Avatar billede elpede Nybegynder
08. juni 2009 - 13:06 Der er 35 kommentarer og
1 løsning

ieframe dnserror

Hej eksperter

Efter at have klikket på noget link jeg fik via facebook, har jeg fået en eller anden orm...koobface..noget. Den er jeg blevet af med tror jeg, men min ie er helt syg.
Jeg oplever det samme som staklen i dette indlæg: http://www.eksperten.dk/spm/877416

Hvad gør jeg da jeg ikke kan få adgang til nettet. Har dog en anden maskine jeg kan hente filer på.

Ser frem til Jeres hjælp!

mvh,

Per
Avatar billede elpede Nybegynder
08. juni 2009 - 14:01 #1
her er windows diagnosticerings loggen:

Seneste tidspunkt for kørsel af diagnosticering: 06/08/09 13:59:55 Diagnosticering af netværkskort
Registrering af netværksplacering

info Bruger privat internetforbindelse
Identifikation af netværkskort

info Netværksforbindelse: Navn=LAN-forbindelse, Enhed=Broadcom NetLink (TM) Gigabit Ethernet, Medietype=LAN, Undermedietype=LAN
info Netværksforbindelse: Navn=Trådløs netværksforbindelse, Enhed=Intel(R) PRO/Wireless 3945ABG Network Connection, Medietype=LAN, Undermedietype=TRÅDLØS
info Netværksforbindelse: Navn=LAN-forbindelse 2, Enhed=NCP Secure Client Adapter, Medietype=LAN, Undermedietype=LAN
info Netværksforbindelse: Navn=LAN-forbindelse 3, Enhed=ZyWALL SecuExtender Virtual NIC, Medietype=LAN, Undermedietype=LAN
info Netværksforbindelse: Navn=DrayTek Virtual Interface, Enhed=TAP-Win32 Adapter V8, Medietype=LAN, Undermedietype=LAN
info Netværksforbindelse: Navn=VMware Network Adapter VMnet1, Enhed=VMware Virtual Ethernet Adapter for VMnet1, Medietype=LAN, Undermedietype=LAN
info Netværksforbindelse: Navn=VMware Network Adapter VMnet8, Enhed=VMware Virtual Ethernet Adapter for VMnet8, Medietype=LAN, Undermedietype=LAN
info Netværksforbindelse: Navn=1394-forbindelse, Enhed=1394-netværkskort, Medietype=LAN, Undermedietype=1394
info Netværksforbindelse: Navn=GPRS-forbindelse, Enhed=Agere Systems HDA Modem, Medietype=TELEFON, Undermedietype=INGEN
info Netværksforbindelse: Navn=JM-Media, Enhed=AVM NDIS WAN CAPI Driver, Medietype=ISDN, Undermedietype=INGEN
info Netværksforbindelse: Navn=Mobilt Bredbånd, Enhed=Agere Systems HDA Modem, Medietype=TELEFON, Undermedietype=INGEN
info Netværksforbindelse: Navn=TDC, Enhed=Agere Systems HDA Modem, Medietype=TELEFON, Undermedietype=INGEN
warn Computeren har mere end ét Ethernet eller mere end ét trådløst netværkskort
info Omdirigerer bruger til supportopkald



Diagnosticering af HTTP, HTTPS, FTP
HTTP-, HTTPS-, FTP-forbindelser

warn HTTP: Fejl 12029 under oprettelse af forbindelse til www.microsoft.com: A connection with the server could not be established 
info FTP (Passiv): Der blev oprettet forbindelse til ftp.microsoft.com.
info HTTPS: Der blev oprettet forbindelse til www.microsoft.com.
warn HTTP: Fejl 12029 under oprettelse af forbindelse til www.hotmail.com: A connection with the server could not be established 
error En HTTP-forbindelse blev ikke oprettet.
Avatar billede f-arn Guru
08. juni 2009 - 14:51 #2
Hent "Malwarebytes' Anti-Malware" her: http://www.besttechie.net/tools/mbam-setup.exe
Installer og start programmet, opdater, lav "fuld systemskanning" under fanebladet "skanner".
Bagefter klik på "vis resultater", tryk på "Fjern det valgte" og send loggen herind sammen med en log fra DDS som du finder her: http://download.bleepingcomputer.com/sUBs/dds.scr

eller her: http://www.forospyware.com/sUBs/dds
08. juni 2009 - 14:53 #3
Win98, ME, W2000, XP, Vista, Win7, ... ?
08. juni 2009 - 14:53 #4
Hent og instalér CCleaner http://www.ccleaner.com/ + http://www.spywarefri.dk/manualer/ccleaner-manual.htm
Under installationen får du tilbudt [Yahoo Toolbar]. Du kan sige ja eller *NEJ* til den.
Lad programmet foretage en oprydning...

--------

Hent Malwarebytes Anti-Malware herfra:
http://www.besttechie.net/tools/mbam-setup.exe
Eller herfra ->
http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html

Installer programmet - når det er gjort skal du lade programmet opdatere sig. Herefter åbner et vindue, hvor du skal flytte prikken til "Kør et fuldstændigt systemscan" - klik på Skan Knappen - lad programmet arbejde. Når det er færdig (det tager lidt tid afhængig af hvor meget du har på computeren).
Derefter - Tryk på "Vis resultater" knappen efter scanningen - og herefter tryk på "Fjern det valgte" - nu åbnes log'en og du skal gemme den et sted, hvor du kan finde den igen.
Kopier indholdet herind sammen med en frisk log fra HiJackThis...

...og her er omtalte HiJackThis ->
http://www.spywareinfo.dk/index.htm#/manualer/hijackthis.htm

Bemærk at HiJackThis.exe programmet skal gemmes i en dertil oprettet mappe og IKKE køres direkte fra nettet...

PS: Brug denne version af HJT -> http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe

(Jooo - jeg har 'virus' på hjernen...)

Mht.: Vista - HøjreMusseTast på *.EXE filen - Kør som Administrator...

------------------
08. juni 2009 - 14:54 #5
<f-arn> kom 'først' *S*
Avatar billede elpede Nybegynder
08. juni 2009 - 14:56 #6
Win XP pro
Avatar billede johnstigers Seniormester
08. juni 2009 - 20:46 #7
Status?
Scanner den stadig?
Avatar billede elpede Nybegynder
08. juni 2009 - 21:46 #8
haha....nej nu er jeg klar.

Første log:

Malwarebytes' Anti-Malware 1.37
Database version: 2182
Windows 5.1.2600 Service Pack 3

08-06-2009 21:10:36
mbam-log-2009-06-08 (21-10-26).txt

Skan type: Fuldstændig skanning (C:\|E:\|)
Objekter skannet: 229735
Tid tilbagelagt: 1 hour(s), 49 minute(s), 40 second(s)

Inficerede Hukommelses Processer: 0
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 0
Inficerede Registeringsdatabase Værdier: 6
Inficerede Registeringsdatabase Filer: 0
Inficerede Mapper: 4
Inficerede Filer: 10

Inficerede Hukommelses Processer:
(Ingen mistænkelige filer fundet)

Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Nøgler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Værdier:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysmstray (Worm.KoobFace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysfbtray (Worm.KoobFace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pp (Backdoor.Bot) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysldtray (Backdoor.Bot) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysdll (Worm.Autorun) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SYS32DLL (Worm.KoobFace) -> No action taken.

Inficerede Registeringsdatabase Filer:
(Ingen mistænkelige filer fundet)

Inficerede Mapper:
C:\WINDOWS\system32\121973 (Trojan.BHO) -> No action taken.
C:\WINDOWS\system32\870159 (Trojan.FakeAlert) -> No action taken.
C:\Programmer\websrvx (Trojan.Downloader) -> No action taken.
C:\WINDOWS\system32\547372 (Trojan.BHO) -> No action taken.

Inficerede Filer:
c:\system volume information\_restore{451f1296-4812-4452-bc45-6051609c8820}\RP312\A0042154.exe (Worm.KoobFace) -> No action taken.
C:\WINDOWS\msmark2.dat (Worm.KoobFace) -> No action taken.
c:\WINDOWS\st_1242900204.exe (Backdoor.Bot) -> No action taken.
c:\WINDOWS\st_1242906502.exe (Backdoor.Bot) -> No action taken.
c:\WINDOWS\st_1242918634.exe (Backdoor.Bot) -> No action taken.
c:\WINDOWS\st_1242969141.exe (Backdoor.Bot) -> No action taken.
c:\WINDOWS\st_1242975438.exe (Backdoor.Bot) -> No action taken.
c:\WINDOWS\st_1242987570.exe (Backdoor.Bot) -> No action taken.
c:\WINDOWS\9g2234wesdf3dfgjf23 (Worm.KoobFace) -> No action taken.
C:\WINDOWS\f23567.dat (Worm.KoobFace) -> No action taken.
Avatar billede elpede Nybegynder
08. juni 2009 - 21:47 #9
Attach log fra dds.scr

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-05-14.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 30-10-2007 13:42:53
System Uptime: 06-08-2009 18:55:36 (-1413 hours ago)

Motherboard: Hewlett-Packard |  | 30AA
Processor: Intel(R) Core(TM)2 CPU        T5600  @ 1.83GHz | U10 | 1828/166mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 50 GiB total, 11,224 GiB free.
D: is CDROM (CDFS)
E: is FIXED (NTFS) - 6 GiB total, 5,876 GiB free.

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 1394-netværkskort
Device ID: V1394\NIC1394\291D320E23F99
Manufacturer: Microsoft
Name: 1394-netværkskort
PNP Device ID: V1394\NIC1394\291D320E23F99
Service: NIC1394

Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Description: Nokia Windows Portable Device Driver
Device ID: ROOT\WPD\0000
Manufacturer: Nokia
Name: Nokia E65
PNP Device ID: ROOT\WPD\0000
Service: WUDFRd

Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Description: Nokia Windows Portable Device Driver
Device ID: ROOT\WPD\0001
Manufacturer: Nokia
Name: Nokia E65dows Portable Device Driver
PNP Device ID: ROOT\WPD\0001
Service: WUDFRd

Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Description: Nokia 7610 Supernova
Device ID: ROOT\WPD\0002
Manufacturer: Nokia
Name: Nokia 7610 Supernova
PNP Device ID: ROOT\WPD\0002
Service: WUDFRd

==== System Restore Points ===================

RP295: 17-04-2009 07:08:52 - Software Distribution Service 3.0
RP296: 20-04-2009 08:06:35 - Systemkontrolpunkt
RP297: 21-04-2009 09:08:33 - Systemkontrolpunkt
RP298: 23-04-2009 08:44:42 - Systemkontrolpunkt
RP299: 24-04-2009 10:09:04 - Systemkontrolpunkt
RP300: 27-04-2009 10:25:38 - Systemkontrolpunkt
RP301: 28-04-2009 11:08:52 - Systemkontrolpunkt
RP302: 30-04-2009 08:02:29 - Software Distribution Service 3.0
RP303: 04-05-2009 10:37:09 - Systemkontrolpunkt
RP304: 06-05-2009 07:20:41 - Systemkontrolpunkt
RP305: 07-05-2009 08:12:07 - Systemkontrolpunkt
RP306: 11-05-2009 09:14:41 - Systemkontrolpunkt
RP307: 12-05-2009 12:06:16 - Systemkontrolpunkt
RP308: 13-05-2009 07:52:01 - Software Distribution Service 3.0
RP309: 14-05-2009 10:28:42 - Systemkontrolpunkt
RP310: 18-05-2009 07:42:14 - Systemkontrolpunkt
RP311: 19-05-2009 10:10:14 - Systemkontrolpunkt
RP312: 20-05-2009 10:59:15 - Systemkontrolpunkt
RP313: 21-05-2009 11:50:53 - Systemkontrolpunkt
RP314: 22-05-2009 12:05:50 - Systemkontrolpunkt
RP315: 25-05-2009 11:55:51 - Systemkontrolpunkt
RP316: 27-05-2009 07:20:05 - Systemkontrolpunkt
RP317: 28-05-2009 09:38:55 - Systemkontrolpunkt
RP318: 29-05-2009 09:39:51 - Gendan handling
RP319: 02-06-2009 11:58:39 - Systemkontrolpunkt
RP320: 03-06-2009 12:04:40 - Systemkontrolpunkt
RP321: 08-06-2009 12:39:30 - Systemkontrolpunkt
RP322: 08-06-2009 14:11:00 - Removed VMware Player.

==== Installed Programs ======================


32 Bit HP BiDi Channel Components Installer
Adobe Common File Installer
Adobe Flash Player 10 ActiveX
Adobe Flash Player Plugin
Adobe Illustrator 10
Adobe Photoshop Elements 6.0
Adobe Premiere Elements 4.0
Adobe Premiere Elements 4.0 Templates
Adobe Reader 8.1.5 - Dansk
Adobe Shockwave Player
Adobe SVG Viewer 3.0
Agere Systems HDA Modem
Application Installer 4.00.B5
Azureus Vuze
Belkin Range Extender
Blackjack Ballroom Casino
Casino Action
Casino Classic
Choice Guard
Classic Poker
Digia Client
ExtractNow
Fingerprint Sensor Minimum Install
FloorPlan 3D v9
GIMP 2.4.2
Google Chrome
Google Earth
Google Update Helper
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix til Windows Internet Explorer 7 (KB947864)
Hotfix til Windows Media Player 11 (KB939683)
Hotfix til Windows XP (KB952287)
HP Backup and Recovery Manager Installation
HP Billed-cd
HP Integrated Module with Bluetooth wireless technology
HP Photo and Imaging 2.0 - Scanners
HP Quick Launch Buttons 6.00 H1
HP Support Phone Numbers
HpSdpAppCoreApp
Intel(R) Graphics Media Accelerator Driver
InterActual Player
IP Office Admin Suite
IP Office Voicemail Pro
IPO500 Configurator Tool 4.2
J2SE Runtime Environment 5.0 Update 11
Java(TM) 6 Update 13
Java(TM) 6 Update 5
Java(TM) 6 Update 7
KB408682
KSU-Setup
KSULabel
Malwarebytes' Anti-Malware
Messenger Plus! 3
MetaFrame Presentation Server Web Client for Win32
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Danish Language Pack
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Application Error Reporting
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft National Language Support Downlevel APIs
Microsoft Office PowerPoint Viewer 2003
Microsoft User-Mode Driver Framework Feature Pack 1.5
Microsoft Visual C++ 2005 Redistributable
Mobile Partner
Mobilt Bredband
MSVCRT
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6.0 Parser (KB933579)
NCP Secure Entry Client
Nero Suite
Nokia Connectivity Cable Driver
Nokia Flashing Cable Driver
Nokia PC Suite
Nokia Software Updater
Norman Virus Control
Ontrack Data Recovery Verifile Data Reports
Opdatering til Windows XP (KB951072-v2)
Opdatering til Windows XP (KB951978)
Opdatering til Windows XP (KB955839)
Opdatering til Windows XP (KB961503)
Opdatering til Windows XP (KB967715)
Overførselsværktøj til Windows Live
PC Connectivity Solution
PhoneManager
QuickTime
RTC Client API v1.2
Segoe UI
SIEMENS USB Data Cable
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB938127)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB942615)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB944533)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB950759)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB953838)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB956390)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB958215)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB960714)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB961260)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB963027)
Sikkerhedsopdatering til Windows Media Player (KB911564)
Sikkerhedsopdatering til Windows Media Player (KB952069)
Sikkerhedsopdatering til Windows Media Player 10 (KB936782)
Sikkerhedsopdatering til Windows Media Player 11 (KB936782)
Sikkerhedsopdatering til Windows Media Player 11 (KB954154)
Sikkerhedsopdatering til Windows Media Player 6.4 (KB925398)
Sikkerhedsopdatering til Windows Media Player 9 (KB911565)
Sikkerhedsopdatering til Windows XP (KB923561)
Sikkerhedsopdatering til Windows XP (KB923689)
Sikkerhedsopdatering til Windows XP (KB923789)
Sikkerhedsopdatering til Windows XP (KB938464)
Sikkerhedsopdatering til Windows XP (KB941569)
Sikkerhedsopdatering til Windows XP (KB946648)
Sikkerhedsopdatering til Windows XP (KB950760)
Sikkerhedsopdatering til Windows XP (KB950762)
Sikkerhedsopdatering til Windows XP (KB950974)
Sikkerhedsopdatering til Windows XP (KB951066)
Sikkerhedsopdatering til Windows XP (KB951376-v2)
Sikkerhedsopdatering til Windows XP (KB951376)
Sikkerhedsopdatering til Windows XP (KB951698)
Sikkerhedsopdatering til Windows XP (KB951748)
Sikkerhedsopdatering til Windows XP (KB952004)
Sikkerhedsopdatering til Windows XP (KB952954)
Sikkerhedsopdatering til Windows XP (KB953839)
Sikkerhedsopdatering til Windows XP (KB954211)
Sikkerhedsopdatering til Windows XP (KB954459)
Sikkerhedsopdatering til Windows XP (KB954600)
Sikkerhedsopdatering til Windows XP (KB955069)
Sikkerhedsopdatering til Windows XP (KB956391)
Sikkerhedsopdatering til Windows XP (KB956572)
Sikkerhedsopdatering til Windows XP (KB956802)
Sikkerhedsopdatering til Windows XP (KB956803)
Sikkerhedsopdatering til Windows XP (KB956841)
Sikkerhedsopdatering til Windows XP (KB957095)
Sikkerhedsopdatering til Windows XP (KB957097)
Sikkerhedsopdatering til Windows XP (KB958644)
Sikkerhedsopdatering til Windows XP (KB958687)
Sikkerhedsopdatering til Windows XP (KB958690)
Sikkerhedsopdatering til Windows XP (KB959426)
Sikkerhedsopdatering til Windows XP (KB960225)
Sikkerhedsopdatering til Windows XP (KB960715)
Sikkerhedsopdatering til Windows XP (KB960803)
Sikkerhedsopdatering til Windows XP (KB961373)
SoftConsole
Sonic eDVD
Sony Ericsson PC Suite for Smartphones
Sony Ericsson Symbian 9 Drivers
SoundMAX
Spelling Dictionaries Support For Adobe Reader 8
Symantec Technical Support Web Controls
Synaptics Pointing Device Driver
TeamViewer 4
Techlogica HTTP Server 1.03
Texas Instruments PCIxx21/x515/xx12 drivers.
Tilmeldingsassistent til Windows Live
TIPCI
Update Service
USB Super Link
Vigtig opdatering til Windows Media Player 11 (KB959772)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VLC media player 0.9.8a
VNC Free Edition 4.1.3
WebFldrs XP
Windows Driver Package - Nokia (WUDFRd) WPD  (11/03/2006 6.82.26.2)
Windows Driver Package - Nokia Modem  (11/03/2006 6.82.0.1)
Windows Genuine Advantage Notifications (KB905474)
Windows Internet Explorer 7
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinPcap 4.0.2
Wireshark 1.0.8
ZyWALL SecuExtender

==== End Of File ===========================
Avatar billede elpede Nybegynder
08. juni 2009 - 21:48 #10
DDS log

DDS (Ver_09-05-14.01) - NTFSx86 
Run by Per Jensen at 21:10:53,79 on 08-06-2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional  5.1.2600.3.1252.45.1030.18.503.123 [GMT 2:00]

AV: Norman Security Suite *On-access scanning enabled* (Updated)  {EB9EFB40-AE72-4C43-B204-0FCD0E92D5F1}

============== Running Processes ===============

C:\Programmer\Norman\Npm\Bin\eLogsvc.exe
C:\Programmer\Norman\Ngs\Bin\Nprosec.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Programmer\Norman\Npm\Bin\Zanda.exe
C:\Programmer\Norman\npm\bin\nvoy.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\msdtc.exe
C:\Programmer\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Programmer\WIDCOMM\Bluetooth-software\bin\btwdins.exe
C:\Programmer\svpniptun\FtmSrv.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\Programmer\Google\Update\GoogleUpdate.exe
C:\Programmer\NCP\SecureClient\ncpclcfg.exe
C:\Programmer\NCP\SecureClient\ncprwsnt.exe
C:\Programmer\NCP\SecureClient\ncpsec.exe
C:\Programmer\NCP\SecureClient\rwsrsu.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\mqsvc.exe
C:\Programmer\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Programmer\Norman\Npm\Bin\scheduler.exe
C:\Programmer\Norman\Npm\Bin\Njeeves.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\Programmer\Norman\nse\bin\NSESVC.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Programmer\Analog Devices\Core\smax4pnp.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Programmer\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\SMINST\Scheduler.exe
C:\Programmer\Norman\Npm\Bin\ZLH.EXE
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Programmer\Adobe\Photoshop Elements 6.0\apdproxy.exe
C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Programmer\MessengerPlus! 3\MsgPlus.exe
c:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Programmer\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Programmer\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Per Jensen\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe
C:\Programmer\svpniptun\FtmTray.exe
C:\Programmer\Norman\Nvc\bin\nvcoas.exe
C:\Programmer\Norman\Nvc\Bin\Nip.exe
C:\Programmer\Norman\Nvc\Bin\cclaw.exe
C:\Programmer\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Per Jensen\Skrivebord\dds.scr
C:\WINDOWS\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.dk/
uInternet Connection Wizard,ShellNext = hxxp://www.hp.com/
uInternet Settings,ProxyOverride = *.local;<local>
uInternet Settings,ProxyServer = http=localhost:7171
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\programmer\fælles filer\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Hjælp til tilmelding til Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\programmer\fælles filer\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\programmer\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\programmer\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [MessengerPlus3] "c:\programmer\messengerplus! 3\MsgPlus.exe" /WinStart
uRun: [Google Update] "c:\documents and settings\per jensen\lokale indstillinger\application data\google\update\GoogleUpdate.exe" /c
uRun: [SYS32DLL] SYS32DLL
uRun: [SYSDLL] SYSDLL
uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockw~1\SWHELP~1.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)" -"http://www.gratisspil.dk/onlineGame/games/play.php?title=FFX%20Runner&enc=ZmZ4cnVubmVyXzEyMTIyNDM2MTIuZGly&width=600&height=500"
mRun: [MsmqIntCert] regsvr32 /s mqrt.dll
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [SoundMAXPnP] c:\programmer\analog devices\core\smax4pnp.exe
mRun: [SoundMAX] c:\programmer\analog devices\soundmax\Smax4.exe /tray
mRun: [SynTPEnh] c:\programmer\synaptics\syntp\SynTPEnh.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [Cpqset] c:\programmer\hpq\default settings\cpqset.exe
mRun: [Recguard] c:\windows\sminst\Recguard.exe
mRun: [Reminder] c:\windows\creator\Remind_XP.exe
mRun: [Scheduler] c:\windows\sminst\Scheduler.exe
mRun: [Norman ZANDA] "c:\programmer\norman\npm\bin\ZLH.EXE" /LOAD /SPLASH
mRun: [PC Suite for Smartphones] "c:\programmer\sony ericsson\mobile4\application launcher\Application Launcher.exe" /startoptions
mRun: [QuickTime Task] "c:\programmer\quicktime\qttask.exe" -atboottime
mRun: [PCSuiteTrayApplication] c:\programmer\nokia\nokia pc suite 6\LaunchApplication.exe -startup
mRun: [Adobe Photo Downloader] "c:\programmer\adobe\photoshop elements 6.0\apdproxy.exe"
mRun: [Share-to-Web Namespace Daemon] c:\programmer\hewlett-packard\hp share-to-web\hpgs2wnd.exe
mRun: [MessengerPlus3] "c:\programmer\messengerplus! 3\MsgPlus.exe"
mRun: [Adobe Reader Speed Launcher] "c:\programmer\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [SunJavaUpdateSched] "c:\programmer\java\jre6\bin\jusched.exe"
mRun: [sysldtray] c:\windows\ld08.exe
mRun: [sysfbtray] c:\windows\freddy43.exe
mRun: [sysmstray] c:\windows\mstre19.exe
mRun: [pp] c:\windows\pp10.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [PcSync] c:\programmer\nokia\nokia pc suite 6\PcSync2.exe /NoDialog
StartupFolder: c:\docume~1\alluse~1\menuen~1\progra~1\start\zywall~1.lnk - c:\programmer\svpniptun\FtmTray.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\programmer\messenger\msmsgs.exe
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {09987A35-84AC-4FB6-9144-4416BA5462BE} - hxxp://www.winner-team.dk/images/windemox/demox.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {19D6A3D5-EA50-4C3B-88F0-79627C325570} - hxxps://www.one.com/static/controls/IlosoftMultipleImageUpload.dll
DPF: {6D868B99-8B01-4B25-9BD1-ED37AFDF5E29} - hxxp://www.ontrackdatarecovery.com/verifile/npvfasp.cab
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} - hxxps://signin3.valueactive.com/Register/Branding/olr3313/OCX/v1018/flashax.cab
DPF: {DC6FEBC5-0A2D-458A-A01B-5DB15EEC4305} - hxxp://webc.pinsensvenner.dk/controls/IlosoftImageUpload.dll
DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

============= SERVICES / DRIVERS ===============

R1 NGS;Norman General Security Driver;c:\programmer\norman\ngs\bin\ngs.sys [2009-4-3 22712]
R1 NPROSEC;Norman Security driver;c:\programmer\norman\ngs\bin\nprosec.sys [2009-5-13 53816]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\programmer\adobe\photoshop elements 6.0\PhotoshopElementsFileAgent.exe [2007-9-11 124832]
R2 FullTunnel;Full Tunnel Mode Service;c:\programmer\svpniptun\FtmSrv.exe [2009-4-16 233472]
R2 ncpclcfg;ncpclcfg;c:\programmer\ncp\secureclient\ncpclcfg.exe [2007-10-31 77824]
R2 ncprwsnt;ncprwsnt;c:\programmer\ncp\secureclient\NCPRWSNT.EXE [2007-10-31 1019904]
R2 NcpSec;NcpSec;c:\programmer\ncp\secureclient\NCPSEC.EXE [2007-10-31 45056]
R2 Ndiskio;Ndiskio;c:\programmer\norman\nse\bin\Ndiskio.sys [2007-10-30 20448]
R2 Norman ZANDA;Norman ZANDA;c:\programmer\norman\npm\bin\Zanda.exe [2007-10-30 408696]
R2 NPROSECSVC;Norman Security service;c:\programmer\norman\ngs\bin\nprosec.exe [2009-5-13 121912]
R2 NVOY;Norman Resource Provider;c:\programmer\norman\npm\bin\nvoy.exe [2009-4-3 126008]
R2 rwsrsu;RwsRsu;c:\programmer\ncp\secureclient\RWSRSU.exe [2007-10-31 266240]
R3 AVMWAN;AVM NDIS WAN CAPI Driver;c:\windows\system32\drivers\avmwan.sys [2008-12-5 37568]
R3 FtmDrv;ZyWALL SecuExtender Virtual NIC;c:\windows\system32\drivers\FtmDrv.sys [2009-4-16 14848]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2006-2-28 87808]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2005-10-21 36352]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-6-8 40160]
R3 ncplentp;NCP Secure Client Adapter Driver;c:\windows\system32\drivers\ncplentp.sys [2007-10-31 73408]
R3 nsesvc;Norman Scanner Engine Service;c:\programmer\norman\nse\bin\Nsesvc.exe [2009-5-20 310328]
R3 NvcMFlt;NvcMFlt;c:\windows\system32\drivers\nvcw32mf.sys [2007-10-30 19512]
R3 nvcoas;Norman Virus Control on-access component;c:\programmer\norman\nvc\bin\Nvcoas.exe [2009-2-23 195640]
R3 Scheduler;Norman Scheduler Service;c:\programmer\norman\npm\bin\scheduler.exe [2009-5-13 130104]
R3 zebrceb;Sony Ericsson Cable Emulation Bus (WDM);c:\windows\system32\drivers\zebrceb.sys [2007-12-3 62984]
S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys --> c:\windows\system32\drivers\Lbd.sys [?]
S2 gupdate1c9959e955ef8e1;Google Update Service (gupdate1c9959e955ef8e1);c:\programmer\google\update\GoogleUpdate.exe [2009-2-23 133104]
S3 fxusbase;AVM ISDN-stik FRITZ!X USB;c:\windows\system32\drivers\fxusbase.sys [2008-12-5 454912]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2009-1-13 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2009-1-13 8320]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-6 34064]
S3 NVCScheduler;Norman Virus Control Scheduler;"c:\programmer\norman\npm\bin\nvcsched.exe" --> c:\programmer\norman\npm\bin\Nvcsched.exe [?]
S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [2005-10-8 22272]
S3 Usblink;Usblink Driver;c:\windows\system32\drivers\ulink.sys [2008-5-23 40788]
S3 VMProDBService;VMProDBService;c:\programmer\avaya\ip office\voicemail pro\vm\VMPDBSvc.exe [2007-11-21 102400]
S3 VoicemailProServer;VoicemailProServer;c:\programmer\avaya\ip office\voicemail pro\vm\VMProV5Svc.exe [2007-11-21 3641344]
S3 VPPP;DrayTek Virtual PPP Adapter;c:\windows\system32\drivers\VPPP.sys [2008-6-18 32784]
S3 zebrbus;Sony Ericsson Composite Device driver;c:\windows\system32\drivers\zebrbus.sys [2007-12-3 83080]
S3 zebrmdfl;Sony Ericsson Modem Filter;c:\windows\system32\drivers\zebrmdfl.sys [2007-12-3 15112]
S3 zebrmdm;Sony Ericsson Port (WDM);c:\windows\system32\drivers\zebrmdm.sys [2007-12-3 108296]
S3 zebrmdmc;Sony Ericsson mRouter Port (WDM);c:\windows\system32\drivers\zebrmdmc.sys [2007-12-3 108424]
S3 zebrsce;Sony Ericsson PC-Connect Port;c:\windows\system32\drivers\zebrsce.sys [2007-12-3 90888]

=============== Created Last 30 ================

2009-06-08 15:03    <DIR>    --d-----    c:\docume~1\perjen~1\applic~1\Malwarebytes
2009-06-08 15:03    40,160    a-------    c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-08 15:03    19,096    a-------    c:\windows\system32\drivers\mbam.sys
2009-06-08 15:03    <DIR>    --d-----    c:\programmer\Malwarebytes' Anti-Malware
2009-06-08 15:03    <DIR>    --d-----    c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-06-08 14:12    <DIR>    --d-----    c:\windows\system32\appmgmt
2009-06-02 14:50    <DIR>    --d-----    c:\docume~1\perjen~1\applic~1\Wireshark
2009-06-02 14:48    <DIR>    --d-----    c:\programmer\WinPcap
2009-06-02 14:37    <DIR>    --d-----    c:\programmer\Wireshark
2009-05-29 09:41    <DIR>    --d-----    c:\windows\system32\wbem\Repository
2009-05-25 07:41    <DIR>    --d-----    c:\programmer\Spyware Doctor
2009-05-25 07:03    <DIR>    --d-----    c:\windows\system32\121973
2009-05-22 07:11    0    a-------    c:\windows\st_1242975438.exe
2009-05-22 07:11    0    a-------    c:\windows\st_1242987570.exe
2009-05-22 07:11    0    a-------    c:\windows\st_1242969141.exe
2009-05-21 12:02    0    a-------    c:\windows\st_1242906502.exe
2009-05-21 12:02    0    a-------    c:\windows\st_1242918634.exe
2009-05-21 12:02    0    a-------    c:\windows\st_1242900204.exe
2009-05-21 09:57    <DIR>    --d-----    c:\programmer\Lavasoft
2009-05-21 09:55    <DIR>    --d-----    c:\programmer\Adaware
2009-05-21 08:11    <DIR>    --d-----    c:\windows\system32\870159
2009-05-20 21:26    <DIR>    --d-----    c:\windows\system32\547372
2009-05-20 21:26    2    ----h---    c:\windows\sto453148.dat
2009-05-20 21:26    2    ----h---    c:\windows\sto452739.dat
2009-05-20 21:26    2    ----h---    c:\windows\sto452712.dat
2009-05-20 07:12    2    ----h---    c:\windows\sto453266.dat
2009-05-20 07:12    2    ----h---    c:\windows\sto452857.dat
2009-05-20 07:12    2    ----h---    c:\windows\sto452830.dat
2009-05-19 13:33    1    a-------    c:\windows\9g2234wesdf3dfgjf23
2009-05-19 13:33    <DIR>    --d-----    c:\programmer\websrvx
2009-05-19 13:33    2    ----h---    c:\windows\sto453553.dat
2009-05-19 13:33    1    ----h---    c:\windows\msmark2.dat
2009-05-19 13:33    2    ----h---    c:\windows\sto453144.dat
2009-05-19 13:33    2    ----h---    c:\windows\sto453117.dat
2009-05-19 13:33    1    ----h---    c:\windows\f23567.dat
2009-05-11 08:10    54,156    a---h---    c:\windows\QTFont.qfn

==================== Find3M  ====================

2009-06-08 14:11    430,908    a-------    c:\windows\system32\perfh006.dat
2009-06-08 14:11    78,416    a-------    c:\windows\system32\perfc006.dat
2009-04-16 10:14    52,224    a-------    c:\documents and settings\per jensen\ftmepc.dll
2009-04-16 10:14    0    a-------    c:\documents and settings\per jensen\ssllnch.exe
2009-04-16 10:14    126,976    a-------    c:\documents and settings\per jensen\ssltun.dll
2009-04-16 10:14    9,216    a-------    c:\documents and settings\per jensen\sslsocks.dll
2009-03-21 16:08    1,006,080    --------    c:\windows\system32\dllcache\kernel32.dll
2009-03-10 22:18    968,584    --------    c:\windows\system32\dllcache\WgaTray.exe
2009-03-10 22:18    265,096    --------    c:\windows\system32\dllcache\wgaLogon.dll
2008-07-22 10:55    340    a---h---    c:\documents and settings\per jensen\hpothb07.dat
2008-02-27 15:53    1,306    a-------    c:\programmer\launch.ica
2008-09-02 08:09    32,768    a--sh---    c:\windows\system32\config\systemprofile\lokale indstillinger\oversigt\history.ie5\mshist012008090220080903\index.dat

============= FINISH: 21:11:38,59 ===============
08. juni 2009 - 21:59 #11
PS: Har du fornylig fået noget 'snavs' fra en Facebook besked/link ?

mRun: [sysldtray] c:\windows\ld08.exe
mRun: [sysfbtray] c:\windows\freddy43.exe
mRun: [sysmstray] c:\windows\mstre19.exe
mRun: [pp] c:\windows\pp10.exe

------------

Når loggen fra MalwareBytes skriver -> No action taken hvad tror du så det betyder ?
Du glemte denne 'detalje' -> Tryk på "Vis resultater" knappen efter scanningen - og herefter tryk på "Fjern det valgte" - !!!
Så OM igen med MalwareBytes, KØR EN OPDATE FØRST - nyeste version er 2249 i skrivende stund. Du bruger en gammel 2182 version...
Avatar billede elpede Nybegynder
08. juni 2009 - 22:07 #12
jeg har først slettet filerne efter jeg gemte loggen - my mistake.
Burde det være nok?
Jeg opdaterer lige og scanner igen.
Avatar billede f-arn Guru
08. juni 2009 - 22:17 #13
c:\WINDOWS\st_1242987570.exe (Backdoor.Bot) -> No action taken.

Står også her

2009-05-22 07:11    0    a-------    c:\windows\st_1242987570.exe

Så den var ikke slettet da du lavede DDD loggen
Avatar billede elpede Nybegynder
08. juni 2009 - 22:19 #14
nej præcis....
Avatar billede elpede Nybegynder
08. juni 2009 - 22:22 #15
jeg får i øvrigt ikke lov til at opdatere MalwareBytes. Den skriver at jeg skal tjekke internetforbindelsen...
Avatar billede f-arn Guru
08. juni 2009 - 22:24 #16
Du kan hente en opdatering til malwarebytes her når du ikke kan få programmet til at hente den.

http://malwarebytes.gt500.org/database.jsp

Det er nok ikke den allernyeste men den er bedre end den du kører med.

Bagefter må du gerne lave en ny DDS log
Avatar billede elpede Nybegynder
08. juni 2009 - 22:26 #17
tak...jeg fortsætter i morgen.
Avatar billede elpede Nybegynder
09. juni 2009 - 14:48 #18
så fik jeg scannet engang mere...

MalwareBytes log:

Malwarebytes' Anti-Malware 1.37
Database version: 2202
Windows 5.1.2600 Service Pack 3

09-06-2009 14:43:03
mbam-log-2009-06-09 (14-43-03).txt

Skan type: Fuldstændig skanning (C:\|E:\|)
Objekter skannet: 231138
Tid tilbagelagt: 1 hour(s), 39 minute(s), 33 second(s)

Inficerede Hukommelses Processer: 0
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 0
Inficerede Registeringsdatabase Værdier: 0
Inficerede Registeringsdatabase Filer: 0
Inficerede Mapper: 0
Inficerede Filer: 0

Inficerede Hukommelses Processer:
(Ingen mistænkelige filer fundet)

Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Nøgler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Værdier:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Filer:
(Ingen mistænkelige filer fundet)

Inficerede Mapper:
(Ingen mistænkelige filer fundet)

Inficerede Filer:
(Ingen mistænkelige filer fundet)
Avatar billede elpede Nybegynder
09. juni 2009 - 14:48 #19
derefter attach:


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-05-14.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 30-10-2007 13:42:53
System Uptime: 06-09-2009 08:06:11 (-2130 hours ago)

Motherboard: Hewlett-Packard |  | 30AA
Processor: Intel(R) Core(TM)2 CPU        T5600  @ 1.83GHz | U10 | 1828/166mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 50 GiB total, 11,22 GiB free.
D: is CDROM (CDFS)
E: is FIXED (NTFS) - 6 GiB total, 5,876 GiB free.
N: is NetworkDisk (NTFS) - 72 GiB total, 58,344 GiB free.

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 1394-netværkskort
Device ID: V1394\NIC1394\291D320E23F99
Manufacturer: Microsoft
Name: 1394-netværkskort
PNP Device ID: V1394\NIC1394\291D320E23F99
Service: NIC1394

Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Description: Nokia Windows Portable Device Driver
Device ID: ROOT\WPD\0000
Manufacturer: Nokia
Name: Nokia E65
PNP Device ID: ROOT\WPD\0000
Service: WUDFRd

Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Description: Nokia Windows Portable Device Driver
Device ID: ROOT\WPD\0001
Manufacturer: Nokia
Name: Nokia E65dows Portable Device Driver
PNP Device ID: ROOT\WPD\0001
Service: WUDFRd

Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Description: Nokia 7610 Supernova
Device ID: ROOT\WPD\0002
Manufacturer: Nokia
Name: Nokia 7610 Supernova
PNP Device ID: ROOT\WPD\0002
Service: WUDFRd

==== System Restore Points ===================

RP295: 17-04-2009 07:08:52 - Software Distribution Service 3.0
RP296: 20-04-2009 08:06:35 - Systemkontrolpunkt
RP297: 21-04-2009 09:08:33 - Systemkontrolpunkt
RP298: 23-04-2009 08:44:42 - Systemkontrolpunkt
RP299: 24-04-2009 10:09:04 - Systemkontrolpunkt
RP300: 27-04-2009 10:25:38 - Systemkontrolpunkt
RP301: 28-04-2009 11:08:52 - Systemkontrolpunkt
RP302: 30-04-2009 08:02:29 - Software Distribution Service 3.0
RP303: 04-05-2009 10:37:09 - Systemkontrolpunkt
RP304: 06-05-2009 07:20:41 - Systemkontrolpunkt
RP305: 07-05-2009 08:12:07 - Systemkontrolpunkt
RP306: 11-05-2009 09:14:41 - Systemkontrolpunkt
RP307: 12-05-2009 12:06:16 - Systemkontrolpunkt
RP308: 13-05-2009 07:52:01 - Software Distribution Service 3.0
RP309: 14-05-2009 10:28:42 - Systemkontrolpunkt
RP310: 18-05-2009 07:42:14 - Systemkontrolpunkt
RP311: 19-05-2009 10:10:14 - Systemkontrolpunkt
RP312: 20-05-2009 10:59:15 - Systemkontrolpunkt
RP313: 21-05-2009 11:50:53 - Systemkontrolpunkt
RP314: 22-05-2009 12:05:50 - Systemkontrolpunkt
RP315: 25-05-2009 11:55:51 - Systemkontrolpunkt
RP316: 27-05-2009 07:20:05 - Systemkontrolpunkt
RP317: 28-05-2009 09:38:55 - Systemkontrolpunkt
RP318: 29-05-2009 09:39:51 - Gendan handling
RP319: 02-06-2009 11:58:39 - Systemkontrolpunkt
RP320: 03-06-2009 12:04:40 - Systemkontrolpunkt
RP321: 08-06-2009 12:39:30 - Systemkontrolpunkt
RP322: 08-06-2009 14:11:00 - Removed VMware Player.
RP323: 09-06-2009 14:20:35 - Systemkontrolpunkt

==== Installed Programs ======================


32 Bit HP BiDi Channel Components Installer
Adobe Common File Installer
Adobe Flash Player 10 ActiveX
Adobe Flash Player Plugin
Adobe Illustrator 10
Adobe Photoshop Elements 6.0
Adobe Premiere Elements 4.0
Adobe Premiere Elements 4.0 Templates
Adobe Reader 8.1.5 - Dansk
Adobe Shockwave Player
Adobe SVG Viewer 3.0
Agere Systems HDA Modem
Application Installer 4.00.B5
Azureus Vuze
Belkin Range Extender
Blackjack Ballroom Casino
Casino Action
Casino Classic
Choice Guard
Classic Poker
Digia Client
ExtractNow
Fingerprint Sensor Minimum Install
FloorPlan 3D v9
GIMP 2.4.2
Google Chrome
Google Earth
Google Update Helper
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix til Windows Internet Explorer 7 (KB947864)
Hotfix til Windows Media Player 11 (KB939683)
Hotfix til Windows XP (KB952287)
HP Backup and Recovery Manager Installation
HP Billed-cd
HP Integrated Module with Bluetooth wireless technology
HP Photo and Imaging 2.0 - Scanners
HP Quick Launch Buttons 6.00 H1
HP Support Phone Numbers
HpSdpAppCoreApp
Intel(R) Graphics Media Accelerator Driver
InterActual Player
IP Office Admin Suite
IP Office Voicemail Pro
IPO500 Configurator Tool 4.2
J2SE Runtime Environment 5.0 Update 11
Java(TM) 6 Update 13
Java(TM) 6 Update 5
Java(TM) 6 Update 7
KB408682
KSU-Setup
KSULabel
Malwarebytes' Anti-Malware
Messenger Plus! 3
MetaFrame Presentation Server Web Client for Win32
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Danish Language Pack
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Application Error Reporting
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft National Language Support Downlevel APIs
Microsoft Office PowerPoint Viewer 2003
Microsoft User-Mode Driver Framework Feature Pack 1.5
Microsoft Visual C++ 2005 Redistributable
Mobile Partner
Mobilt Bredband
MSVCRT
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6.0 Parser (KB933579)
NCP Secure Entry Client
Nero Suite
Nokia Connectivity Cable Driver
Nokia Flashing Cable Driver
Nokia PC Suite
Nokia Software Updater
Norman Virus Control
Ontrack Data Recovery Verifile Data Reports
Opdatering til Windows XP (KB951072-v2)
Opdatering til Windows XP (KB951978)
Opdatering til Windows XP (KB955839)
Opdatering til Windows XP (KB961503)
Opdatering til Windows XP (KB967715)
Overførselsværktøj til Windows Live
PC Connectivity Solution
PhoneManager
QuickTime
RTC Client API v1.2
Segoe UI
SIEMENS USB Data Cable
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB938127)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB942615)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB944533)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB950759)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB953838)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB956390)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB958215)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB960714)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB961260)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB963027)
Sikkerhedsopdatering til Windows Media Player (KB911564)
Sikkerhedsopdatering til Windows Media Player (KB952069)
Sikkerhedsopdatering til Windows Media Player 10 (KB936782)
Sikkerhedsopdatering til Windows Media Player 11 (KB936782)
Sikkerhedsopdatering til Windows Media Player 11 (KB954154)
Sikkerhedsopdatering til Windows Media Player 6.4 (KB925398)
Sikkerhedsopdatering til Windows Media Player 9 (KB911565)
Sikkerhedsopdatering til Windows XP (KB923561)
Sikkerhedsopdatering til Windows XP (KB923689)
Sikkerhedsopdatering til Windows XP (KB923789)
Sikkerhedsopdatering til Windows XP (KB938464)
Sikkerhedsopdatering til Windows XP (KB941569)
Sikkerhedsopdatering til Windows XP (KB946648)
Sikkerhedsopdatering til Windows XP (KB950760)
Sikkerhedsopdatering til Windows XP (KB950762)
Sikkerhedsopdatering til Windows XP (KB950974)
Sikkerhedsopdatering til Windows XP (KB951066)
Sikkerhedsopdatering til Windows XP (KB951376-v2)
Sikkerhedsopdatering til Windows XP (KB951376)
Sikkerhedsopdatering til Windows XP (KB951698)
Sikkerhedsopdatering til Windows XP (KB951748)
Sikkerhedsopdatering til Windows XP (KB952004)
Sikkerhedsopdatering til Windows XP (KB952954)
Sikkerhedsopdatering til Windows XP (KB953839)
Sikkerhedsopdatering til Windows XP (KB954211)
Sikkerhedsopdatering til Windows XP (KB954459)
Sikkerhedsopdatering til Windows XP (KB954600)
Sikkerhedsopdatering til Windows XP (KB955069)
Sikkerhedsopdatering til Windows XP (KB956391)
Sikkerhedsopdatering til Windows XP (KB956572)
Sikkerhedsopdatering til Windows XP (KB956802)
Sikkerhedsopdatering til Windows XP (KB956803)
Sikkerhedsopdatering til Windows XP (KB956841)
Sikkerhedsopdatering til Windows XP (KB957095)
Sikkerhedsopdatering til Windows XP (KB957097)
Sikkerhedsopdatering til Windows XP (KB958644)
Sikkerhedsopdatering til Windows XP (KB958687)
Sikkerhedsopdatering til Windows XP (KB958690)
Sikkerhedsopdatering til Windows XP (KB959426)
Sikkerhedsopdatering til Windows XP (KB960225)
Sikkerhedsopdatering til Windows XP (KB960715)
Sikkerhedsopdatering til Windows XP (KB960803)
Sikkerhedsopdatering til Windows XP (KB961373)
SoftConsole
Sonic eDVD
Sony Ericsson PC Suite for Smartphones
Sony Ericsson Symbian 9 Drivers
SoundMAX
Spelling Dictionaries Support For Adobe Reader 8
Symantec Technical Support Web Controls
Synaptics Pointing Device Driver
TeamViewer 4
Techlogica HTTP Server 1.03
Texas Instruments PCIxx21/x515/xx12 drivers.
Tilmeldingsassistent til Windows Live
TIPCI
Update Service
USB Super Link
Vigtig opdatering til Windows Media Player 11 (KB959772)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VLC media player 0.9.8a
VNC Free Edition 4.1.3
WebFldrs XP
Windows Driver Package - Nokia (WUDFRd) WPD  (11/03/2006 6.82.26.2)
Windows Driver Package - Nokia Modem  (11/03/2006 6.82.0.1)
Windows Genuine Advantage Notifications (KB905474)
Windows Internet Explorer 7
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinPcap 4.0.2
Wireshark 1.0.8
ZyWALL SecuExtender

==== End Of File ===========================
Avatar billede elpede Nybegynder
09. juni 2009 - 14:49 #20
og så DDS:


DDS (Ver_09-05-14.01) - NTFSx86 
Run by Per Jensen at 14:45:10,09 on 09-06-2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional  5.1.2600.3.1252.45.1030.18.503.147 [GMT 2:00]

AV: Norman Security Suite *On-access scanning enabled* (Updated)  {EB9EFB40-AE72-4C43-B204-0FCD0E92D5F1}

============== Running Processes ===============

C:\Programmer\Norman\Npm\Bin\eLogsvc.exe
C:\Programmer\Norman\Ngs\Bin\Nprosec.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Programmer\Norman\Npm\Bin\Zanda.exe
C:\Programmer\Norman\npm\bin\nvoy.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\msdtc.exe
C:\Programmer\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Programmer\WIDCOMM\Bluetooth-software\bin\btwdins.exe
C:\Programmer\svpniptun\FtmSrv.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\Programmer\Google\Update\GoogleUpdate.exe
C:\Programmer\NCP\SecureClient\ncpclcfg.exe
C:\Programmer\NCP\SecureClient\ncprwsnt.exe
C:\Programmer\NCP\SecureClient\ncpsec.exe
C:\Programmer\NCP\SecureClient\rwsrsu.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\mqsvc.exe
C:\Programmer\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Programmer\Norman\Npm\Bin\scheduler.exe
C:\Programmer\Norman\Npm\Bin\Njeeves.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Programmer\Analog Devices\Core\smax4pnp.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Programmer\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\SMINST\Scheduler.exe
C:\Programmer\Norman\Npm\Bin\ZLH.EXE
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Programmer\Adobe\Photoshop Elements 6.0\apdproxy.exe
C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Programmer\MessengerPlus! 3\MsgPlus.exe
C:\Programmer\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Per Jensen\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe
C:\Programmer\PC Connectivity Solution\ServiceLayer.exe
c:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Programmer\svpniptun\FtmTray.exe
C:\Programmer\Norman\nse\bin\NSESVC.EXE
C:\Programmer\Norman\Nvc\Bin\Nip.exe
C:\Programmer\Norman\Nvc\bin\nvcoas.exe
C:\Programmer\Norman\Nvc\Bin\cclaw.exe
C:\WINDOWS\system32\mstsc.exe
C:\Documents and Settings\Per Jensen\Skrivebord\dds.scr
C:\WINDOWS\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.dk/
uInternet Connection Wizard,ShellNext = hxxp://www.hp.com/
uInternet Settings,ProxyOverride = *.local;<local>
uInternet Settings,ProxyServer = http=localhost:7171
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\programmer\fælles filer\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Hjælp til tilmelding til Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\programmer\fælles filer\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\programmer\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\programmer\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [MessengerPlus3] "c:\programmer\messengerplus! 3\MsgPlus.exe" /WinStart
uRun: [Google Update] "c:\documents and settings\per jensen\lokale indstillinger\application data\google\update\GoogleUpdate.exe" /c
uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockw~1\SWHELP~1.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)" -"http://www.gratisspil.dk/onlineGame/games/play.php?title=FFX%20Runner&enc=ZmZ4cnVubmVyXzEyMTIyNDM2MTIuZGly&width=600&height=500"
mRun: [MsmqIntCert] regsvr32 /s mqrt.dll
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [SoundMAXPnP] c:\programmer\analog devices\core\smax4pnp.exe
mRun: [SoundMAX] c:\programmer\analog devices\soundmax\Smax4.exe /tray
mRun: [SynTPEnh] c:\programmer\synaptics\syntp\SynTPEnh.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [Cpqset] c:\programmer\hpq\default settings\cpqset.exe
mRun: [Recguard] c:\windows\sminst\Recguard.exe
mRun: [Reminder] c:\windows\creator\Remind_XP.exe
mRun: [Scheduler] c:\windows\sminst\Scheduler.exe
mRun: [Norman ZANDA] "c:\programmer\norman\npm\bin\ZLH.EXE" /LOAD /SPLASH
mRun: [PC Suite for Smartphones] "c:\programmer\sony ericsson\mobile4\application launcher\Application Launcher.exe" /startoptions
mRun: [QuickTime Task] "c:\programmer\quicktime\qttask.exe" -atboottime
mRun: [PCSuiteTrayApplication] c:\programmer\nokia\nokia pc suite 6\LaunchApplication.exe -startup
mRun: [Adobe Photo Downloader] "c:\programmer\adobe\photoshop elements 6.0\apdproxy.exe"
mRun: [Share-to-Web Namespace Daemon] c:\programmer\hewlett-packard\hp share-to-web\hpgs2wnd.exe
mRun: [MessengerPlus3] "c:\programmer\messengerplus! 3\MsgPlus.exe"
mRun: [Adobe Reader Speed Launcher] "c:\programmer\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [SunJavaUpdateSched] "c:\programmer\java\jre6\bin\jusched.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [PcSync] c:\programmer\nokia\nokia pc suite 6\PcSync2.exe /NoDialog
StartupFolder: c:\docume~1\alluse~1\menuen~1\progra~1\start\zywall~1.lnk - c:\programmer\svpniptun\FtmTray.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\programmer\messenger\msmsgs.exe
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {09987A35-84AC-4FB6-9144-4416BA5462BE} - hxxp://www.winner-team.dk/images/windemox/demox.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {19D6A3D5-EA50-4C3B-88F0-79627C325570} - hxxps://www.one.com/static/controls/IlosoftMultipleImageUpload.dll
DPF: {6D868B99-8B01-4B25-9BD1-ED37AFDF5E29} - hxxp://www.ontrackdatarecovery.com/verifile/npvfasp.cab
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} - hxxps://signin3.valueactive.com/Register/Branding/olr3313/OCX/v1018/flashax.cab
DPF: {DC6FEBC5-0A2D-458A-A01B-5DB15EEC4305} - hxxp://webc.pinsensvenner.dk/controls/IlosoftImageUpload.dll
DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

============= SERVICES / DRIVERS ===============

R1 NGS;Norman General Security Driver;c:\programmer\norman\ngs\bin\ngs.sys [2009-4-3 22712]
R1 NPROSEC;Norman Security driver;c:\programmer\norman\ngs\bin\nprosec.sys [2009-5-13 53816]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\programmer\adobe\photoshop elements 6.0\PhotoshopElementsFileAgent.exe [2007-9-11 124832]
R2 FullTunnel;Full Tunnel Mode Service;c:\programmer\svpniptun\FtmSrv.exe [2009-4-16 233472]
R2 ncpclcfg;ncpclcfg;c:\programmer\ncp\secureclient\ncpclcfg.exe [2007-10-31 77824]
R2 ncprwsnt;ncprwsnt;c:\programmer\ncp\secureclient\NCPRWSNT.EXE [2007-10-31 1019904]
R2 NcpSec;NcpSec;c:\programmer\ncp\secureclient\NCPSEC.EXE [2007-10-31 45056]
R2 Ndiskio;Ndiskio;c:\programmer\norman\nse\bin\Ndiskio.sys [2007-10-30 20448]
R2 Norman ZANDA;Norman ZANDA;c:\programmer\norman\npm\bin\Zanda.exe [2007-10-30 408696]
R2 NPROSECSVC;Norman Security service;c:\programmer\norman\ngs\bin\nprosec.exe [2009-5-13 121912]
R2 NVOY;Norman Resource Provider;c:\programmer\norman\npm\bin\nvoy.exe [2009-4-3 126008]
R2 rwsrsu;RwsRsu;c:\programmer\ncp\secureclient\RWSRSU.exe [2007-10-31 266240]
R3 AVMWAN;AVM NDIS WAN CAPI Driver;c:\windows\system32\drivers\avmwan.sys [2008-12-5 37568]
R3 FtmDrv;ZyWALL SecuExtender Virtual NIC;c:\windows\system32\drivers\FtmDrv.sys [2009-4-16 14848]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2006-2-28 87808]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2005-10-21 36352]
R3 ncplentp;NCP Secure Client Adapter Driver;c:\windows\system32\drivers\ncplentp.sys [2007-10-31 73408]
R3 nsesvc;Norman Scanner Engine Service;c:\programmer\norman\nse\bin\Nsesvc.exe [2009-5-20 310328]
R3 NvcMFlt;NvcMFlt;c:\windows\system32\drivers\nvcw32mf.sys [2007-10-30 19512]
R3 nvcoas;Norman Virus Control on-access component;c:\programmer\norman\nvc\bin\Nvcoas.exe [2009-2-23 195640]
R3 Scheduler;Norman Scheduler Service;c:\programmer\norman\npm\bin\scheduler.exe [2009-5-13 130104]
R3 zebrceb;Sony Ericsson Cable Emulation Bus (WDM);c:\windows\system32\drivers\zebrceb.sys [2007-12-3 62984]
S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys --> c:\windows\system32\drivers\Lbd.sys [?]
S2 gupdate1c9959e955ef8e1;Google Update Service (gupdate1c9959e955ef8e1);c:\programmer\google\update\GoogleUpdate.exe [2009-2-23 133104]
S3 fxusbase;AVM ISDN-stik FRITZ!X USB;c:\windows\system32\drivers\fxusbase.sys [2008-12-5 454912]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2009-1-13 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2009-1-13 8320]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-6 34064]
S3 NVCScheduler;Norman Virus Control Scheduler;"c:\programmer\norman\npm\bin\nvcsched.exe" --> c:\programmer\norman\npm\bin\Nvcsched.exe [?]
S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [2005-10-8 22272]
S3 Usblink;Usblink Driver;c:\windows\system32\drivers\ulink.sys [2008-5-23 40788]
S3 VMProDBService;VMProDBService;c:\programmer\avaya\ip office\voicemail pro\vm\VMPDBSvc.exe [2007-11-21 102400]
S3 VoicemailProServer;VoicemailProServer;c:\programmer\avaya\ip office\voicemail pro\vm\VMProV5Svc.exe [2007-11-21 3641344]
S3 VPPP;DrayTek Virtual PPP Adapter;c:\windows\system32\drivers\VPPP.sys [2008-6-18 32784]
S3 zebrbus;Sony Ericsson Composite Device driver;c:\windows\system32\drivers\zebrbus.sys [2007-12-3 83080]
S3 zebrmdfl;Sony Ericsson Modem Filter;c:\windows\system32\drivers\zebrmdfl.sys [2007-12-3 15112]
S3 zebrmdm;Sony Ericsson Port (WDM);c:\windows\system32\drivers\zebrmdm.sys [2007-12-3 108296]
S3 zebrmdmc;Sony Ericsson mRouter Port (WDM);c:\windows\system32\drivers\zebrmdmc.sys [2007-12-3 108424]
S3 zebrsce;Sony Ericsson PC-Connect Port;c:\windows\system32\drivers\zebrsce.sys [2007-12-3 90888]

=============== Created Last 30 ================

2009-06-08 15:03    <DIR>    --d-----    c:\docume~1\perjen~1\applic~1\Malwarebytes
2009-06-08 15:03    40,160    a-------    c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-08 15:03    19,096    a-------    c:\windows\system32\drivers\mbam.sys
2009-06-08 15:03    <DIR>    --d-----    c:\programmer\Malwarebytes' Anti-Malware
2009-06-08 15:03    <DIR>    --d-----    c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-06-08 14:12    <DIR>    --d-----    c:\windows\system32\appmgmt
2009-06-02 14:50    <DIR>    --d-----    c:\docume~1\perjen~1\applic~1\Wireshark
2009-06-02 14:48    <DIR>    --d-----    c:\programmer\WinPcap
2009-06-02 14:37    <DIR>    --d-----    c:\programmer\Wireshark
2009-05-29 09:41    <DIR>    --d-----    c:\windows\system32\wbem\Repository
2009-05-25 07:41    <DIR>    --d-----    c:\programmer\Spyware Doctor
2009-05-21 09:57    <DIR>    --d-----    c:\programmer\Lavasoft
2009-05-21 09:55    <DIR>    --d-----    c:\programmer\Adaware
2009-05-20 21:26    2    ----h---    c:\windows\sto453148.dat
2009-05-20 21:26    2    ----h---    c:\windows\sto452739.dat
2009-05-20 21:26    2    ----h---    c:\windows\sto452712.dat
2009-05-20 07:12    2    ----h---    c:\windows\sto453266.dat
2009-05-20 07:12    2    ----h---    c:\windows\sto452857.dat
2009-05-20 07:12    2    ----h---    c:\windows\sto452830.dat
2009-05-19 13:33    2    ----h---    c:\windows\sto453553.dat
2009-05-19 13:33    2    ----h---    c:\windows\sto453144.dat
2009-05-19 13:33    2    ----h---    c:\windows\sto453117.dat
2009-05-11 08:10    54,156    a---h---    c:\windows\QTFont.qfn

==================== Find3M  ====================

2009-06-08 14:11    430,908    a-------    c:\windows\system32\perfh006.dat
2009-06-08 14:11    78,416    a-------    c:\windows\system32\perfc006.dat
2009-04-16 10:14    52,224    a-------    c:\documents and settings\per jensen\ftmepc.dll
2009-04-16 10:14    0    a-------    c:\documents and settings\per jensen\ssllnch.exe
2009-04-16 10:14    126,976    a-------    c:\documents and settings\per jensen\ssltun.dll
2009-04-16 10:14    9,216    a-------    c:\documents and settings\per jensen\sslsocks.dll
2009-03-21 16:08    1,006,080    --------    c:\windows\system32\dllcache\kernel32.dll
2008-07-22 10:55    340    a---h---    c:\documents and settings\per jensen\hpothb07.dat
2008-02-27 15:53    1,306    a-------    c:\programmer\launch.ica
2008-09-02 08:09    32,768    a--sh---    c:\windows\system32\config\systemprofile\lokale indstillinger\oversigt\history.ie5\mshist012008090220080903\index.dat

============= FINISH: 14:45:55,89 ===============
Avatar billede f-arn Guru
09. juni 2009 - 15:18 #21
Er det her noget du ved noget om?

c:\docume~1\alluse~1\menuen~1\progra~1\start\zywall~1.lnk - c:\programmer\svpniptun\FtmTray.exe

Det ligger i din startupmenu.
Avatar billede f-arn Guru
09. juni 2009 - 16:53 #22
Hent og gem Combofix på dit skrivebord:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe eller herfra

http://subs.geekstogo.com/ComboFix.exe



Højreklik på skrivebordet og vælg ny->tekstdokument og kopier  indholdet mellem  linierne ind og gem filen som CFScript.txt

Du skal sikre dig at den ikke kommer til at hedde CFScript.txt.txt


--------------

Killall::

Snapshot::

Hosts::

DDS::
uInternet Settings,ProxyOverride = *.local;<local>
uInternet Settings,ProxyServer = http=localhost:7171



-------------

Da Combofix kan konflikte med din antivirus er det vigtigt at du deaktiverer den.

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen.
http://www.fromsej.saknet.dk/billeder/cfscript.gif


Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når Combofix er færdig, og efter det (muligvis) har genstartet, skulle der gerne åbnes en logfil: combofix.txt som ligger her C:\ Combofix txt

Indholdet af denne fil må du gerne lægge herind.

Bagefter må du gerne prøve at  opdatere og køre malwarebytes.(hurtig skanning)
Avatar billede elpede Nybegynder
09. juni 2009 - 21:13 #23
ja det er en slags VPN klient der bruges til at oprette forbindelse til en Zywall SSL 10.
Avatar billede elpede Nybegynder
09. juni 2009 - 21:45 #24
log fra combofix:

ComboFix 09-06-09.01 - Per Jensen 09-06-2009 21:24.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.45.1030.18.503.113 [GMT 2:00]
Kører fra: c:\documents and settings\Per Jensen\Skrivebord\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\Per Jensen\Skrivebord\CFScript.txt
AV: Norman Security Suite *On-access scanning disabled* (Updated) {EB9EFB40-AE72-4C43-B204-0FCD0E92D5F1}

advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\PERJEN~1\LOKALE~1\Temp\install_flash_player.exe
c:\documents and settings\Per Jensen\ssllnch.exe
c:\windows\system32\IMSEventLogger.dll
c:\windows\system32\IMSMfcSupport.dll
c:\windows\system32\IMSSupport.dll
E:\Autorun.inf
E:\Desktop.ini

.
(((((((((((((((((((((((((((((  Filer skabt fra 2009-05-09 til 2009-06-09  )))))))))))))))))))))))))))))))))))
.

2009-06-08 13:03 . 2009-06-08 13:03    --------    d-----w-    c:\documents and settings\Per Jensen\Application Data\Malwarebytes
2009-06-08 13:03 . 2009-05-26 11:20    40160    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-08 13:03 . 2009-06-08 13:03    --------    d-----w-    c:\programmer\Malwarebytes' Anti-Malware
2009-06-08 13:03 . 2009-06-08 13:03    --------    d-----w-    c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-08 13:03 . 2009-05-26 11:19    19096    ----a-w-    c:\windows\system32\drivers\mbam.sys
2009-06-02 12:50 . 2009-06-02 12:50    --------    d-----w-    c:\documents and settings\Per Jensen\Application Data\Wireshark
2009-06-02 12:48 . 2009-06-02 12:49    --------    d-----w-    c:\programmer\WinPcap
2009-06-02 12:37 . 2009-06-02 12:49    --------    d-----w-    c:\programmer\Wireshark
2009-05-29 07:41 . 2009-05-29 07:41    --------    d-----w-    c:\windows\system32\wbem\Repository
2009-05-25 05:41 . 2009-06-08 10:15    --------    d---a-w-    c:\documents and settings\All Users\Application Data\TEMP
2009-05-25 05:41 . 2009-06-08 10:17    --------    d-----w-    c:\programmer\Spyware Doctor
2009-05-21 08:21 . 2009-05-21 08:21    --------    d-----w-    c:\documents and settings\LocalService\Skrivebord
2009-05-21 07:57 . 2009-06-04 05:07    --------    d-----w-    c:\programmer\Lavasoft
2009-05-21 07:57 . 2009-06-04 05:07    --------    d-----w-    c:\documents and settings\All Users\Application Data\Lavasoft
2009-05-21 07:55 . 2009-05-21 07:55    --------    d-----w-    c:\programmer\Adaware
2009-05-20 19:26 . 2009-05-20 19:26    2    ---h--w-    c:\windows\sto453148.dat
2009-05-20 19:26 . 2009-05-20 19:26    2    ---h--w-    c:\windows\sto452739.dat
2009-05-20 19:26 . 2009-05-20 19:26    2    ---h--w-    c:\windows\sto452712.dat
2009-05-20 05:12 . 2009-05-20 05:12    2    ---h--w-    c:\windows\sto453266.dat
2009-05-20 05:12 . 2009-05-20 05:12    2    ---h--w-    c:\windows\sto452857.dat
2009-05-20 05:12 . 2009-05-20 05:12    2    ---h--w-    c:\windows\sto452830.dat
2009-05-19 11:33 . 2009-05-19 11:33    2    ---h--w-    c:\windows\sto453553.dat
2009-05-19 11:33 . 2009-05-19 11:33    2    ---h--w-    c:\windows\sto453144.dat
2009-05-19 11:33 . 2009-05-19 11:33    2    ---h--w-    c:\windows\sto453117.dat

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-09 19:31 . 2007-10-30 13:43    --------    d-----w-    c:\programmer\Norman
2009-06-08 12:11 . 2008-09-26 06:53    --------    d-----w-    c:\documents and settings\All Users\Application Data\VMware
2009-06-08 12:11 . 2004-09-17 10:35    78416    ----a-w-    c:\windows\system32\perfc006.dat
2009-06-08 12:11 . 2004-09-17 10:35    430908    ----a-w-    c:\windows\system32\perfh006.dat
2009-06-08 12:10 . 2008-11-03 13:59    --------    d-----w-    c:\programmer\VPN klient
2009-06-08 10:17 . 2008-09-26 06:56    --------    d-----w-    c:\documents and settings\LocalService\Application Data\VMware
2009-05-20 19:31 . 2008-06-19 07:54    --------    d-----w-    c:\programmer\Google
2009-05-20 12:55 . 2008-01-07 12:09    --------    d-----w-    c:\documents and settings\Per Jensen\Application Data\TeamViewer
2009-05-20 06:54 . 2008-03-05 10:11    --------    d-----w-    c:\programmer\Avaya
2009-05-11 11:20 . 2008-04-03 06:53    --------    d-----w-    c:\programmer\Forte label
2009-04-29 13:12 . 2009-04-29 13:10    --------    d-----w-    c:\programmer\Mobile Partner
2009-04-24 11:57 . 2009-04-24 11:57    --------    d-----w-    c:\programmer\CasinoAction
2009-04-16 08:14 . 2009-04-16 08:14    --------    d-----w-    c:\programmer\svpniptun
2009-04-16 08:14 . 2009-04-16 08:14    52224    ----a-w-    c:\documents and settings\Per Jensen\ftmepc.dll
2009-04-16 08:14 . 2009-04-16 08:14    9216    ----a-w-    c:\documents and settings\Per Jensen\sslsocks.dll
2009-04-16 08:14 . 2009-04-16 08:14    126976    ----a-w-    c:\documents and settings\Per Jensen\ssltun.dll
2009-04-16 04:59 . 2009-04-16 04:59    --------    d-----w-    c:\documents and settings\LocalService\Application Data\Xerox
2009-04-06 05:23 . 2009-04-06 05:23    152576    ----a-w-    c:\documents and settings\Per Jensen\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-02 07:03 . 2008-03-05 10:13    19000    ----a-w-    c:\documents and settings\Per Jensen\Lokale indstillinger\Application Data\GDIPFONTCACHEV1.DAT
2009-03-19 07:52 . 2009-03-19 07:52    152576    ----a-w-    c:\documents and settings\Per Jensen\Application Data\Sun\Java\jre1.6.0_12\lzma.dll
2008-02-27 13:53 . 2008-02-27 13:53    1306    ----a-w-    c:\programmer\launch.ica
.

(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MessengerPlus3"="c:\programmer\MessengerPlus! 3\MsgPlus.exe" [2008-04-23 190024]
"Google Update"="c:\documents and settings\Per Jensen\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-03 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\programmer\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"SynTPEnh"="c:\programmer\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 761948]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"QlbCtrl"="c:\programmer\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-05-08 131072]
"Cpqset"="c:\programmer\HPQ\Default Settings\cpqset.exe" [2006-01-26 172094]
"Recguard"="c:\windows\Sminst\Recguard.exe" [2005-12-20 1187840]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2006-03-09 806912]
"Scheduler"="c:\windows\SMINST\Scheduler.exe" [2006-02-15 892928]
"Norman ZANDA"="c:\programmer\Norman\Npm\Bin\ZLH.EXE" [2009-02-11 187504]
"PC Suite for Smartphones"="c:\programmer\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" [2006-04-25 487424]
"QuickTime Task"="c:\programmer\QuickTime\qttask.exe" [2007-12-03 155648]
"PCSuiteTrayApplication"="c:\programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-11-28 222720]
"Adobe Photo Downloader"="c:\programmer\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-10 67488]
"Share-to-Web Namespace Daemon"="c:\programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632]
"MessengerPlus3"="c:\programmer\MessengerPlus! 3\MsgPlus.exe" [2008-04-23 190024]
"Adobe Reader Speed Launcher"="c:\programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\programmer\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"MsmqIntCert"="mqrt.dll" - c:\windows\system32\mqrt.dll [2008-04-14 177152]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2006-01-30 88203]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"PcSync"="c:\programmer\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-11-09 1634304]

c:\documents and settings\All Users\Menuen Start\Programmer\Start\
ZyWALL SecuExtender.lnk - c:\programmer\svpniptun\FtmTray.exe [2009-4-16 204800]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\WINDOWS\\SMINST\\Scheduler.exe"=
"c:\\Programmer\\NCP\\SecureClient\\NCPMON.exe"=
"c:\\Programmer\\Messenger\\msmsgs.exe"=
"c:\\Programmer\\Intuwave\\Shared\\mRouterRuntime\\mRouterRuntime.exe"=
"c:\\Programmer\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Programmer\\Avaya\\IP Office\\Manager\\Manager.exe"=
"c:\\Programmer\\Avaya\\IP Office\\Phone Manager\\PhoneManager.exe"=
"c:\\Programmer\\Avaya\\IP Office\\SoftConsole\\SoftConsole.exe"=
"c:\\Programmer\\typo3\\installer\\TYPO3Winstaller\\Apache\\bin\\Apache.exe"=
"c:\\Programmer\\Classic Poker\\UA.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\Azureus\\Azureus.exe"=
"c:\\Programmer\\Techlogica HTTP server\\Techlogica HTTP Server.exe"=
"c:\\Programmer\\Fælles filer\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Programmer\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmer\\Java\\jre6\\bin\\java.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 NGS;Norman General Security Driver;c:\programmer\Norman\Ngs\Bin\ngs.sys [03-04-2009 08:29 22712]
R1 NPROSEC;Norman Security driver;c:\programmer\Norman\Ngs\Bin\nprosec.sys [13-05-2009 07:17 53816]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\programmer\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [11-09-2007 01:45 124832]
R2 FullTunnel;Full Tunnel Mode Service;c:\programmer\svpniptun\FtmSrv.exe [16-04-2009 10:14 233472]
R2 ncpclcfg;ncpclcfg;c:\programmer\NCP\SecureClient\ncpclcfg.exe [31-10-2007 11:08 77824]
R2 ncprwsnt;ncprwsnt;c:\programmer\NCP\SecureClient\NCPRWSNT.EXE [31-10-2007 11:08 1019904]
R2 NcpSec;NcpSec;c:\programmer\NCP\SecureClient\NCPSEC.EXE [31-10-2007 11:08 45056]
R2 Ndiskio;Ndiskio;c:\programmer\Norman\Nse\Bin\Ndiskio.sys [30-10-2007 16:40 20448]
R2 NPROSECSVC;Norman Security service;c:\programmer\Norman\Ngs\Bin\nprosec.exe [13-05-2009 07:17 121912]
R2 NVOY;Norman Resource Provider;c:\programmer\Norman\Npm\Bin\nvoy.exe [03-04-2009 08:29 126008]
R2 rwsrsu;RwsRsu;c:\programmer\NCP\SecureClient\RWSRSU.exe [31-10-2007 11:08 266240]
R3 AVMWAN;AVM NDIS WAN CAPI Driver;c:\windows\system32\drivers\avmwan.sys [05-12-2008 12:47 37568]
R3 FtmDrv;ZyWALL SecuExtender Virtual NIC;c:\windows\system32\drivers\FtmDrv.sys [16-04-2009 10:14 14848]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [28-02-2006 19:05 87808]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [21-10-2005 13:19 36352]
R3 ncplentp;NCP Secure Client Adapter Driver;c:\windows\system32\drivers\ncplentp.sys [31-10-2007 11:08 73408]
R3 nsesvc;Norman Scanner Engine Service;c:\programmer\Norman\Nse\Bin\Nsesvc.exe [20-05-2009 07:21 310328]
R3 NvcMFlt;NvcMFlt;c:\windows\system32\drivers\nvcw32mf.sys [30-10-2007 16:40 19512]
R3 nvcoas;Norman Virus Control on-access component;c:\programmer\Norman\NVC\bin\Nvcoas.exe [23-02-2009 08:06 195640]
R3 Scheduler;Norman Scheduler Service;c:\programmer\Norman\Npm\Bin\scheduler.exe [13-05-2009 07:17 130104]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 gupdate1c9959e955ef8e1;Google Update Service (gupdate1c9959e955ef8e1);c:\programmer\Google\Update\GoogleUpdate.exe [23-02-2009 12:07 133104]
S3 fxusbase;AVM ISDN-stik FRITZ!X USB;c:\windows\system32\drivers\fxusbase.sys [05-12-2008 12:47 454912]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [13-01-2009 08:16 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [13-01-2009 08:16 8320]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [06-11-2007 22:22 34064]
S3 NVCScheduler;Norman Virus Control Scheduler;"c:\programmer\Norman\Npm\Bin\Nvcsched.exe" --> c:\programmer\Norman\Npm\Bin\Nvcsched.exe [?]
S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [08-10-2005 12:00 22272]
S3 Usblink;Usblink Driver;c:\windows\system32\drivers\ulink.sys [23-05-2008 08:51 40788]
S3 VMProDBService;VMProDBService;c:\programmer\Avaya\IP Office\Voicemail Pro\VM\VMPDBSvc.exe [21-11-2007 22:27 102400]
S3 VoicemailProServer;VoicemailProServer;c:\programmer\Avaya\IP Office\Voicemail Pro\VM\VMProV5Svc.exe [21-11-2007 22:26 3641344]
S3 VPPP;DrayTek Virtual PPP Adapter;c:\windows\system32\drivers\VPPP.sys [18-06-2008 10:09 32784]

--- Andre Services/Drivers i Hukommelsen ---

*Deregistered* - mchInjDrv

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12    REG_MULTI_SZ      Pml Driver HPZ12 Net Driver HPZ12
.
Indhold af mappen 'Planlagte Opgaver'

2009-06-09 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2009-02-23 10:07]

2009-06-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-814552024-205059043-3646978261-1005.job
- c:\documents and settings\Per Jensen\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 09:32]
.
- - - - TOMME GENVEJE FJERNET - - - -

HKCU-RunOnce-Shockwave Updater - c:\windows\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100465 -Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET
SafeBoot-procexp90.Sys


.
------- Yderligere scanning -------
.
uStart Page = hxxp://www.google.dk/
uInternet Connection Wizard,ShellNext = hxxp://www.hp.com/
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {09987A35-84AC-4FB6-9144-4416BA5462BE} - hxxp://www.winner-team.dk/images/windemox/demox.cab
DPF: {19D6A3D5-EA50-4C3B-88F0-79627C325570} - hxxps://www.one.com/static/controls/IlosoftMultipleImageUpload.dll
DPF: {6D868B99-8B01-4B25-9BD1-ED37AFDF5E29} - hxxp://www.ontrackdatarecovery.com/verifile/npvfasp.cab
DPF: {DC6FEBC5-0A2D-458A-A01B-5DB15EEC4305} - hxxp://webc.pinsensvenner.dk/controls/IlosoftImageUpload.dll
DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-09 21:32
Windows 5.1.2600 Service Pack 3 NTFS

scanner skjulte processer ... 

scanner skjulte autostarter ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  Cpqset = c:\programmer\HPQ\Default Settings\cpqset.exe????????P??????n??|?P???? ??4B????????? ????hB??????P?

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer: 0

**************************************************************************
.
--------------------- DLLs startet under kørende Processer ---------------------

- - - - - - - > 'explorer.exe'(1020)
c:\programmer\Norman\nvc\bin\Niphk.dll
c:\programmer\MessengerPlus! 3\MsgPlusLoader.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\programmer\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\programmer\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\programmer\PC Connectivity Solution\ConnAPI.DLL
c:\programmer\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_dan.nlr
c:\programmer\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\programmer\Norman\Npm\Bin\elogsvc.exe
c:\programmer\Norman\Npm\Bin\Zanda.exe
c:\windows\system32\scardsvr.exe
c:\windows\system32\msdtc.exe
c:\programmer\WIDCOMM\Bluetooth-software\bin\btwdins.exe
c:\programmer\Java\jre6\bin\jqs.exe
c:\windows\system32\mqsvc.exe
c:\programmer\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\system32\mqtgsvc.exe
c:\programmer\Norman\Npm\Bin\Njeeves.exe
c:\progra~1\ANALOG~1\Core\smax4pnp.exe
c:\progra~1\SYNAPT~1\SynTP\SynTPEnh.exe
c:\progra~1\HEWLET~1\HPQUIC~1\QLBCTRL.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\SMINST\SCHEDU~1.EXE
c:\progra~1\Norman\Npm\Bin\Zlh.exe
c:\progra~1\QUICKT~1\qttask.exe
c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
c:\programmer\PC Connectivity Solution\ServiceLayer.exe
c:\programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
c:\programmer\Norman\NVC\bin\Nip.exe
c:\programmer\Norman\NVC\bin\CClaw.exe
.
**************************************************************************
.
Gennemført tid: 2009-06-09 21:43 - maskinen blev genstartet
ComboFix-quarantined-files.txt  2009-06-09 19:43

Pre-Kørsel: 11.990.401.024 byte ledig
Post-Kørsel: 12.647.972.864 byte ledig

245    --- E O F ---    2009-05-13 05:54
Avatar billede elpede Nybegynder
09. juni 2009 - 22:29 #25
Det virker....f-arn send fluks et svar!
You are the man!!!!
Avatar billede f-arn Guru
09. juni 2009 - 22:32 #26
Jeg vil nu gerne lige se en log fra malwarebytes :-)
Avatar billede elpede Nybegynder
09. juni 2009 - 22:54 #27
ok så.....er på vej ;-)
Avatar billede elpede Nybegynder
09. juni 2009 - 23:10 #28
ups...malwarebytes log:

Malwarebytes' Anti-Malware 1.37
Database version: 2255
Windows 5.1.2600 Service Pack 3

09-06-2009 23:07:14
mbam-log-2009-06-09 (23-07-14).txt

Skan type: Hurtig skanning
Objekter skannet: 99940
Tid tilbagelagt: 6 minute(s), 52 second(s)

Inficerede Hukommelses Processer: 0
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 0
Inficerede Registeringsdatabase Værdier: 0
Inficerede Registeringsdatabase Filer: 0
Inficerede Mapper: 0
Inficerede Filer: 9

Inficerede Hukommelses Processer:
(Ingen mistænkelige filer fundet)

Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Nøgler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Værdier:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Filer:
(Ingen mistænkelige filer fundet)

Inficerede Mapper:
(Ingen mistænkelige filer fundet)

Inficerede Filer:
c:\WINDOWS\sto452712.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
c:\WINDOWS\sto452739.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
c:\WINDOWS\sto452830.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
c:\WINDOWS\sto452857.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
c:\WINDOWS\sto453117.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
c:\WINDOWS\sto453144.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
c:\WINDOWS\sto453148.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
c:\WINDOWS\sto453266.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
c:\WINDOWS\sto453553.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
Avatar billede f-arn Guru
10. juni 2009 - 08:58 #29
Det var resten. Du kan se om den kan finde mere, hvis du opdatere og kører endnu en hurtig skan. Jeg ved ikke rigtig med den MessengerPlus3. Den har ikke det bedste rygte, så du skal måske overveje at afinstallere den.
Avatar billede elpede Nybegynder
10. juni 2009 - 15:23 #30
min norman snuppede lige en trojansk hest, så der er stadig noget der lurer. Har lige opdateret Malwarebytes igen, så jeg kører lige en fuld scanning. Tak for hjælpen.
Avatar billede f-arn Guru
10. juni 2009 - 18:33 #31
Hvor fandt norman noget?
Avatar billede elpede Nybegynder
11. juni 2009 - 07:17 #32
Der er en meget dårlig log/oversigt i Norman, så jeg kan ikke umiddelbart se hvor den ligger, men den har fundet noget der hedder: W32/Renos.CNZ
Avatar billede f-arn Guru
11. juni 2009 - 08:28 #33
Fandt malwarebytets noget.
Avatar billede elpede Nybegynder
11. juni 2009 - 09:03 #34
har først sat den til at scanne her til morgen. Giver en melding senere.
Avatar billede elpede Nybegynder
11. juni 2009 - 09:34 #35
Malwarebytes' Anti-Malware 1.37
Database version: 2261
Windows 5.1.2600 Service Pack 3

11-06-2009 09:34:39
mbam-log-2009-06-11 (09-34-39).txt

Skan type: Fuldstændig skanning (C:\|E:\|)
Objekter skannet: 231410
Tid tilbagelagt: 1 hour(s), 39 minute(s), 44 second(s)

Inficerede Hukommelses Processer: 0
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 0
Inficerede Registeringsdatabase Værdier: 0
Inficerede Registeringsdatabase Filer: 0
Inficerede Mapper: 0
Inficerede Filer: 0

Inficerede Hukommelses Processer:
(Ingen mistænkelige filer fundet)

Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Nøgler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Værdier:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Filer:
(Ingen mistænkelige filer fundet)

Inficerede Mapper:
(Ingen mistænkelige filer fundet)

Inficerede Filer:
(Ingen mistænkelige filer fundet)
Avatar billede f-arn Guru
11. juni 2009 - 11:21 #36
Prøv at kopiere en log fra norman herind. Gerne sammen med en ny log fra en opdateret Malwarebytes. Den skal helst være lavet som hurtig skan. Ifølge deres eget forum er den faktisk bedre.
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester