Avatar billede mivroth Nybegynder
09. december 2008 - 08:56 Der er 3 kommentarer og
1 løsning

Nogle der gider kigge disse log igemmen

Hej

Har lige 2 log filer


ComboFix 08-12-07.01 - Ejer 2008-12-09  0:19:31.1 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1030.18.687 [GMT 1:00]
Kører fra: c:\documents and settings\Ejer\Skrivebord\ComboFix.exe
* Dannede nyt systemgendannelsespunkt

[COLOR=RED][B]advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !![/B][/COLOR]
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programmer\AntiSpywareExpert
c:\programmer\AntiSpywareExpert\BL.dat
c:\programmer\AntiSpywareExpert\WL.dat
c:\windows\admintxt.txt
c:\windows\service.exe
c:\windows\system32\agvrcddf.dll
c:\windows\system32\antiwpa.dll
c:\windows\system32\dawapyeg.ini
c:\windows\system32\fhqhol.dll
c:\windows\system32\hgGaARhg.dll
c:\windows\system32\hilrlgbx.dll
c:\windows\system32\kbihwjvq.ini
c:\windows\system32\mlJAroml.dll
c:\windows\system32\nniprcul.dll
c:\windows\system32\opnnkkHb.dll
c:\windows\system32\tDfLRqru.ini
c:\windows\system32\tDfLRqru.ini2
c:\windows\system32\ttxqfm.dll
c:\windows\system32\ygdkmfof.ini

.
(((((((((((((((((((((((((((((  Filer skabt fra 2008-11-09 til 2008-12-09  )))))))))))))))))))))))))))))))))))
.

2008-12-09 00:13 . 2008-12-09 00:16    <DIR>    d--------    c:\windows\SxsCaPendDel
2008-12-09 00:09 . 2008-12-09 00:09    <DIR>    d--------    c:\documents and settings\All Users\Application Data\Avg7
2008-12-08 23:31 . 2008-12-08 23:31    <DIR>    d--------    c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-12-08 23:23 . 2008-12-08 23:23    <DIR>    d--------    c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-08 23:22 . 2008-12-08 23:22    <DIR>    d--------    c:\programmer\SUPERAntiSpyware
2008-12-08 23:22 . 2008-12-08 23:22    <DIR>    d--------    c:\programmer\Fælles filer\Wise Installation Wizard
2008-12-08 23:22 . 2008-12-08 23:22    <DIR>    d--------    c:\documents and settings\Ejer\Application Data\SUPERAntiSpyware.com
2008-12-08 23:12 . 2008-12-08 23:12    <DIR>    d--------    c:\programmer\CCleaner
2008-12-08 22:24 . 2008-12-08 22:24    <DIR>    d--------    c:\programmer\ltmoh
2008-12-08 22:24 . 2007-11-06 15:38    1,161,888    --a------    c:\windows\system32\drivers\AGRSM.sys
2008-12-08 22:24 . 2007-11-06 15:38    491,520    --a------    c:\windows\system32\cselect.exe
2008-12-08 22:24 . 2007-11-06 15:38    128,113    --a------    c:\windows\system32\csellang.ini
2008-12-08 22:24 . 2007-11-06 15:38    77,824    --a------    c:\windows\system32\tosmreg.exe
2008-12-08 22:24 . 2007-11-06 15:38    45,056    --a------    c:\windows\system32\csellang.dll
2008-12-08 22:24 . 2007-11-06 15:38    13,312    --a------    c:\windows\system32\agrscoin.dll
2008-12-08 22:24 . 2007-11-06 15:38    10,150    --a------    c:\windows\system32\tosmreg.ini
2008-12-08 22:24 . 2007-11-06 15:38    9,216    --a------    c:\windows\system32\agrsmsvc.exe
2008-12-08 22:24 . 2007-11-06 15:38    7,671    --a------    c:\windows\system32\cseltbl.ini
2008-12-08 22:08 . 2008-12-09 00:09    <DIR>    d--------    c:\documents and settings\Administrator\Skrivebord
2008-12-08 22:08 . 2008-10-29 12:05    <DIR>    d--h-----    c:\documents and settings\Administrator\Skabeloner
2008-12-08 22:08 . 2008-10-29 13:01    <DIR>    d--h-----    c:\documents and settings\Administrator\Printere
2008-12-08 22:08 . 2008-10-29 13:01    <DIR>    dr-------    c:\documents and settings\Administrator\Menuen Start
2008-12-08 22:08 . 2008-10-29 13:01    <DIR>    d--h-----    c:\documents and settings\Administrator\Lokale indstillinger
2008-12-08 22:08 . 2008-10-29 13:01    <DIR>    d--------    c:\documents and settings\Administrator\Foretrukne
2008-12-08 22:08 . 2008-10-29 13:01    <DIR>    d--------    c:\documents and settings\Administrator\Dokumenter
2008-12-08 22:08 . 2008-10-29 13:01    <DIR>    d--h-----    c:\documents and settings\Administrator\Andre computere
2008-12-08 22:08 . 2008-12-08 22:08    <DIR>    d--------    c:\documents and settings\Administrator
2008-11-27 17:42 . 2008-11-27 17:42    268    --ah-----    C:\sqmdata08.sqm
2008-11-27 17:42 . 2008-11-27 17:42    244    --ah-----    C:\sqmnoopt08.sqm
2008-11-27 17:27 . 2008-11-27 17:27    268    --ah-----    C:\sqmdata07.sqm
2008-11-27 17:27 . 2008-11-27 17:27    244    --ah-----    C:\sqmnoopt07.sqm
2008-11-27 16:13 . 2008-11-27 16:13    268    --ah-----    C:\sqmdata06.sqm
2008-11-27 16:13 . 2008-11-27 16:13    244    --ah-----    C:\sqmnoopt06.sqm
2008-11-27 15:55 . 2008-11-27 15:55    <DIR>    d--------    c:\programmer\TickUploadIso
2008-11-27 15:48 . 2008-11-27 15:48    268    --ah-----    C:\sqmdata05.sqm
2008-11-27 15:48 . 2008-11-27 15:48    244    --ah-----    C:\sqmnoopt05.sqm
2008-11-27 01:49 . 2008-11-27 01:49    268    --ah-----    C:\sqmdata04.sqm
2008-11-27 01:49 . 2008-11-27 01:49    244    --ah-----    C:\sqmnoopt04.sqm
2008-11-27 00:13 . 2008-11-27 00:13    <DIR>    d--------    c:\documents and settings\Ejer\Application Data\Birdstep Technology
2008-11-27 00:13 . 2007-05-28 17:00    10,240    ---------    c:\windows\system32\drivers\mdvrmng.sys
2008-11-24 15:03 . 2008-11-24 15:03    24    --a------    c:\windows\cdplayer.ini
2008-11-20 19:43 . 2008-11-20 19:43    <DIR>    d--------    c:\programmer\Lavasoft
2008-11-20 19:42 . 2008-11-20 19:42    <DIR>    d--------    c:\programmer\SysShield Tools
2008-11-19 15:09 . 2008-11-19 15:09    <DIR>    d--------    c:\programmer\PhotoFiltre
2008-11-18 21:50 . 2008-11-18 21:50    246,272    --a------    c:\windows\system32\urqRLfDt.VIR
2008-11-17 13:05 . 2008-11-17 13:05    <DIR>    d--------    C:\Nørresundby Bank
2008-11-17 00:53 . 2008-11-17 00:53    <DIR>    d--------    c:\programmer\MSN Messenger
2008-11-14 18:05 . 2008-11-14 18:05    1,025    --a------    c:\windows\web32.exe
2008-11-14 15:13 . 2008-11-14 15:13    45,056    --a------    c:\documents and settings\Ejer\javaplugin.exe
2008-11-12 13:13 . 2008-04-14 17:05    21,504    --a------    c:\windows\system32\hidserv.dll
2008-11-12 13:13 . 2008-04-14 17:05    21,504    --a--c---    c:\windows\system32\dllcache\hidserv.dll
2008-11-12 13:13 . 2008-04-14 16:42    14,720    --a------    c:\windows\system32\drivers\kbdhid.sys
2008-11-12 13:13 . 2008-04-14 16:42    14,720    --a--c---    c:\windows\system32\dllcache\kbdhid.sys
2008-11-12 01:14 . 2008-09-04 18:17    1,106,944    -----c---    c:\windows\system32\dllcache\msxml3.dll
2008-11-12 01:14 . 2008-10-24 12:21    455,296    -----c---    c:\windows\system32\dllcache\mrxsmb.sys
2008-11-11 20:30 . 2008-11-12 00:59    <DIR>    d--------    C:\output
2008-11-11 20:26 . 2008-11-12 00:48    <DIR>    d--------    c:\programmer\PhotoScape

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-08 23:12    ---------    d-----w    c:\programmer\VDOWNLOADER
2008-12-08 23:11    ---------    d-----w    c:\programmer\Windows Live
2008-12-08 23:08    ---------    d-----w    c:\programmer\Google
2008-11-27 14:56    ---------    d-----w    c:\documents and settings\Ejer\Application Data\TickUploadIso
2008-11-27 14:56    ---------    d-----w    c:\documents and settings\All Users\Application Data\comp two long internet
2008-11-26 23:12    69,361    ----a-w    c:\windows\Huawei ModemsUninstall.exe
2008-11-26 23:12    ---------    d--h--w    c:\programmer\InstallShield Installation Information
2008-11-26 23:01    ---------    d-----w    c:\documents and settings\All Users\Application Data\Birdstep Technology
2008-11-13 02:20    ---------    d-----w    c:\programmer\Messenger Plus! Live
2008-11-11 00:59    ---------    d-----w    c:\documents and settings\Ejer\Application Data\Azureus
2008-11-06 15:36    ---------    d-----w    c:\programmer\Dansk Trafikskole Materiel
2008-11-04 23:47    ---------    d-----w    c:\programmer\Windows Media Connect 2
2008-10-31 23:46    ---------    d-----w    c:\documents and settings\Ejer\Application Data\Media Player Classic
2008-10-31 23:36    ---------    d-----w    c:\documents and settings\Ejer\Application Data\Uniblue
2008-10-31 23:26    ---------    d-----w    c:\documents and settings\Ejer\Application Data\vlc
2008-10-31 23:23    ---------    d-----w    c:\programmer\VideoLAN
2008-10-30 18:49    ---------    d-----w    c:\programmer\Steam
2008-10-30 12:01    ---------    d-----w    c:\programmer\Fælles filer\InstallShield
2008-10-30 10:13    ---------    d-----w    c:\programmer\Microsoft CAPICOM 2.1.0.2
2008-10-30 00:25    ---------    d-----w    c:\documents and settings\Ejer\Application Data\Desktopicon
2008-10-29 23:19    ---------    d-----w    c:\programmer\Fælles filer\xing shared
2008-10-29 23:19    ---------    d-----w    c:\programmer\Fælles filer\Real
2008-10-29 23:00    ---------    d-----w    c:\documents and settings\All Users\Application Data\WLInstaller
2008-10-29 22:52    ---------    d-----w    c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-10-29 22:48    ---------    d-----w    c:\programmer\Circle Developement
2008-10-29 22:34    ---------    d-----w    c:\programmer\Adverts
2008-10-29 21:15    ---------    d-----w    c:\documents and settings\All Users\Application Data\avg8
2008-10-29 18:46    ---------    d-----w    c:\programmer\Java
2008-10-29 16:26    ---------    dcsh--w    c:\programmer\Fælles filer\WindowsLiveInstaller
2008-10-29 16:02    ---------    d-----w    c:\programmer\MessengerPlus! 3
2008-10-29 15:02    ---------    d-----w    c:\documents and settings\All Users\Application Data\Azureus
2008-10-29 14:42    ---------    d-----w    c:\programmer\Huawei Modems
2008-10-29 14:42    ---------    d-----w    c:\programmer\3
2008-10-29 13:15    319,488    ----a-w    c:\windows\HideWin.exe
2008-10-29 12:47    ---------    d-----w    c:\programmer\Intel
2008-10-29 12:42    ---------    d-----w    c:\programmer\Synaptics
2008-10-29 12:41    ---------    d-----w    c:\programmer\TOSHIBA
2008-10-29 11:36    ---------    d-----w    c:\programmer\Realtek
2008-10-29 11:33    ---------    d-----w    c:\programmer\REALTEK RTL8187B Wireless LAN Driver
2008-10-29 11:33    ---------    d-----w    c:\documents and settings\Ejer\Application Data\InstallShield
2008-10-29 11:11    ---------    d-----w    c:\programmer\microsoft frontpage
2008-10-29 11:10    ---------    d-----w    c:\programmer\Fælles filer\Java
2008-10-29 11:07    ---------    d-----w    c:\programmer\Onlinetjenester
2008-10-29 11:06    ---------    d-----w    c:\programmer\Fælles filer\Tjenester
2008-10-29 08:38    277,784    ----a-w    c:\windows\system32\drivers\iaStor.sys
2008-10-24 11:21    455,296    ----a-w    c:\windows\system32\drivers\mrxsmb.sys
2008-10-13 17:26    4,879,360    ----a-w    c:\windows\system32\drivers\RtkHDAud.sys
2008-10-09 13:54    17,021,440    ----a-w    c:\windows\RTHDCPL.EXE
2008-09-30 15:38    2,168,320    ----a-w    c:\windows\MicCal.exe
2008-09-19 16:48    1,200,128    ----a-w    c:\windows\RtlUpd.exe
.

(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\programmer\Java\jre6\bin\jusched.exe" [2008-10-29 136600]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-11-06 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-11-06 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-11-06 138008]
"SynTPEnh"="c:\programmer\Synaptics\SynTP\SynTPEnh.exe" [2007-11-06 888832]
"TkBellExe"="c:\programmer\Fælles filer\Real\Update_OB\realsched.exe" [2008-10-30 185872]
"Long Internet Team Stupid"="c:\documents and settings\All Users\Application Data\comp two long internet\Mode hold.exe" [2008-12-09 2450432]
"NDSTray.exe"="NDSTray.exe" [BU]
"RTHDCPL"="RTHDCPL.EXE" [2008-10-09 c:\windows\RTHDCPL.EXE]
"CFSServ.exe"="CFSServ.exe" [BU]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Menuen Start\Programmer\Start\
Opdateringsagent.lnk - c:\programmer\3\3Connect\AutoUpdateSrv.exe [2008-11-27 442368]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmer\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 c:\programmer\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=fbbspk.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmer\\MSN Messenger\\livecall.exe"=

S1 SASDIFSV;SASDIFSV;\??\c:\programmer\SUPERAntiSpyware\SASDIFSV.SYS [2008-02-29 8944]
S1 SASKUTIL;SASKUTIL;\??\c:\programmer\SUPERAntiSpyware\SASKUTIL.sys [2008-02-29 51440]
S2 mdvrmng;Mobile IP Route Manager;\??\c:\windows\system32\drivers\mdvrmng.sys [2008-11-27 10240]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187B.sys [2008-10-29 264576]
S3 SASENUM;SASENUM;\??\c:\programmer\SUPERAntiSpyware\SASENUM.SYS [2006-02-16 4096]
.
Indhold af mappen 'Planlagte Opgaver'

2008-12-08 c:\windows\Tasks\A3CA8AF79185086B.job
- c:\docume~1\ejer\applic~1\tickup~1\axis mix help.exe [2008-11-27 15:56]
.
- - - - TOMME GENVEJE FJERNET - - - -

BHO-{0500e8c7-675c-4a92-9ffc-dd8e934bd24d} - c:\windows\system32\fbbspk.dll
BHO-{47DEEE06-70FF-427E-A2EB-6C07B67C9257} - (no file)
BHO-{B1629D92-AFE4-4B23-A39D-B092F1D1BCBF} - (no file)
HKU-Default-Run-Picasa Media Detector - c:\programmer\Picasa2\PicasaMediaDetector.exe
ShellExecuteHooks-{B1629D92-AFE4-4B23-A39D-B092F1D1BCBF} - (no file)
Notify-yaywtQjK - yaywtQjK.dll



**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-09 08:47:03
Windows 5.1.2600 Service Pack 3 NTFS

scanner skjulte processer ...

scanner skjulte autostarter ...

scanner skjulte filer ...

scanning gennemført med succes
skjulte filer: 0

**************************************************************************
.
--------------------- DLLs startet under kørende Processer ---------------------

- - - - - - - > 'winlogon.exe'(240)
c:\programmer\SUPERAntiSpyware\SASWINLO.dll
.
Gennemført tid: 2008-12-09  8:48:04 - maskinen blev genstartet [Administrator]
ComboFix-quarantined-files.txt  2008-12-09 07:48:02

Pre-Kørsel: 63.975.677.952 byte ledig
Post-Kørsel: 63,925,850,112 byte ledig

210    --- E O F ---    2008-11-14 05:49:15


Logfile of HijackThis v1.99.1
Scan saved at 00:18:09, on 09-12-2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Programmer\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programmer\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Programmer\TOSHIBA\ConfigFree\NDSTray.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\3\3Connect\AutoUpdateSrv.exe
C:\WINDOWS\service.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Ejer\Skrivebord\alternativ.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: {d42db439-e8dd-cff9-29a4-c5767c8e0050} - {0500e8c7-675c-4a92-9ffc-dd8e934bd24d} - C:\WINDOWS\system32\fbbspk.dll (file missing)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {47DEEE06-70FF-427E-A2EB-6C07B67C9257} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre6\bin\ssv.dll
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {B1629D92-AFE4-4B23-A39D-B092F1D1BCBF} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Windows Service] service.exe
O4 - HKLM\..\Run: [Long Internet Team Stupid] C:\Documents and Settings\All Users\Application Data\comp two long internet\Mode hold.exe
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Programmer\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [SOAP JOY] C:\DOCUME~1\Ejer\APPLIC~1\TICKUP~1\Bore Dumb.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Programmer\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Opdateringsagent.lnk = ?
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1225296488312
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=24931
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programmer\Windows Live\Mail\mailcomm.dll
O20 - AppInit_DLLs: fbbspk.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: yaywtQjK - yaywtQjK.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programmer\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Programmer\Java\jre6\bin\jqs.exe" -service -config "C:\Programmer\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
Avatar billede f-arn Guru
09. december 2008 - 12:49 #1
Hent "Malwarebytes' Anti-Malware" her: http://www.malwarebytes.org/mbam.php
Installer og start programmet, opdater, lav "fuld systemskanning" under fanebladet "skanner".
Bagefter klik på "vis resultater", tryk på "Fjern det valgte" og send loggen herind sammen med en log fra Hijackthis som du finder her:

http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe
Kør HijackThis, klik på "Do a systemscan scan and save a logfile"  kopier loggens tekst og send den herind.

Bemærk Hijackthis skal gemmes på computeren og ikke køres fra nettet

Og jo, brug denne version af hijachthis
Avatar billede mivroth Nybegynder
09. december 2008 - 21:20 #2
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:18, on 2008-12-09
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Programmer\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\Programmer\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Programmer\TOSHIBA\ConfigFree\NDSTray.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Programmer\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Programmer\3\3Connect\AutoUpdateSrv.exe
c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Programmer\3\3Connect\Wilog.exe
C:\Documents and Settings\Ejer\Skrivebord\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre6\bin\ssv.dll
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Programmer\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [SOAP JOY] C:\DOCUME~1\Ejer\APPLIC~1\TICKUP~1\Bore Dumb.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Programmer\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Opdateringsagent.lnk = ?
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1225296488312
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=24931
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3B504F77-35DA-4F5E-9130-F68E4624C43A}: NameServer = 80.251.201.177 80.251.201.178
O17 - HKLM\System\CS1\Services\Tcpip\..\{3B504F77-35DA-4F5E-9130-F68E4624C43A}: NameServer = 80.251.201.177 80.251.201.178
O20 - AppInit_DLLs: fbbspk.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programmer\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmer\Java\jre6\bin\jqs.exe

--
End of file - 5890 bytes

Malwarebytes' Anti-Malware 1.31
Database version: 1478
Windows 5.1.2600 Service Pack 3

2008-12-09 20:36:12
mbam-log-2008-12-09 (20-36-12).txt

Skan type: Fuldstændig skanning (C:\|)
Objekter skannet: 83335
Tid tilbagelagt: 18 minute(s), 33 second(s)

Inficerede Hukommelses Processer: 0
Inficerede Hukommelses Moduler: 1
Inficerede Registeringsdatabase Nøgler: 3
Inficerede Registeringsdatabase Værdier: 1
Inficerede Registeringsdatabase Filer: 0
Inficerede Mapper: 0
Inficerede Filer: 21

Inficerede Hukommelses Processer:
(Ingen mistænkelige filer fundet)

Inficerede Hukommelses Moduler:
C:\WINDOWS\system32\antiwpa.dll (Trojan.I.Stole.Windows) -> Delete on reboot.

Inficerede Registeringsdatabase Nøgler:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b1629d92-afe4-4b23-a39d-b092f1d1bcbf} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\antiwpa (Trojan.I.Stole.Windows) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.

Inficerede Registeringsdatabase Værdier:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Long Internet Team Stupid (Trojan.Agent) -> Quarantined and deleted successfully.

Inficerede Registeringsdatabase Filer:
(Ingen mistænkelige filer fundet)

Inficerede Mapper:
(Ingen mistænkelige filer fundet)

Inficerede Filer:
C:\Qoobox\Quarantine\C\WINDOWS\system32\agvrcddf.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\fhqhol.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\hgGaARhg.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\hilrlgbx.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\mlJAroml.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\nniprcul.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\opnnkkHb.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\ttxqfm.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{43618517-4DE3-4B08-B021-3EF239CA2B0C}\RP71\A0029150.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{43618517-4DE3-4B08-B021-3EF239CA2B0C}\RP78\A0040396.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{43618517-4DE3-4B08-B021-3EF239CA2B0C}\RP93\A0051294.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{43618517-4DE3-4B08-B021-3EF239CA2B0C}\RP93\A0051297.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{43618517-4DE3-4B08-B021-3EF239CA2B0C}\RP93\A0051298.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{43618517-4DE3-4B08-B021-3EF239CA2B0C}\RP93\A0051299.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{43618517-4DE3-4B08-B021-3EF239CA2B0C}\RP93\A0051301.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{43618517-4DE3-4B08-B021-3EF239CA2B0C}\RP93\A0051302.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{43618517-4DE3-4B08-B021-3EF239CA2B0C}\RP93\A0051303.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{43618517-4DE3-4B08-B021-3EF239CA2B0C}\RP93\A0051305.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\urqRLfDt.VIR (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\comp two long internet\Mode hold.exe (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\antiwpa.dll (Trojan.I.Stole.Windows) -> Delete on reboot.
Avatar billede f-arn Guru
10. december 2008 - 14:34 #3
Genstart i fejlsikker tilstand. Start hijackthis, klik 'do a system scan only' og marker disse linier:
O4 - HKCU\..\Run: [SOAP JOY] C:\DOCUME~1\Ejer\APPLIC~1\TICKUP~1\Bore Dumb.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{3B504F77-35DA-4F5E-9130-F68E4624C43A}: NameServer = 80.251.201.177 80.251.201.178
O17 - HKLM\System\CS1\Services\Tcpip\..\{3B504F77-35DA-4F5E-9130-F68E4624C43A}: NameServer = 80.251.201.177 80.251.201.178
O20 - AppInit_DLLs: fbbspk.dll
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
Luk alle andre vinduer og klik 'fix checked'
Genstart normalt og send en ny hjt log
Avatar billede mivroth Nybegynder
15. februar 2009 - 19:55 #4
s
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester