Avatar billede karstenjunior Nybegynder
29. januar 2009 - 18:19 Der er 9 kommentarer og
1 løsning

er min pc inficeret

jeg synes min pc ter sig besynderligt. Er der nogen, der gider se påminlog ffra hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:17:13, on 29-01-2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Programmer\Canon\Easy-PrintToolBox\BJPSMAIN.EXE
C:\Programmer\Support.com\bin\tgcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\keyhook.exe
C:\Programmer\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programmer\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\sistray.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\PC Connectivity Solution\ServiceLayer.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\BitTorrent\bittorrent.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Karsten Garfield\Lokale indstillinger\Temporary Internet Files\Content.IE5\JF75I28A\HiJackThis[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmer\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programmer\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Programmer\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [hcenter] "C:\Programmer\Support.com\bin\tgcmd.exe" /server /startmonitor
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Registry Helper] "C:\Programmer\Registry Helper\RegistryHelper.Exe" /boot
O4 - HKCU\..\Run: [Disk Cleaner] "C:\Programmer\Disk Cleaner\DiskCleaner.exe" /cosell
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Programmer\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Programmer\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Programmer\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Programmer\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1213051351125
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://danid.dk/csp/authenticode/digitalsignatur-csp.exe
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmer\Java\jre6\bin\jqs.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmer\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 6713 bytes
Avatar billede f-arn Guru
29. januar 2009 - 18:48 #1
Hent "Malwarebytes' Anti-Malware" her: http://www.besttechie.net/tools/mbam-setup.exe
Installer og start programmet, opdater, lav "fuld systemskanning" under fanebladet "skanner".
Bagefter klik på "vis resultater", tryk på "Fjern det valgte" og send loggen herind sammen med en log fra DDS som du finder her: http://www.techsupportforum.com/sectools/sUBs/dds
Den laver to logs, gem dds.txt et sted hvor du kan finde den og kopier teksten herind.
29. januar 2009 - 19:09 #2
C:\Programmer\BitTorrent\bittorrent.exe -> *SUK*
Avatar billede karstenjunior Nybegynder
29. januar 2009 - 20:08 #3
her er så de ønkede logs
Malwarebytes' Anti-Malware 1.33
Database version: 1705
Windows 5.1.2600 Service Pack 3

29-01-2009 20:02:15
mbam-log-2009-01-29 (20-02-15).txt

Skan type: Fuldstændig skanning (C:\|)
Objekter skannet: 84899
Tid tilbagelagt: 25 minute(s), 7 second(s)

Inficerede Hukommelses Processer: 0
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 1
Inficerede Registeringsdatabase Værdier: 1
Inficerede Registeringsdatabase Filer: 0
Inficerede Mapper: 0
Inficerede Filer: 0

Inficerede Hukommelses Processer:
(Ingen mistænkelige filer fundet)

Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Nøgler:
HKEY_LOCAL_MACHINE\SOFTWARE\Registry Helper (Rogue.RegistryHelper) -> Quarantined and deleted successfully.

Inficerede Registeringsdatabase Værdier:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Registry Helper (Rogue.RegistryHelper) -> Quarantined and deleted successfully.

Inficerede Registeringsdatabase Filer:
(Ingen mistænkelige filer fundet)

Inficerede Mapper:
(Ingen mistænkelige filer fundet)

Inficerede Filer:
(Ingen mistænkelige filer fundet)

DDS (Ver_09-01-19.01) - NTFSx86 
Run by Karsten Garfield at 20:03:24,56 on 29-01-2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition  5.1.2600.3.1252.45.1030.18.1503.995 [GMT 1:00]

AV: avast! antivirus 4.8.1296 [VPS 090129-0] *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Programmer\Canon\Easy-PrintToolBox\BJPSMAIN.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\keyhook.exe
C:\Programmer\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programmer\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\sistray.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Programmer\PC Connectivity Solution\ServiceLayer.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\BitTorrent\bittorrent.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\spider.exe
C:\Programmer\Microsoft Office\Office\WINWORD.EXE
C:\Documents and Settings\Karsten Garfield\Lokale indstillinger\Temporary Internet Files\Content.IE5\SB5QMNV5\dds[1].com

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.dk/
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\programmer\adobe\acrobat 5.0\reader\activex\AcroIEHelper.ocx
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\programmer\java\jre6\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\programmer\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\programmer\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\programmer\canon\easy-webprint\Toolband.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [MSMSGS] "c:\programmer\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Disk Cleaner] "c:\programmer\disk cleaner\DiskCleaner.exe" /cosell
mRun: [PCSuiteTrayApplication] c:\programmer\nokia\nokia pc suite 6\LaunchApplication.exe -startup
mRun: [Easy-PrintToolBox] c:\programmer\canon\easy-printtoolbox\BJPSMAIN.EXE /logon
mRun: [hcenter] "c:\programmer\support.com\bin\tgcmd.exe" /server /startmonitor
mRun: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
mRun: [SiSUSBRG] c:\windows\SiSUSBrg.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [SiS Windows KeyHook] c:\windows\system32\keyhook.exe
mRun: [SunJavaUpdateSched] "c:\programmer\java\jre6\bin\jusched.exe"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRunOnce: [Malwarebytes' Anti-Malware] c:\programmer\malwarebytes' anti-malware\mbamgui.exe /install /silent
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [Nokia.PCSync] c:\programmer\nokia\nokia pc suite 6\PcSync2.exe /NoDialog
StartupFolder: c:\docume~1\alluse~1\menuen~1\progra~1\start\micros~1.lnk - c:\programmer\microsoft office\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\menuen~1\progra~1\start\utilit~1.lnk - c:\windows\system32\sistray.exe
IE: Easy-WebPrint Add To Print List - c:\programmer\canon\easy-webprint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\programmer\canon\easy-webprint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\programmer\canon\easy-webprint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\programmer\canon\easy-webprint\Resource.dll/RC_Print.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\programmer\messenger\msmsgs.exe
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1213051351125
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} - hxxps://danid.dk/csp/authenticode/digitalsignatur-csp.exe
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} - hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-1-29 111184]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\programmer\alwil software\avast4\ashMaiSv.exe [2009-1-29 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\programmer\alwil software\avast4\ashWebSv.exe [2009-1-29 352920]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-1-29 20560]
R4 avast! Antivirus;avast! Antivirus;c:\programmer\alwil software\avast4\ashServ.exe [2009-1-29 155160]

=============== Created Last 30 ================

2009-01-29 19:27    15,504    a-------    c:\windows\system32\drivers\mbam.sys
2009-01-29 19:27    38,496    a-------    c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-29 19:27    <DIR>    --d-----    c:\programmer\Malwarebytes' Anti-Malware
2009-01-29 09:49    26,944    a-------    c:\windows\system32\drivers\aavmker4.sys
2009-01-29 09:47    <DIR>    --d-----    c:\docume~1\alluse~1\applic~1\Avg8
2009-01-28 09:18    1,374    a-------    c:\windows\imsins.BAK
2009-01-28 09:18    <DIR>    --d-----    c:\windows\SxsCaPendDel
2009-01-20 09:08    <DIR>    --d-----    c:\docume~1\alluse~1\applic~1\Disk Cleaner
2009-01-20 09:08    <DIR>    --d-----    c:\programmer\Disk Cleaner
2009-01-16 11:08    176,128    --------    c:\windows\system32\SiSApCom.dll
2009-01-16 11:08    106,496    --------    c:\windows\system32\TVMode.dll
2009-01-16 11:07    <DIR>    --d-----    c:\programmer\SiS VGA Utilities V3.59
2009-01-16 11:06    <DIR>    --d-----    c:\windows\system32\trayres
2009-01-16 11:06    102,551    a-------    c:\windows\system32\VGAunistlog.ini
2009-01-16 06:48    <DIR>    --d-----    c:\documents and settings\karsten garfield\eee
2009-01-16 06:46    45,984    a-------    c:\windows\system32\ins2.exe
2009-01-15 21:19    <DIR>    --d-----    c:\docume~1\karste~1\applic~1\Thinstall
2009-01-14 15:37    <DIR>    --d-----    c:\docume~1\karste~1\applic~1\RegTool
2009-01-14 15:37    <DIR>    --d-----    c:\programmer\RegTool
2009-01-14 09:57    626,688    a-------    c:\windows\system32\vp7vfw.dll
2009-01-14 09:57    102,439    a-------    c:\windows\system32\sipr3260.dll
2009-01-14 09:57    65,602    a-------    c:\windows\system32\cook3260.dll
2009-01-14 09:57    1,184,984    a-------    c:\windows\system32\wvc1dmod.dll
2009-01-14 09:57    <DIR>    --d-----    c:\programmer\VSO
2009-01-11 17:11    164    --------    c:\windows\avrack.ini
2009-01-08 15:42    <DIR>    --d-----    c:\docume~1\karste~1\applic~1\Cryptomathic
2009-01-08 15:41    <DIR>    --d-----    c:\programmer\TDC
2009-01-06 21:06    13,030    a-------    C:\PDOXUSRS.NET
2009-01-06 21:06    37    a-------    c:\windows\iltwain.ini
2009-01-06 16:00    <DIR>    --d-----    C:\VideoOutput
2009-01-02 09:58    <DIR>    --d-----    c:\docume~1\karste~1\applic~1\Malwarebytes
2009-01-02 09:58    <DIR>    --d-----    c:\docume~1\alluse~1\applic~1\Malwarebytes

==================== Find3M  ====================

2009-01-28 09:17    356,398    a-------    c:\windows\system32\perfh006.dat
2009-01-28 09:17    62,280    a-------    c:\windows\system32\perfc006.dat
2009-01-16 11:44    410,984    a-------    c:\windows\system32\deploytk.dll
2009-01-11 17:02    0    a-------    c:\documents and settings\karsten garfield\temp.dat
2008-12-11 11:57    333,952    a-------    c:\windows\system32\drivers\srv.sys
2008-10-09 08:49    66    a-------    c:\programmer\subc.ini
2008-06-24 09:27    87,608    a-------    c:\docume~1\karste~1\applic~1\inst.exe
2008-06-24 09:27    47,360    a-------    c:\docume~1\karste~1\applic~1\pcouffin.sys
2008-06-11 05:25    18,046,088    a-------    c:\programmer\tdcnetsupport.exe
2008-02-15 12:36    12,069,528    a-------    c:\programmer\designpro_danish.exe
2003-11-24 19:31    911,360    a-------    c:\programmer\subc.exe

============= FINISH: 20:03:39,10 ===============
Avatar billede f-arn Guru
30. januar 2009 - 13:19 #4
Der er ikke noget der helt sikkert et malware. Hvad mener du med "jeg synes min pc ter sig besynderligt"?

Hent og gem: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Kør så combofix.exe og følg anvisningerne.
Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når combofix er færdig, og efter det har genstartet, skulle der gerne åbnes en logfil: combofix.txt
Indholdet af denne fil må du gerne lægge herind.
Avatar billede karstenjunior Nybegynder
30. januar 2009 - 22:06 #5
her er så resultatet med combofix:
ComboFix 09-01-21.04 - Karsten Garfield 2009-01-30 21:53:42.2 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1030.18.1503.1050 [GMT 1:00]
Kører fra: c:\documents and settings\Karsten Garfield\Dokumenter\Downloads\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 090130-0] *On-access scanning disabled* (Updated)
.
- REDUCED FUNCTIONALITY MODE -
.

(((((((((((((((((((((((((((((  Filer skabt fra 2008-12-28 til 2009-01-30  )))))))))))))))))))))))))))))))))))
.

2009-01-30 09:26 . 2009-01-30 09:26    <DIR>    d--------    c:\windows\RegCure
2009-01-30 09:26 . 2009-01-30 09:28    <DIR>    d--------    c:\programmer\RegCure
2009-01-29 23:22 . 2009-01-29 23:22    23,600    --a------    c:\windows\system32\drivers\TVICHW32.SYS
2009-01-29 22:25 . 2009-01-30 11:39    <DIR>    d--------    c:\programmer\SpeedFan
2009-01-29 22:25 . 2009-01-29 22:25    45    --a------    c:\windows\system32\initdebug.nfo
2009-01-29 22:03 . 2009-01-29 22:03    <DIR>    d--------    c:\programmer\Lavalys
2009-01-29 19:27 . 2009-01-29 19:27    <DIR>    d--------    c:\programmer\Malwarebytes' Anti-Malware
2009-01-29 19:27 . 2009-01-14 16:11    38,496    --a------    c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-29 19:27 . 2009-01-14 16:11    15,504    --a------    c:\windows\system32\drivers\mbam.sys
2009-01-29 16:35 . 2009-01-29 16:35    <DIR>    d--------    c:\windows\LastGood
2009-01-29 09:48 . 2009-01-29 09:48    <DIR>    d--------    c:\programmer\Alwil Software
2009-01-29 09:47 . 2009-01-29 09:47    <DIR>    d--------    c:\documents and settings\All Users\Application Data\Avg8
2009-01-28 09:18 . 2009-01-29 09:32    <DIR>    d--------    c:\windows\SxsCaPendDel
2009-01-28 09:18 . 2009-01-28 09:18    1,374    --a------    c:\windows\imsins.BAK
2009-01-20 09:08 . 2009-01-20 09:36    <DIR>    d--------    c:\programmer\Disk Cleaner
2009-01-20 09:08 . 2009-01-20 09:08    <DIR>    d--------    c:\documents and settings\All Users\Application Data\Disk Cleaner
2009-01-16 11:08 . 2004-07-09 04:10    176,128    ---------    c:\windows\system32\SiSApCom.dll
2009-01-16 11:08 . 2004-07-09 04:10    106,496    ---------    c:\windows\system32\TVMode.dll
2009-01-16 11:07 . 2009-01-16 11:08    <DIR>    d--------    c:\programmer\SiS VGA Utilities V3.59
2009-01-16 11:06 . 2009-01-16 11:07    <DIR>    d--------    c:\windows\system32\trayres
2009-01-16 11:06 . 2009-01-16 11:08    102,551    --a------    c:\windows\system32\VGAunistlog.ini
2009-01-16 06:48 . 2009-01-16 06:50    <DIR>    d--------    c:\documents and settings\Karsten Garfield\eee
2009-01-16 06:46 . 2009-01-16 06:46    45,984    --a------    c:\windows\system32\ins2.exe
2009-01-15 21:28 . 2009-01-16 12:20    <DIR>    d-a------    c:\documents and settings\All Users\Application Data\TEMP
2009-01-15 21:19 . 2009-01-15 21:19    <DIR>    d--------    c:\documents and settings\Karsten Garfield\Application Data\Thinstall
2009-01-14 15:37 . 2009-01-14 15:40    <DIR>    d--------    c:\documents and settings\Karsten Garfield\Application Data\RegTool
2009-01-14 09:57 . 2009-01-14 09:57    <DIR>    d--------    c:\programmer\VSO
2009-01-14 09:57 . 2006-05-20 16:16    1,184,984    --a------    c:\windows\system32\wvc1dmod.dll
2009-01-14 09:57 . 2006-05-11 19:21    626,688    --a------    c:\windows\system32\vp7vfw.dll
2009-01-14 09:57 . 2002-12-10 02:20    102,439    --a------    c:\windows\system32\sipr3260.dll
2009-01-14 09:57 . 2007-03-18 20:37    65,602    --a------    c:\windows\system32\cook3260.dll
2009-01-11 17:11 . 2001-07-06 08:19    164    ---------    c:\windows\avrack.ini
2009-01-08 15:42 . 2009-01-08 15:42    <DIR>    d--------    c:\documents and settings\Karsten Garfield\Application Data\Cryptomathic
2009-01-08 15:41 . 2009-01-08 15:41    <DIR>    d--------    c:\programmer\TDC
2009-01-06 21:06 . 2009-01-06 21:08    13,030    --a------    C:\PDOXUSRS.NET
2009-01-06 21:06 . 2009-01-06 21:08    37    --a------    c:\windows\iltwain.ini
2009-01-06 21:05 . 2009-01-06 21:05    <DIR>    d--------    c:\programmer\Borland
2009-01-06 16:00 . 2009-01-06 16:06    <DIR>    d--------    C:\VideoOutput
2009-01-02 09:58 . 2009-01-02 09:58    <DIR>    d--------    c:\documents and settings\Karsten Garfield\Application Data\Malwarebytes
2009-01-02 09:58 . 2009-01-02 09:58    <DIR>    d--------    c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-24 14:17 . 2008-12-24 14:17    <DIR>    d--------    c:\programmer\Fælles filer\Ahead
2008-12-24 14:17 . 2001-07-06 14:41    569,344    --a------    c:\windows\system32\imagr5.dll
2008-12-24 14:17 . 2001-07-06 12:44    544,768    --a------    c:\windows\system32\imagx5.dll
2008-12-24 14:17 . 2001-07-06 18:24    283,920    --a------    c:\windows\system32\ImagXpr5.dll
2008-12-24 14:17 . 2001-07-09 11:50    155,648    --a------    c:\windows\system32\NeroCheck.exe
2008-12-24 14:17 . 2004-03-03 21:30    125,184    --a------    c:\windows\system32\drivers\imagesrv.sys
2008-12-24 14:17 . 2000-06-26 11:45    106,496    --a------    c:\windows\system32\TwnLib20.dll
2008-12-24 14:17 . 2001-06-26 08:15    38,912    --a------    c:\windows\system32\picn20.dll
2008-12-24 14:17 . 2004-03-03 21:30    5,504    --a------    c:\windows\system32\drivers\imagedrv.sys
2008-12-16 11:35 . 2009-01-16 11:44    410,984    --a------    c:\windows\system32\deploytk.dll
2008-12-16 10:29 . 2008-12-16 10:29    <DIR>    d--------    c:\documents and settings\Karsten Garfield\.oces
2008-12-16 10:29 . 2009-01-11 17:02    0    --a------    c:\documents and settings\Karsten Garfield\temp.dat

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-30 20:53    ---------    d-----w    c:\documents and settings\Karsten Garfield\Application Data\BitTorrent
2009-01-30 10:40    ---------    d-----w    c:\documents and settings\Karsten Garfield\Application Data\Vso
2009-01-16 11:16    ---------    d--h--w    c:\programmer\InstallShield Installation Information
2009-01-14 07:57    ---------    d-----w    c:\programmer\Fælles filer\HP
2009-01-13 14:42    ---------    d-----w    c:\programmer\Java
2009-01-13 07:15    ---------    d-----w    c:\programmer\NCH Software
2009-01-11 16:11    ---------    d-----w    c:\programmer\AvRack
2009-01-08 14:41    ---------    d-----w    c:\programmer\Fælles filer\Wise Installation Wizard
2008-12-24 13:17    ---------    d-----w    c:\programmer\Ahead
2008-12-11 10:57    333,952    ----a-w    c:\windows\system32\drivers\srv.sys
2008-10-23 12:41    286,720    ----a-w    c:\windows\system32\gdi32.dll
2008-10-16 20:18    826,368    ----a-w    c:\windows\system32\wininet.dll
2008-10-16 13:13    202,776    ----a-w    c:\windows\system32\wuweb.dll
2008-10-16 13:13    1,809,944    ----a-w    c:\windows\system32\wuaueng.dll
2008-10-16 13:12    561,688    ----a-w    c:\windows\system32\wuapi.dll
2008-10-16 13:12    323,608    ----a-w    c:\windows\system32\wucltui.dll
2008-10-16 13:09    92,696    ----a-w    c:\windows\system32\cdm.dll
2008-10-16 13:09    51,224    ----a-w    c:\windows\system32\wuauclt.exe
2008-10-16 13:09    43,544    ----a-w    c:\windows\system32\wups2.dll
2008-10-16 13:08    34,328    ----a-w    c:\windows\system32\wups.dll
2008-10-15 16:37    337,408    ----a-w    c:\windows\system32\netapi32(2)(2).dll
2008-10-03 10:03    247,326    ------w    c:\windows\system32\strmdll.dll
2008-06-24 08:27    87,608    ----a-w    c:\documents and settings\Karsten Garfield\Application Data\inst.exe
2008-06-24 08:27    47,360    ----a-w    c:\documents and settings\Karsten Garfield\Application Data\pcouffin.sys
2008-06-11 04:25    18,046,088    ----a-w    c:\programmer\tdcnetsupport.exe
2008-02-15 11:36    12,069,528    ----a-w    c:\programmer\designpro_danish.exe
.

(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\programmer\Messenger\msmsgs.exe" [2008-04-14 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCSuiteTrayApplication"="c:\programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
"Easy-PrintToolBox"="c:\programmer\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
"hcenter"="c:\programmer\Support.com\bin\tgcmd.exe" [2005-04-08 1757184]
"SiSUSBRG"="c:\windows\SiSUSBrg.exe" [2004-07-09 106496]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SiS Windows KeyHook"="c:\windows\system32\keyhook.exe" [2004-05-12 249856]
"SunJavaUpdateSched"="c:\programmer\Java\jre6\bin\jusched.exe" [2009-01-16 136600]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"Cmaudio"="cmicnfg.cpl" [BU]
"SoundMan"="SOUNDMAN.EXE" [2004-05-14 c:\windows\soundman.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\programmer\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]

c:\documents and settings\All Users\Menuen Start\Programmer\Start\
Microsoft Office.lnk - c:\programmer\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
Utility Tray.lnk - c:\windows\system32\sistray.exe [2009-01-16 335872]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\BitTorrent\\bittorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\Support.com\\bin\\tgcmd.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-01-29 111184]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-01-29 20560]

--- Andre Services/Drivers i Hukommelsen ---

*NewlyCreated* - AAVMKER4
*NewlyCreated* - ASWFSBLK
*NewlyCreated* - ASWMON2
*NewlyCreated* - ASWRDR
*NewlyCreated* - ASWSP
*NewlyCreated* - ASWTDI
*NewlyCreated* - ASWUPDSV
*NewlyCreated* - AVAST!_ANTIVIRUS
*NewlyCreated* - AVAST!_MAIL_SCANNER
*NewlyCreated* - AVAST!_WEB_SCANNER
*NewlyCreated* - GIVEIO
*NewlyCreated* - SPEEDFAN
*NewlyCreated* - TVICHW32

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{621FCD24-4498-4324-A81E-07D331376EDF}]
c:\programmer\PixiePack Codec Pack\InstallerHelper.exe
.
Indhold af mappen 'Planlagte Opgaver'

2009-01-30 c:\windows\Tasks\RegCure Program Check.job
- c:\programmer\RegCure\RegCure.exe [2007-08-02 10:20]

2009-01-30 c:\windows\Tasks\RegCure.job
- c:\programmer\RegCure\RegCure.exe [2007-08-02 10:20]

2009-01-30 c:\windows\Tasks\RegTool Scan.job
- c:\programmer\RegTool\RegTool.exe []

2009-01-30 c:\windows\Tasks\RegTool Scan.job
- c:\programmer\RegTool []

2009-01-29 c:\windows\Tasks\Schedule Task Weekly.job
- c:\programmer\Registry Easy\RE.exe []
.
.
------- Yderligere scanning -------
.
uStart Page = hxxp://www.google.dk/
IE: Easy-WebPrint Add To Print List - c:\programmer\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\programmer\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\programmer\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\programmer\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} - hxxps://danid.dk/csp/authenticode/digitalsignatur-csp.exe
DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} - hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-30 21:53:52
Windows 5.1.2600 Service Pack 3 NTFS

scanner skjulte processer ... 

scanner skjulte autostarter ...

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer: 0

**************************************************************************
.
Gennemført tid: 2009-01-30 21:55:17
ComboFix-quarantined-files.txt  2009-01-30 20:54:58
ComboFix2.txt  2009-01-30 20:48:31

Pre-Kørsel: 160,696,127,488 byte ledig
Post-Kørsel: 160,687,206,400 byte ledig

179    --- E O F ---    2009-01-14 07:50:00

problem: Pc'en hakker og jeg kan heller ikke opdatere windows framework
Avatar billede f-arn Guru
31. januar 2009 - 19:25 #6
Jeg vil gerne ha' dig til at hente en ny udgave af combofix, deaktivere Avast, starte notesblok og kopiere det der står mellem -------- linierne ind.

----------------------------

Killall::

Snapshot::

Filelook::
c:\programmer\Registry Easy\RE.exe

-------------------- 

Gem det som CFScript.txt samme sted som du har combofix.
Vær opmmærksom på at den ikke kommer til at hedde CFScript.txt.txt

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen.
Se her hvordan -> http://img.photobucket.com/albums/v666/sUBs/CFScript.gif


Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.

Når combofix er færdig, og efter det har genstartet, skulle der gerne åbnes en logfil: combofix.txt

Indholdet af denne fil må du gerne lægge herind til gennemsyn.
01. februar 2009 - 00:29 #7
(( Sku' vi lige få denne C:\Programmer\BitTorrent\bittorrent.exe af vejen ? Eller går det let galt igen !!! ?))
16. februar 2010 - 11:12 #8
(Hvad endte denne tråd med ?)

Samt de andre 'glemte' -> http://www.eksperten.dk/list/spoergsmaal/karstenjunior (Dem der ikke er grønne)
Avatar billede karstenjunior Nybegynder
12. september 2011 - 22:22 #9
så blev det løst
Avatar billede karstenjunior Nybegynder
12. september 2011 - 22:26 #10
så blev det løst
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester