Avatar billede madamscroller Nybegynder
29. juni 2009 - 22:28 Der er 17 kommentarer og
1 løsning

Jeg kan ikke åbne forskellige antivirus sider.

Hej Alle


Har et meget mærkeligt problem, fx kan jeg ikke opdatere mit Symantec virus program, har afinst det og prøvet med et gratis prog (virusfighter) kan heller ikke opdatere.

Tænkte så det kunne være noget spyware så jeg havde en AD-AWARE 2007v7.0.2.3 liggende, men den kan heller ikke opdatere.

Når jeg så vil prøve at gå på fx www.lavasoft.com bliver jeg redirect til en side der først hedder www.top100search.com hvorpå siden kommer til at hedde http://67.201.36.14/nolink.html.
Tekst på siden hedder "Sorry this link no longer available"
Det samme med symantec's side

Hvad søren gør man så???


Mvh Rasmus
Avatar billede vejmand Juniormester
29. juni 2009 - 22:30 #1
29. juni 2009 - 22:35 #2
Skal vi gætte:
Win98, ME, W2000, XP, Vista, Win7, ... ?
29. juni 2009 - 22:35 #3
Hent og instalér CCleaner http://www.ccleaner.com/ + http://www.spywarefri.dk/manualer/manual-for-installation-og-brug-af-ccleaner/
Under installationen får du tilbudt [Yahoo Toolbar]. Du kan sige ja eller *NEJ* til den.
Lad programmet foretage en oprydning...

--------

Hent Malwarebytes Anti-Malware herfra:
http://www.besttechie.net/tools/mbam-setup.exe
Eller herfra ->
http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html

Installer programmet - når det er gjort skal du lade programmet opdatere sig. Herefter åbner et vindue, hvor du skal flytte prikken til "Kør et fuldstændigt systemscan" - klik på Skan Knappen - lad programmet arbejde. Når det er færdig (det tager lidt tid afhængig af hvor meget du har på computeren).
Derefter - Tryk på "Vis resultater" knappen efter scanningen - og herefter tryk på "Fjern det valgte" - nu åbnes log'en og du skal gemme den et sted, hvor du kan finde den igen.
Kopier indholdet herind sammen med en frisk log fra HiJackThis...

...og her er omtalte HiJackThis ->
http://www.spywareinfo.dk/index.htm#/manualer/hijackthis.htm

Bemærk at HiJackThis.exe programmet skal gemmes i en dertil oprettet mappe og IKKE køres direkte fra nettet...

PS: Brug denne version af HJT -> http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe

(Jooo - jeg har 'virus' på hjernen...)

Mht.: Vista - HøjreMusseTast på *.EXE filen - Kør som Administrator...

------------------
29. juni 2009 - 22:36 #4
(Det er muligt at ovenstående programmer skal hentes via en anden PC og SÅ overføres hertil med vha. passende medie ...)
Avatar billede madamscroller Nybegynder
29. juni 2009 - 22:39 #5
Ok det vil jeg gå i gang med.
Avatar billede madamscroller Nybegynder
29. juni 2009 - 22:58 #6
Skal du have CC reporten??
Avatar billede madamscroller Nybegynder
29. juni 2009 - 23:09 #7
Jeg kan ikke få lov til at inst malwarebyte, jeg kan se den under joblisten/processer men inst prog starter ikke op...!
Avatar billede f-arn Guru
30. juni 2009 - 01:14 #8
Hent og pak RootRepeal ud.

http://rootrepeal.googlepages.com/RootRepeal.zip

Start og vælg "report", klik skan og sæt flueben i "files"  og lad den søge
Når den er færdig viser den en liste over filer.
Tryk på "save report" og send den herind.
Avatar billede madamscroller Nybegynder
30. juni 2009 - 07:51 #9
Hej, her er reporten:


ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Time:            2009/06/30 07:45
Program Version:        Version 1.3.0.0
Windows Version:        Windows XP Media Center Edition SP3
==================================================

Hidden/Locked Files
-------------------
Path: C:\WINDOWS\system32\TDSShrsr.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\TDSSkkdu.log
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\TDSSlxwp.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\TDSSoiqh.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\TDSSorvd.dat
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\TDSSriqp.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\TDSSxfum.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\TDSS3757.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\TDSS3b5e.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\TDSS407e.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\TDSS40ad.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\TDSS4810.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\TDSS4c75.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\TDSS5416.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\TDSS5985.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\TDSS5fce.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\TDSS3321.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\TDSS27b7.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\TDSS2e8d.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\drivers\TDSSpqlt.sys
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\Ulrik\Local Settings\Temp\TDSSff49.tmp
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\Ulrik\Application Data\SecuROM\UserData\ЃϵϳЅЂϿϽϯІχϯπρϴϱЄϱЃϵϳЅ
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Ulrik\Application Data\SecuROM\UserData\ЃϵϳЅЂϿϽϯІχϯπρЂϻϵЉЃϵϳЅ
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Ulrik\Local Settings\Apps\2.0\6TA098RP.2G0\8NWYQWOB.4TZ\manifests\clickonce_bootstrap.exe.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Ulrik\Local Settings\Apps\2.0\6TA098RP.2G0\8NWYQWOB.4TZ\manifests\clickonce_bootstrap.exe.manifest
Status: Locked to the Windows API!

==EOF==
Avatar billede f-arn Guru
30. juni 2009 - 12:18 #10
Start RootRepeal igen og find denne:

Path: C:\WINDOWS\system32\drivers\TDSSpqlt.sys

Højreklik på den og vælg "wipe file"
Genstart straks og prøv om du ikke kan installere og køre malwarebytes. Husk opdatering. Vi vi gerne se logs fra Malwarebytes og combofix

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Avatar billede madamscroller Nybegynder
30. juni 2009 - 23:14 #11
F-arn det virkede jo.!!

Jeg har lige sat den igang med at scanne...

Der plejer jo at gå en rum tid. Så jeg har en logs fra malware og combo i morgen...
Avatar billede madamscroller Nybegynder
01. juli 2009 - 00:04 #12
Combofix log:

ComboFix 09-06-29.07 - Ulrik 30-06-2009 23:52.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.45.1033.18.2046.1655 [GMT 2:00]
Kører fra: c:\documents and settings\Ulrik\Desktop\ComboFix.exe

advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\Ulrik\LOCALS~1\Temp\install_flash_player.exe
c:\windows\kb913800.exe
c:\windows\system32\TDSSorvd.dat

.
(((((((((((((((((((((((((((((((((((((((  Drivers/Tjenester  )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_TDSSSERV.SYS
-------\Service_TDSSserv.sys


(((((((((((((((((((((((((((((  Filer skabt fra 2009-05-28 til 2009-06-30  )))))))))))))))))))))))))))))))))))
.

2009-06-30 21:10 . 2009-06-30 21:10    --------    d-----w-    c:\documents and settings\Ulrik\Application Data\Malwarebytes
2009-06-30 21:10 . 2009-06-17 09:27    38160    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-30 21:10 . 2009-06-30 21:10    --------    d-----w-    c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-30 21:10 . 2009-06-17 09:27    19096    ----a-w-    c:\windows\system32\drivers\mbam.sys
2009-06-30 21:10 . 2009-06-30 21:10    --------    d-----w-    c:\program files\Malwarebytes' Anti-Malware
2009-06-29 20:53 . 2009-06-29 20:53    --------    d-----w-    c:\program files\CCleaner
2009-06-29 20:14 . 2009-06-29 20:14    --------    d-----w-    c:\program files\Lavasoft
2009-06-29 20:14 . 2009-06-29 20:14    --------    d-----w-    c:\documents and settings\All Users\Application Data\Lavasoft
2009-06-29 20:00 . 2009-06-29 20:00    --------    d-sh--w-    c:\documents and settings\Ulrik\PrivacIE
2009-06-29 19:59 . 2009-06-29 19:59    --------    d-sh--w-    c:\documents and settings\Ulrik\IECompatCache
2009-06-29 19:49 . 2009-06-29 19:49    --------    d-sh--w-    c:\windows\system32\config\systemprofile\IETldCache
2009-06-29 19:48 . 2009-06-29 19:48    --------    d-sh--w-    c:\documents and settings\Ulrik\IETldCache
2009-06-29 19:47 . 2009-06-02 10:12    102912    -c----w-    c:\windows\system32\dllcache\iecompat.dll
2009-06-29 19:47 . 2009-06-29 19:47    --------    d-----w-    c:\windows\ie8updates
2009-06-29 19:47 . 2009-04-30 21:22    12800    -c----w-    c:\windows\system32\dllcache\xpshims.dll
2009-06-29 19:47 . 2009-04-30 21:22    246272    -c----w-    c:\windows\system32\dllcache\ieproxy.dll
2009-06-29 19:46 . 2009-06-29 19:46    --------    dc-h--w-    c:\windows\ie8
2009-06-29 18:01 . 2009-06-29 18:01    --------    d-----w-    C:\ESET.Smart.Security.NOD32.Antivirus.3.0.667-DB4Ever
2009-06-29 17:58 . 2009-06-29 17:58    --------    d-----w-    c:\program files\UlisesSoft
2009-06-29 17:46 . 2009-06-29 17:46    --------    d-----w-    c:\documents and settings\All Users\Application Data\ESET
2009-06-29 17:26 . 2009-06-29 17:26    --------    d-----w-    c:\documents and settings\Ulrik\Local Settings\Application Data\Symantec
2009-06-29 17:24 . 2009-06-29 20:08    --------    d-----w-    c:\documents and settings\All Users\Application Data\Symantec
2009-06-18 10:55 . 2009-06-18 10:55    --------    d-----w-    c:\program files\QuickTime

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-30 21:56 . 2007-10-13 10:27    --------    d-----w-    c:\program files\Steam
2009-06-29 20:14 . 2009-03-26 18:11    --------    d-----w-    c:\program files\Common Files\Wise Installation Wizard
2009-06-29 20:08 . 2008-04-27 16:09    --------    d-----w-    c:\program files\Common Files\Symantec Shared
2009-06-04 13:57 . 2007-02-08 17:11    --------    d-----w-    c:\program files\World of Warcraft
2009-05-13 05:15 . 2006-03-04 03:33    915456    ----a-w-    c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2004-08-10 11:00    345600    ----a-w-    c:\windows\system32\localspl.dll
2009-04-21 13:03 . 2009-04-21 13:03    75048    ----a-w-    c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-04-17 12:26 . 2004-08-10 11:00    1847168    ----a-w-    c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-10 11:00    585216    ----a-w-    c:\windows\system32\rpcrt4.dll
2007-02-21 21:51 . 2007-05-19 15:45    66672    ----a-w-    c:\program files\mozilla firefox\components\jar50.dll
2007-02-21 21:51 . 2007-05-19 15:45    54376    ----a-w-    c:\program files\mozilla firefox\components\jsd3250.dll
2007-02-21 21:51 . 2007-05-19 15:45    34952    ----a-w-    c:\program files\mozilla firefox\components\myspell.dll
2007-02-21 21:51 . 2007-05-19 15:45    46720    ----a-w-    c:\program files\mozilla firefox\components\spellchk.dll
2007-02-21 21:51 . 2007-05-19 15:45    172144    ----a-w-    c:\program files\mozilla firefox\components\xpinstal.dll
2009-02-24 19:34 . 2009-02-24 19:34    1044480    ----a-w-    c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34    200704    ----a-w-    c:\program files\mozilla firefox\plugins\ssldivx.dll
.

(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Steam"="c:\program files\Steam\Steam.exe" [2009-06-12 1217784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-09-13 7696384]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-24 136600]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-26 177472]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3-enGB-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.6.6337-enGB-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Cyanide\\GameCenter\\GameCenter.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Steam\\SteamApps\\julikras\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Steam\\SteamApps\\julikras123\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\davidpratt\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R1 NGS;Norman General Security Driver;c:\virusfighter\Nvc\Bin\ngs.sys [26-03-2009 19:09 22712]
S3 USBAAPL;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl.sys [20-12-2008 16:39 32000]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Indhold af mappen 'Planlagte Opgaver'

2009-03-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2009-06-30 c:\windows\Tasks\Søg efter opdateringer til Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 10:20]
.
- - - - TOMME GENVEJE FJERNET - - - -

Notify-NavLogon - (no file)


.
------- Yderligere scanning -------
.
uStart Page = hxxp://www.google.dk/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://g.msn.dk/0SEDADK/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: {9C196458-4145-46AF-8A77-1506878DFECA} - ftp://ftp.sektornet.dk/sektornet/skolekom/fcplugin.cab
FF - ProfilePath - c:\documents and settings\Ulrik\Application Data\Mozilla\Firefox\Profiles\fhtedc7d.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-30 23:57
Windows 5.1.2600 Service Pack 3 NTFS

scanner skjulte processer ... 

scanner skjulte autostarter ...

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer: 0

**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------

[HKEY_USERS\S-1-5-21-1229272821-261903793-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:2f,13,60,98,d3,87,21,7d,de,9d,3d,ce,22,72,68,80,5b,ae,9b,9e,6d,9c,05,
  b7,e8,d0,a9,b5,93,5d,ed,a9,12,ae,aa,7e,c2,b3,89,c1,a9,02,bb,87,f5,aa,df,b9,\
"??"=hex:c1,94,61,d8,ca,1e,17,01,b6,6b,3b,b1,8b,7b,9e,0b
.
--------------------- DLLs startet under kørende Processer ---------------------

- - - - - - - > 'explorer.exe'(1504)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\dllhost.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Windows Live\Messenger\usnsvc.exe
.
**************************************************************************
.
Gennemført tid: 2009-06-30 23:59 - maskinen blev genstartet
ComboFix-quarantined-files.txt  2009-06-30 21:59

Pre-Kørsel: 274.401.873.920 bytes free
Post-Kørsel: 274.656.866.304 byte ledig

181    --- E O F ---    2009-06-29 19:47
Avatar billede madamscroller Nybegynder
01. juli 2009 - 00:04 #13
Malware log:

Malwarebytes' Anti-Malware 1.38
Database version: 2356
Windows 5.1.2600 Service Pack 3

30-06-2009 23:46:44
mbam-log-2009-06-30 (23-46-44).txt

Skan type: Fuldstændig skanning (C:\|I:\|)
Objekter skannet: 159747
Tid tilbagelagt: 33 minute(s), 38 second(s)

Inficerede Hukommelses Processer: 0
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 8
Inficerede Registeringsdatabase Værdier: 1
Inficerede Registeringsdatabase Filer: 0
Inficerede Mapper: 15
Inficerede Filer: 36

Inficerede Hukommelses Processer:
(Ingen mistænkelige filer fundet)

Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Nøgler:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Cognac (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\CrucialSoft Ltd (Rogue.MSantiSpyware2009) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\MSFox (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\TDSSdata (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\TDSS (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Solt Lake Software (Rogue.ProAntiSpyware2009) -> Quarantined and deleted successfully.

Inficerede Registeringsdatabase Værdier:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\WINID (Malware.Trace) -> Quarantined and deleted successfully.

Inficerede Registeringsdatabase Filer:
(Ingen mistænkelige filer fundet)

Inficerede Mapper:
c:\program files\VirusRemover2008 (Rogue.VirusRemove) -> Quarantined and deleted successfully.
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\crucialsoft ltd\MS AntiSpyware 2009 (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\crucialsoft ltd\ms antispyware 2009\BASE (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\crucialsoft ltd\ms antispyware 2009\DELETED (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\crucialsoft ltd\ms antispyware 2009\LOG (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\crucialsoft ltd\ms antispyware 2009\SAVED (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\documents and settings\Ulrik\application data\VirusRemover2008 (Rogue.VirusRemover) -> Quarantined and deleted successfully.
c:\documents and settings\Ulrik\application data\virusremover2008\Logs (Rogue.VirusRemover) -> Quarantined and deleted successfully.
c:\documents and settings\All Users\Application Data\Solt Lake Software (Rogue.ProAntiSpyware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\solt lake software\Pro Antispyware 2009 (Rogue.ProAntiSpyware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\solt lake software\pro antispyware 2009\BASE (Rogue.ProAntiSpyware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\solt lake software\pro antispyware 2009\DELETED (Rogue.ProAntiSpyware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\solt lake software\pro antispyware 2009\LOG (Rogue.ProAntiSpyware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\solt lake software\pro antispyware 2009\SAVED (Rogue.ProAntiSpyware) -> Quarantined and deleted successfully.

Inficerede Filer:
c:\system volume information\_restore{d43cbcf7-5ffe-4b4b-8736-ba4dca3b3eca}\RP138\A0060965.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d43cbcf7-5ffe-4b4b-8736-ba4dca3b3eca}\RP138\A0060967.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\TDSShrsr.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\TDSSriqp.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\TDSS3757.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\TDSS3b5e.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\TDSS40ad.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\TDSS4810.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\TDSS4c75.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\TDSS5416.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\TDSS5985.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\TDSS5fce.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\TDSS3321.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\TDSS2e8d.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\crucialsoft ltd\ms antispyware 2009\BASE\vbase.tmp (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\crucialsoft ltd\ms antispyware 2009\LOG\20081223135053984.log (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\crucialsoft ltd\ms antispyware 2009\LOG\20081223183837093.log (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\crucialsoft ltd\ms antispyware 2009\LOG\20081223184211046.log (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\crucialsoft ltd\ms antispyware 2009\LOG\20081226182325000.log (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\crucialsoft ltd\ms antispyware 2009\LOG\20081226182644250.log (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\crucialsoft ltd\ms antispyware 2009\LOG\20081226201201453.log (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\crucialsoft ltd\ms antispyware 2009\LOG\20081227104112468.log (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\crucialsoft ltd\ms antispyware 2009\LOG\20081228133654484.log (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\crucialsoft ltd\ms antispyware 2009\LOG\20081228141127453.log (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\documents and settings\Ulrik\application data\virusremover2008\Logs\scns.log (Rogue.VirusRemover) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\solt lake software\pro antispyware 2009\LOG\20081226193648573.log (Rogue.ProAntiSpyware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\solt lake software\pro antispyware 2009\LOG\20081226201022029.log (Rogue.ProAntiSpyware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\solt lake software\pro antispyware 2009\LOG\20081226201202765.log (Rogue.ProAntiSpyware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\solt lake software\pro antispyware 2009\LOG\20081227104113234.log (Rogue.ProAntiSpyware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\solt lake software\pro antispyware 2009\LOG\20081228133654421.log (Rogue.ProAntiSpyware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\solt lake software\pro antispyware 2009\LOG\20081228141127656.log (Rogue.ProAntiSpyware) -> Quarantined and deleted successfully.
c:\documents and settings\Ulrik\local settings\Temp\TDSSff49.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\TDSS27b7.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\TDSS407e.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\TDSSkkdu.log (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\drivers\TDSSpqlt.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
Avatar billede madamscroller Nybegynder
01. juli 2009 - 00:05 #14
Hijack this log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:05:26, on 01-07-2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Ulrik\Desktop\HiJackThis-1.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.dk/0SEDADK/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: FirstClass® - {02011FE3-C22B-451d-9A25-BF4DBB38B8E7} - C:\WINDOWS\Downloaded Program Files\fcplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1170006158875
O16 - DPF: {9C196458-4145-46AF-8A77-1506878DFECA} (FirstClass® Control) - ftp://ftp.sektornet.dk/sektornet/skolekom/fcplugin.cab
O18 - Protocol: fcp - {B3133379-8789-4D3C-9593-C205D7297501} - C:\WINDOWS\Downloaded Program Files\fcplugin.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6643 bytes
Avatar billede f-arn Guru
01. juli 2009 - 19:36 #15
Hvordan kører computeren nu?
Avatar billede madamscroller Nybegynder
01. juli 2009 - 21:45 #16
Pt kører den uden problemer, der er ikke noget at se i de div logs??

Jeg kan åbne de forskellige antivirus sider osv.

Skal vi sige at det var det.


Mange tak herfra....


Mvh Rasmus

Ps skriver du lige et svar.
Avatar billede f-arn Guru
02. juli 2009 - 13:26 #17
Det ser pænt ud bortset fra at jeg ikke synes jeg kan se noget antivirus program.
http://www.spywarefri.dk/sikkerhedspakken/
Avatar billede madamscroller Nybegynder
02. juli 2009 - 22:59 #18
Jeg har inst det efter scaningen.


Mange tak for hjælpen!
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester