C:\Programmer\WAV\wav1.dat (Rogue.WindowsAntivirus2008) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wav.cpl (Rogue.WindowsAntivirus2008) -> Quarantined and deleted successfully.
C:\xptray.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\algg.exe (Trojan.Zlob) -> Delete on reboot.
C:\Documents and Settings\All Users\Menuen Start\Antivirus Scan.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Menuen Start\Online Spyware Test.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Programmer\Applications\iebtm.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Programmer\Applications\iebtmm.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Programmer\Applications\iebtu.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Programmer\Applications\iebu.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Programmer\Applications\myd.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Programmer\Applications\mym.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Programmer\Applications\myp.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Programmer\Applications\myv.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Programmer\Applications\ot.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Programmer\Applications\ts.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Programmer\Applications\wcm.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Programmer\Applications\wcu.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Programmer\MSX\msx1.dat (Rogue.MSAntivirus) -> Quarantined and deleted successfully.
C:\Programmer\MSX\MSX.cpl (Rogue.MSAntivirus) -> Quarantined and deleted successfully.
C:\Programmer\MSX\msx.ooo (Rogue.MSAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Niels\Lokale indstillinger\Temp\xrg2.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Documents and Settings\Niels\Foretrukne\Antivirus Scan.url (Rogue.Link) -> Quarantined and deleted successfully.