Avatar billede ThomasBojsen93 Nybegynder
02. marts 2010 - 11:37 Der er 9 kommentarer og
1 løsning

Check af HiJackThis Log

Hej derude. Er efterhånden blevet ret mistænksom overfor en Malware infektion. Har kørt bullguard flere gange efterhånden uden nogen form for resultat. Læste mig derefter til at HiJackThis skulle være mere effektivt overfor malware, så derfor har jeg fremskaffet denne log.

Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 11:30:52, on 02-03-2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Lenovo\VeriFace\PManage.exe
C:\Program Files\Lenovo\Energy Management\utility.exe
C:\Program Files\Lenovo\Energy Management\Energy Management.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\BullGuard Ltd\BullGuard\BullGuard.exe
C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
C:\Windows\system32\ctfmon.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\conime.exe
C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Thomas\AppData\Local\Temp\Ajd.exe
C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\HiJackThis\TrendMicro\HiJackThis\HiJackThis.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nixat.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lenovo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nixat.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [VeriFaceManager] C:\Program Files\Lenovo\VeriFace\PManage.exe
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKLM\..\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\utility.exe
O4 - HKLM\..\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [BullGuard] "C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe" -boot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [BullGuard] "C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe"
O4 - HKCU\..\Run: [TOY5KNQ8OC] C:\Users\Thomas\AppData\Local\Temp\Ajd.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\RunOnce: []  (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-20\..\RunOnce: []  (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\RunOnce: []  (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: []  (User 'Default user')
O4 - Startup: 1964233.lnk = C:\Users\Thomas\AppData\Local\Temp\nvvscv.exe
O4 - Startup: 2070234.lnk = C:\Users\Thomas\AppData\Local\Temp\a32pasop.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Download all by YouTube Robot - C:\Program Files\YouTubeRobot\downall.htm
O8 - Extra context menu item: Download by YouTube Robot - C:\Program Files\YouTubeRobot\downlink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send billede til &Bluetooth-enhed... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send siden til &Bluetooth-enhed... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - (no file)
O9 - Extra 'Tools' menuitem: Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BullGuard LiveUpdate (BgLiveSvc) - BullGuard Ltd. - C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
O23 - Service: BgRaSvc - BullGuard Ltd. - C:\Program Files\BullGuard Ltd\BullGuard\Support\BgRaSvc.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe
O23 - Service: IGRS - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lenovo ReadyComm AppSvc - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\AppSvc.exe
O23 - Service: Lenovo ReadyComm ConnSvc - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SMServer - SMServer - C:\Windows\system32\snmvtsvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: STSService - Unknown owner - C:\Program Files\SoundTaxi Media Suite\STSService.exe (file missing)
O23 - Service: System Repair Windows Update Monitor (System_Repair_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe

--
End of file - 10212 bytes
Avatar billede f-arn Guru
02. marts 2010 - 11:52 #1
Hent "Malwarebytes' Anti-Malware" her: http://www.besttechie.net/tools/mbam-setup.exe
Installer og start programmet, klik på fanen opdater, klik Tjek for opdatering, lav "Hurtig skan" under fanebladet "skanner"
Bagefter klik på "vis resultater", tryk på "Fjern det valgte" og send loggen herind sammen med en ny hijackthis log

Mht.: Vista og Windows 7 - højreklik på filen - Kør som Administrator.[

NB Når du opdaterer Malwarebytes, så klik på opdater til den skriver at der ikke er flere opdateringer.
Avatar billede ThomasBojsen93 Nybegynder
02. marts 2010 - 13:19 #2
Malwarebytes' Anti-Malware 1.44
Database version: 3811
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18882

02-03-2010 13:18:08
mbam-log-2010-03-02 (13-18-08).txt

Skan type: Hurtig skanning
Objekter skannet: 108896
Tid tilbagelagt: 5 minute(s), 27 second(s)

Inficerede Hukommelses Processer: 0
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 4
Inficerede Registeringsdatabase Værdier: 0
Inficerede Registeringsdatabase Filer: 0
Inficerede Mapper: 0
Inficerede Filer: 11

Inficerede Hukommelses Processer:
(Ingen mistænkelige filer fundet)

Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Nøgler:
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ROUA3O12PW (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\TOY5KNQ8OC (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Inficerede Registeringsdatabase Værdier:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Filer:
(Ingen mistænkelige filer fundet)

Inficerede Mapper:
(Ingen mistænkelige filer fundet)

Inficerede Filer:
C:\Users\Thomas\AppData\Local\Temp\1157319.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Thomas\AppData\Local\Temp\330434.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Thomas\AppData\Local\Temp\Ajb.exe (Trojan.Fraudpack) -> Quarantined and deleted successfully.
C:\Users\Thomas\AppData\Local\Temp\lms.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Users\Thomas\AppData\Local\Temp\ntexplore.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Users\Thomas\AppData\Local\Temp\nvvscv.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Users\Thomas\AppData\Local\Temp\a32pasop.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Windows\Temp\wmpscfgs.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1964233.lnk (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2070234.lnk (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\Thomas\oashdihasidhasuidhiasdhiashdiuasdhasd (Malware.Trace) -> Quarantined and deleted successfully.


Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 13:19:04, on 02-03-2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Lenovo\VeriFace\PManage.exe
C:\Program Files\Lenovo\Energy Management\utility.exe
C:\Program Files\Lenovo\Energy Management\Energy Management.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\BullGuard Ltd\BullGuard\BullGuard.exe
C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
C:\Windows\system32\ctfmon.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\conime.exe
C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\HiJackThis\TrendMicro\HiJackThis\HiJackThis.exe
C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\System32\NOTEPAD.EXE
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nixat.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lenovo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nixat.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [VeriFaceManager] C:\Program Files\Lenovo\VeriFace\PManage.exe
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKLM\..\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\utility.exe
O4 - HKLM\..\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe
O4 - HKLM\..\Run: [BullGuard] "C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe" -boot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [BullGuard] "C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\RunOnce: []  (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-20\..\RunOnce: []  (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\RunOnce: []  (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: []  (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Download all by YouTube Robot - C:\Program Files\YouTubeRobot\downall.htm
O8 - Extra context menu item: Download by YouTube Robot - C:\Program Files\YouTubeRobot\downlink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send billede til &Bluetooth-enhed... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send siden til &Bluetooth-enhed... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - (no file)
O9 - Extra 'Tools' menuitem: Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BullGuard LiveUpdate (BgLiveSvc) - BullGuard Ltd. - C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
O23 - Service: BgRaSvc - BullGuard Ltd. - C:\Program Files\BullGuard Ltd\BullGuard\Support\BgRaSvc.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe
O23 - Service: IGRS - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lenovo ReadyComm AppSvc - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\AppSvc.exe
O23 - Service: Lenovo ReadyComm ConnSvc - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SMServer - SMServer - C:\Windows\system32\snmvtsvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: STSService - Unknown owner - C:\Program Files\SoundTaxi Media Suite\STSService.exe (file missing)
O23 - Service: System Repair Windows Update Monitor (System_Repair_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe

--
End of file - 9830 bytes
Avatar billede patrick14 Nybegynder
02. marts 2010 - 14:56 #3
afinstaller den hijackthis at du har. Gør så dette:


Hent og kør sas

Hent og installer 1. http://www.superantispyware.com/downloads/SUPERAntiSpyware1241.exe

Start superantispyware, klik på Check for updates.
Klik på Scan your Computer, sæt flueben i de drev der skal scannes. (Fixed disk betyder harddisk)
Flyt prikken til Perform complete scan og klik på Næste, så kører scanningen.


Når den er færdig kommer der et vindue med en opsummering, klik på OK, klik så på næste og så på Udfør.

Der kommer et vindue med Quarantine and removal Complete, klik på OK, klik på Udfør.
Luk programmet, genstart normalt.
---------------------------------------
Start SuperAntiSpyware igen, klik på Preferences, skift til fanebladet Statistics/Logs, i vinduet dobbeltklikker du på SUPERAntiSpyware Scan Log, og gemmer den på skrivebordet.





Hent HijackThis her, gem den I en mappe så du kan finde den.
http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe
1. Dobbeltklik på det nye HijackThis ikon
Vista bruger skal klikke med højre-musetast på program filen > Vælg "Kør som administrator"
2. På menuen der kommer op, klikker du på: Do a systemscan and save a logfile.
3. Efter et kort øjeblik åbner en logfil i notesblok, kopier teksten herind
Avatar billede f-arn Guru
02. marts 2010 - 15:26 #4
Hent og gem Combofix på dit skrivebord:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

eller herfra

http://subs.geekstogo.com/ComboFix.exe

Kør så combofix.exe og følg anvisningerne.

Vigtigt--> Deaktiver dit antivirusprogram da det kan forstyrrer combofix
Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når combofix er færdig, og efter det (muligvis) har genstartet, skulle der gerne åbnes en logfil: combofix.txt
Indholdet af denne fil må du gerne lægge herind.

Den kan findes her:  C:\Combofix.txt
Avatar billede ThomasBojsen93 Nybegynder
02. marts 2010 - 17:25 #5
ComboFix 10-03-01.03 - Thomas 02-03-2010  15:42:20.1.2 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.45.1030.18.3036.2136 [GMT 1:00]
Kører fra: c:\users\Thomas\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-186105711-3158523747-2434017840-1004
c:\$recycle.bin\S-1-5-21-186105711-3158523747-2434017840-500
c:\$recycle.bin\S-1-5-21-3530434775-473878278-3389486113-500
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
c:\recycler\S-1-5-21-2633395656-6837033406-957609252-5426
c:\recycler\S-1-5-21-4262420199-2647965867-257981165-1164
c:\recycler\S-1-5-21-4980013531-4405771239-404542216-4004
c:\recycler\S-1-5-21-5605351285-1250294466-696199822-5994
c:\recycler\S-1-5-21-6485480005-2232648316-895158425-9614
c:\recycler\S-1-5-21-8277965069-1628086033-769540952-4478
c:\recycler\S-1-5-21-8793315954-2464035581-195562868-1232
c:\recycler\S-1-5-21-9429369601-0545584960-034443823-5940
c:\recycler\S-1-5-21-9758471665-5191257731-575439165-3836
c:\users\Thomas\AppData\Roaming\.#
c:\users\Thomas\AppData\Roaming\.#\MBX@1B04@22B2960.###
c:\users\Thomas\AppData\Roaming\.#\MBX@1B04@22B2990.###
c:\users\Thomas\AppData\Roaming\.#\MBX@1B04@22B29C0.###
c:\windows\system32\SIntf16.dll

.
(((((((((((((((((((((((((((((  Filer skabt fra 2010-02-02 til 2010-03-02  )))))))))))))))))))))))))))))))))))
.

2010-03-02 15:18 . 2010-03-02 15:19    --------    d-----w-    c:\users\Thomas\AppData\Local\temp
2010-03-02 15:18 . 2010-03-02 15:18    --------    d-----w-    c:\users\Default\AppData\Local\temp
2010-03-02 14:28 . 2010-03-02 14:28    --------    d-----w-    c:\programdata\SUPERAntiSpyware.com
2010-03-02 14:28 . 2010-03-02 14:32    --------    d-----w-    c:\program files\SUPERAntiSpyware
2010-03-02 14:28 . 2010-03-02 14:34    --------    d-----w-    c:\users\Thomas\AppData\Roaming\SUPERAntiSpyware.com
2010-03-02 11:34 . 2010-03-02 11:34    --------    d-----w-    c:\users\Thomas\AppData\Roaming\Malwarebytes
2010-03-02 11:34 . 2010-01-07 15:07    38224    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-02 11:34 . 2010-03-02 11:34    --------    d-----w-    c:\program files\Malwarebytes' Anti-Malware
2010-03-02 11:34 . 2010-03-02 11:34    --------    d-----w-    c:\programdata\Malwarebytes
2010-03-02 11:34 . 2010-01-07 15:07    19160    ----a-w-    c:\windows\system32\drivers\mbam.sys
2010-03-02 11:00 . 2010-02-24 08:16    181632    ------w-    c:\windows\system32\MpSigStub.exe
2010-03-02 08:48 . 2010-03-02 09:58    --------    d-----w-    c:\programdata\RegCure
2010-03-02 08:48 . 2010-03-02 08:50    --------    d-----w-    c:\program files\RegCure
2010-02-25 09:25 . 2010-01-25 12:00    471552    ----a-w-    c:\windows\system32\secproc_isv.dll
2010-02-25 09:25 . 2010-01-25 12:00    471552    ----a-w-    c:\windows\system32\secproc.dll
2010-02-25 09:25 . 2010-01-25 12:00    152576    ----a-w-    c:\windows\system32\secproc_ssp_isv.dll
2010-02-25 09:25 . 2010-01-25 12:00    152064    ----a-w-    c:\windows\system32\secproc_ssp.dll
2010-02-25 09:25 . 2010-01-25 11:58    332288    ----a-w-    c:\windows\system32\msdrm.dll
2010-02-25 09:25 . 2010-01-25 08:21    526336    ----a-w-    c:\windows\system32\RMActivate_isv.exe
2010-02-25 09:25 . 2010-01-25 08:21    346624    ----a-w-    c:\windows\system32\RMActivate_ssp_isv.exe
2010-02-25 09:25 . 2010-01-25 08:21    518144    ----a-w-    c:\windows\system32\RMActivate.exe
2010-02-25 09:25 . 2010-01-25 08:21    347136    ----a-w-    c:\windows\system32\RMActivate_ssp.exe
2010-02-25 08:08 . 2010-03-02 10:46    --------    d-----w-    C:\adgangforalle.dk
2010-02-24 08:47 . 2010-01-23 09:26    2048    ----a-w-    c:\windows\system32\tzres.dll
2010-02-24 08:46 . 2010-01-06 15:39    1696256    ----a-w-    c:\windows\system32\gameux.dll
2010-02-24 08:46 . 2010-01-06 15:38    28672    ----a-w-    c:\windows\system32\Apphlpdm.dll
2010-02-24 08:46 . 2010-01-06 13:30    4240384    ----a-w-    c:\windows\system32\GameUXLegacyGDFs.dll
2010-02-20 17:07 . 2010-02-20 17:07    --------    d-----w-    C:\Converted
2010-02-20 17:04 . 2010-02-17 17:21    245760    ----a-w-    c:\windows\system32\snmvtsvc.exe
2010-02-20 17:04 . 2010-02-18 07:00    14392    ----a-w-    c:\windows\system32\SndTVideo.dll
2010-02-20 17:04 . 2010-02-18 07:00    5688    ----a-w-    c:\windows\system32\SndTVideo.sys
2010-02-20 17:04 . 2010-02-18 06:59    23096    ----a-w-    c:\windows\system32\SndTAudio.sys
2010-02-20 17:04 . 2010-02-18 06:59    23096    ----a-w-    c:\windows\system32\drivers\SndTAudio.sys
2010-02-20 14:49 . 2010-02-20 14:49    --------    d-----w-    c:\program files\PixiePack Codec Pack
2010-02-20 14:46 . 2010-03-01 09:36    --------    d-----w-    c:\programdata\RapidSolution
2010-02-20 14:46 . 2010-03-01 09:36    --------    d-----w-    c:\program files\RapidSolution
2010-02-20 14:43 . 2010-02-20 14:43    --------    d-----w-    c:\users\Thomas\AppData\Local\RapidSolution
2010-02-16 10:44 . 2010-02-16 10:44    27752    ----a-w-    c:\windows\system32\drivers\rrnetcap.sys
2010-02-12 16:45 . 2010-03-02 13:07    --------    d-----w-    c:\users\Thomas\.xmoto
2010-02-12 16:45 . 2010-03-01 18:42    --------    d-----w-    c:\program files\XMoto
2010-02-12 16:30 . 2010-02-12 16:30    --------    d-----w-    c:\programdata\Big Fish Games
2010-02-12 16:16 . 2010-02-12 16:16    --------    d-----w-    c:\programdata\Trymedia
2010-02-12 16:16 . 2010-02-12 16:16    --------    d-----w-    c:\program files\BFG
2010-02-12 16:06 . 2010-02-12 16:28    --------    d-----w-    c:\programdata\PopCap Games
2010-02-12 14:21 . 2010-02-12 14:21    --------    d-----w-    c:\program files\iPod
2010-02-12 14:21 . 2010-02-12 14:22    --------    d-----w-    c:\program files\iTunes
2010-02-12 14:17 . 2010-02-12 14:17    --------    d-----w-    c:\program files\Safari
2010-02-12 11:57 . 2010-02-12 11:57    --------    d-----w-    c:\program files\Windows Portable Devices
2010-02-09 15:24 . 2009-09-10 02:00    1164800    ----a-w-    c:\windows\system32\UIRibbonRes.dll
2010-02-09 15:24 . 2009-09-10 02:00    92672    ----a-w-    c:\windows\system32\UIAnimation.dll
2010-02-09 15:24 . 2009-09-10 02:01    3023360    ----a-w-    c:\windows\system32\UIRibbon.dll
2010-02-09 15:22 . 2009-10-01 01:02    30208    ----a-w-    c:\windows\system32\WPDShextAutoplay.exe
2010-02-09 15:22 . 2009-10-01 01:02    31232    ----a-w-    c:\windows\system32\BthMtpContextHandler.dll
2010-02-09 15:22 . 2009-10-01 01:01    81920    ----a-w-    c:\windows\system32\wpdbusenum.dll
2010-02-09 15:22 . 2009-10-01 01:01    60928    ----a-w-    c:\windows\system32\PortableDeviceConnectApi.dll
2010-02-09 15:22 . 2009-10-01 01:02    2537472    ----a-w-    c:\windows\system32\wpdshext.dll
2010-02-09 15:22 . 2009-10-01 01:02    334848    ----a-w-    c:\windows\system32\PortableDeviceApi.dll
2010-02-09 15:22 . 2009-10-01 01:02    87552    ----a-w-    c:\windows\system32\WPDShServiceObj.dll
2010-02-09 15:22 . 2009-10-01 01:01    546816    ----a-w-    c:\windows\system32\wpd_ci.dll
2010-02-09 15:22 . 2009-10-01 01:01    160256    ----a-w-    c:\windows\system32\PortableDeviceTypes.dll
2010-02-09 15:22 . 2009-10-01 01:01    196608    ----a-w-    c:\windows\system32\PortableDeviceWMDRM.dll
2010-02-09 15:22 . 2009-10-01 01:01    100864    ----a-w-    c:\windows\system32\PortableDeviceClassExtension.dll
2010-02-09 15:22 . 2009-10-01 01:01    350208    ----a-w-    c:\windows\system32\WPDSp.dll
2010-02-09 15:21 . 2009-10-08 21:07    4096    ----a-w-    c:\windows\system32\oleaccrc.dll
2010-02-09 15:21 . 2009-10-08 21:08    234496    ----a-w-    c:\windows\system32\oleacc.dll
2010-02-09 15:21 . 2009-10-08 21:08    555520    ----a-w-    c:\windows\system32\UIAutomationCore.dll
2010-02-01 08:49 . 2010-02-01 08:52    680    ----a-w-    c:\users\Thomas\AppData\Local\d3d9caps.dat

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-02 14:35 . 2009-07-14 11:22    1418    ----a-w-    c:\windows\bthservsdp.dat
2010-03-02 13:28 . 2009-07-14 11:35    --------    d-----w-    c:\programdata\VeriFace
2010-03-02 12:56 . 2009-12-04 13:52    48670    ----a-w-    c:\programdata\nvModes.dat
2010-03-02 12:30 . 2010-01-01 23:40    --------    d-----w-    c:\programdata\BullGuard
2010-03-02 10:55 . 2009-12-18 22:36    --------    d-----w-    c:\program files\Java
2010-03-02 10:50 . 2009-12-15 15:42    615424    ----a-w-    c:\windows\system32\themeui.dll
2010-03-02 10:49 . 2009-12-18 22:34    --------    d-----w-    c:\programdata\Skype
2010-03-02 10:06 . 2009-07-07 04:47    94724    ----a-w-    c:\windows\system32\perfc006.dat
2010-03-02 10:06 . 2009-07-07 04:47    510052    ----a-w-    c:\windows\system32\perfh006.dat
2010-03-02 08:32 . 2009-12-18 22:39    --------    d-----w-    c:\users\Thomas\AppData\Roaming\LimeWire
2010-03-02 08:32 . 2009-12-18 22:36    --------    d-----w-    c:\users\Thomas\AppData\Roaming\skypePM
2010-03-01 07:06 . 2009-12-04 22:25    106440    ----a-w-    c:\users\Thomas\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-20 23:05 . 2009-12-22 18:03    --------    d-----w-    c:\program files\Warcraft III
2010-02-20 18:29 . 2009-12-22 18:08    77179    ----a-w-    c:\windows\War3Unin.dat
2010-02-20 14:29 . 2010-02-20 14:29    --------    d-----w-    c:\users\Thomas\AppData\Roaming\FreeAudioPack
2010-02-19 14:07 . 2010-01-16 22:11    --------    d-----w-    c:\users\Thomas\AppData\Roaming\dvdcss
2010-02-19 14:05 . 2010-01-09 19:30    --------    d-----w-    c:\users\Thomas\AppData\Roaming\vlc
2010-02-15 22:11 . 2006-11-02 11:18    --------    d-----w-    c:\program files\Windows Mail
2010-02-15 18:39 . 2009-07-07 06:09    --------    d-----w-    c:\programdata\Microsoft Help
2010-02-12 14:21 . 2009-12-05 10:42    --------    d-----w-    c:\program files\Common Files\Apple
2010-02-12 14:14 . 2009-12-05 10:45    --------    d-----w-    c:\program files\QuickTime
2010-02-12 13:32 . 2010-01-01 23:48    87376    ----a-w-    c:\windows\system32\BGLsp.dll
2010-02-12 13:32 . 2008-09-19 13:48    14160    ----a-w-    c:\windows\system32\client_cc.dll
2010-02-12 13:32 . 2008-09-18 09:17    29208    ----a-r-    c:\windows\system32\drivers\Afw.sys
2010-02-12 11:57 . 2010-02-12 11:57    0    ---ha-w-    c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-02-09 13:56 . 2010-01-01 23:40    --------    d-----w-    c:\users\Thomas\AppData\Roaming\BullGuard
2010-02-09 13:56 . 2009-12-18 21:48    --------    d-----w-    c:\program files\Common Files\Steam
2010-02-09 13:56 . 2009-12-05 10:46    --------    d-----w-    c:\program files\Bonjour
2010-02-09 13:56 . 2009-12-05 16:10    --------    d-----w-    c:\program files\Windows Live
2010-02-01 09:12 . 2009-12-05 10:45    --------    d-----w-    c:\programdata\Apple Computer
2010-01-30 01:21 . 2009-12-18 22:36    --------    d-----w-    c:\program files\LimeWire
2010-01-28 19:59 . 2009-07-14 11:40    --------    d-----w-    c:\programdata\NVIDIA
2010-01-28 18:34 . 2006-11-02 12:37    --------    d-----w-    c:\program files\Windows Sidebar
2010-01-28 18:34 . 2006-11-02 12:37    --------    d-----w-    c:\program files\Windows Journal
2010-01-28 18:34 . 2006-11-02 12:37    --------    d-----w-    c:\program files\Windows Collaboration
2010-01-28 18:34 . 2006-11-02 12:37    --------    d-----w-    c:\program files\Windows Calendar
2010-01-28 18:34 . 2006-11-02 12:37    --------    d-----w-    c:\program files\Windows Photo Gallery
2010-01-28 18:34 . 2006-11-02 12:37    --------    d-----w-    c:\program files\Windows Defender
2010-01-26 10:13 . 2008-01-21 02:23    240128    ----a-w-    c:\windows\system32\uxtheme.dll
2010-01-26 10:13 . 2010-01-26 10:13    --------    d-----w-    c:\program files\CodeGazer
2010-01-25 08:44 . 2009-07-07 06:12    --------    d-----w-    c:\program files\Microsoft Works
2010-01-22 08:44 . 2010-01-22 08:44    --------    d-----w-    c:\programdata\Office Genuine Advantage
2010-01-22 08:08 . 2009-07-07 06:32    --------    d-----w-    c:\program files\Common Files\Adobe
2010-01-14 14:58 . 2010-01-14 14:58    249856    ------w-    c:\windows\Setup1.exe
2010-01-14 14:58 . 2010-01-14 14:58    73216    ----a-w-    c:\windows\ST6UNST.EXE
2010-01-13 18:39 . 2010-01-13 18:35    --------    d-----w-    c:\users\Thomas\AppData\Roaming\GetRightToGo
2010-01-12 18:45 . 2010-01-12 18:42    21840    ----atw-    c:\windows\system32\SIntfNT.dll
2010-01-12 18:45 . 2010-01-12 18:42    17212    ----atw-    c:\windows\system32\SIntf32.dll
2010-01-12 18:30 . 2010-01-12 18:30    --------    d-----w-    c:\users\Thomas\AppData\Roaming\DAEMON Tools Lite
2010-01-12 18:24 . 2010-01-12 18:24    691696    ----a-w-    c:\windows\system32\drivers\sptd.sys
2010-01-12 13:06 . 2010-01-12 13:06    --------    d-----w-    c:\programdata\DAEMON Tools Lite
2010-01-11 19:05 . 2010-01-11 19:05    37920    ----a-w-    c:\windows\system32\drivers\tbhsd.sys
2010-01-09 19:29 . 2010-01-09 19:29    --------    d-----w-    c:\program files\VideoLAN
2010-01-04 13:24 . 2010-01-04 13:24    --------    d-----w-    c:\programdata\WindowsSearch
2010-01-02 06:38 . 2010-01-22 08:14    916480    ----a-w-    c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-22 08:14    71680    ----a-w-    c:\windows\system32\iesetup.dll
2010-01-02 06:32 . 2010-01-22 08:14    109056    ----a-w-    c:\windows\system32\iesysprep.dll
2010-01-02 04:57 . 2010-01-22 08:14    133632    ----a-w-    c:\windows\system32\ieUnatt.exe
2010-01-02 00:11 . 2009-12-16 21:43    --------    d-----w-    c:\users\Thomas\AppData\Roaming\Politiken
2010-01-01 23:48 . 2010-01-01 22:46    55504    ----a-w-    c:\windows\system32\drivers\BdFileSpy.sys
2010-01-01 23:37 . 2010-01-01 23:37    --------    d-----w-    c:\program files\BullGuard Ltd
2010-01-01 23:36 . 2010-01-01 23:36    --------    d-----w-    c:\program files\Common Files\SWF Studio
2010-01-01 23:15 . 2010-01-01 23:15    48    ---ha-w-    c:\windows\system32\ezsidmv.dat
2010-01-01 22:46 . 2009-07-07 06:26    --------    d-----w-    c:\programdata\Norton
2009-12-22 18:16 . 2009-12-22 18:08    2829    ----a-w-    c:\windows\War3Unin.pif
2009-12-22 18:16 . 2009-12-22 18:08    139264    ----a-w-    c:\windows\War3Unin.exe
2009-12-11 11:43 . 2010-02-12 12:08    302080    ----a-w-    c:\windows\system32\drivers\srv.sys
2009-12-11 11:43 . 2010-02-12 12:08    98816    ----a-w-    c:\windows\system32\drivers\srvnet.sys
2009-12-08 20:01 . 2010-02-12 12:08    904776    ----a-w-    c:\windows\system32\drivers\tcpip.sys
2009-12-08 17:26 . 2010-02-12 12:08    30720    ----a-w-    c:\windows\system32\drivers\tcpipreg.sys
2009-12-04 18:30 . 2010-02-12 12:08    12288    ----a-w-    c:\windows\system32\tsbyuv.dll
2009-12-04 18:29 . 2010-02-12 12:08    1314816    ----a-w-    c:\windows\system32\quartz.dll
2009-12-04 18:28 . 2010-02-12 12:08    22528    ----a-w-    c:\windows\system32\msyuv.dll
2009-12-04 18:28 . 2010-02-12 12:08    31744    ----a-w-    c:\windows\system32\msvidc32.dll
2009-12-04 18:28 . 2010-02-12 12:08    123904    ----a-w-    c:\windows\system32\msvfw32.dll
2009-12-04 18:28 . 2010-02-12 12:08    13312    ----a-w-    c:\windows\system32\msrle32.dll
2009-12-04 18:28 . 2010-02-12 12:08    82944    ----a-w-    c:\windows\system32\mciavi32.dll
2009-12-04 18:28 . 2010-02-12 12:08    50176    ----a-w-    c:\windows\system32\iyuv_32.dll
2009-12-04 18:27 . 2010-02-12 12:08    91136    ----a-w-    c:\windows\system32\avifil32.dll
2009-12-04 15:56 . 2010-02-12 12:08    212992    ----a-w-    c:\windows\system32\drivers\mrxsmb10.sys
2009-12-04 15:56 . 2010-02-12 12:08    105984    ----a-w-    c:\windows\system32\drivers\mrxsmb.sys
2009-07-07 04:52 . 2009-07-07 04:52    8192    --sha-w-    c:\windows\Users\Default\NTUSER.DAT
.

------- Sigcheck -------

  • 2010-03-02 . 690D53BD10A804BB6D0A772D1C0E6907 . 247296 . . [6.0.6000.16386] . . c:\windows\System32\shsvcs.dll
.
(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc]
@="{771C7324-DA80-49D3-8017-753B0AF60951}"
[HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}]
2009-07-14 11:35    1404928    ----a-w-    c:\windows\System32\IcnOvrly.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"Google Update"="c:\users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-12-05 135664]
"BullGuard"="c:\program files\BullGuard Ltd\BullGuard\bullguard.exe" [2010-02-12 304464]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2008-03-26 163840]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-24 13605408]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-24 92704]
"VeriFaceManager"="c:\program files\Lenovo\VeriFace\PManage.exe" [2009-07-14 3116096]
"UpdateP2GShortCut"="c:\program files\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-12-04 218408]
"EnergyUtility"="c:\program files\Lenovo\Energy Management\utility.exe" [2009-04-23 4097864]
"Energy Management"="c:\program files\Lenovo\Energy Management\Energy Management.exe" [2009-05-04 5064520]
"BullGuard"="c:\program files\BullGuard Ltd\BullGuard\bullguard.exe" [2010-02-12 304464]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-22 141608]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-01-07 1394000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BgMainSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Users^Thomas^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 22:08    417792    ----a-w-    c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-02-20 14:53    1217872    ----a-w-    c:\program files\Valve\Steam\Steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):4f,08,61,98,49,a0,ca,01

R0 Wdkbdmou;Lenovo RMCT KbdMou Service;c:\windows\System32\drivers\Wdkbdmou.sys [03-03-2009 00:15 8832]
R1 afw;Agnitum Firewall Driver;c:\windows\System32\drivers\Afw.sys [18-09-2008 10:17 29208]
R1 funfrm;funfrm;c:\windows\System32\drivers\funfrm.sys [14-07-2009 12:35 48192]
R1 LenovoVCD;LenovoVCD;c:\windows\System32\drivers\LenovoVCD.sys [14-07-2009 12:47 16200]
R2 BdFileSpy;BullGuard File Monitor Driver;c:\windows\System32\drivers\BdFileSpy.sys [01-01-2010 23:46 55504]
R2 BsFileScan;BullGuard File Scan Service;c:\windows\System32\svchost.exe -k BullGuard [21-01-2008 03:23 21504]
R2 BsMailProxy;BullGuard Email Monitoring Service;c:\windows\System32\svchost.exe -k BullGuard [21-01-2008 03:23 21504]
R2 IGRS;IGRS;c:\program files\Lenovo\ReadyComm\common\IGRS.exe [14-02-2008 21:33 32768]
R2 ReadyComm.DirectRouter;ReadyComm.DirectRouter;c:\windows\System32\IgrsSvcs.exe -k IgrsSvcs --> c:\windows\System32\IgrsSvcs.exe -k IgrsSvcs [?]
R2 System_Repair_UpdateMonitor;System Repair Windows Update Monitor;c:\program files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe [07-07-2009 07:25 430080]
R2 tvtumon;tvtumon;c:\windows\System32\drivers\tvtumon.sys [07-07-2009 07:25 48192]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\System32\drivers\AcpiVpc.sys [14-07-2009 12:47 14848]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [23-10-2008 04:41 223232]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\System32\drivers\btwl2cap.sys [14-07-2009 12:44 29736]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\System32\drivers\NETw5v32.sys [14-07-2009 12:30 3668480]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [14-07-2009 12:27 55840]
R3 RRNetCapMP;RRNetCapMP;c:\windows\System32\drivers\rrnetcap.sys [16-02-2010 11:44 27752]
R3 SndTAudio;SndTAudio;c:\windows\System32\drivers\SndTAudio.sys [20-02-2010 18:04 23096]
R3 wdmirror;wdmirror;c:\windows\System32\drivers\WDMirror.sys [03-03-2009 00:14 8832]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [12-01-2010 19:24 691696]
S2 BsFire;BullGuard Firewall Service;c:\windows\System32\svchost.exe -k BullGuard [21-01-2008 03:23 21504]
S3 BgRaSvc;BgRaSvc;c:\program files\BullGuard Ltd\BullGuard\support\bgrasvc.exe [29-07-2008 08:40 83280]
S3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc;c:\program files\Lenovo\ReadyComm\AppSvc.exe [14-07-2009 12:33 379968]
S3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc;c:\program files\Lenovo\ReadyComm\ConnSvc.exe [14-07-2009 12:33 412736]
S3 PS_MDP;ReadyComm Presentation Space Helper Service;c:\windows\System32\IgrsSvcs.exe -k IgrsSvcs --> c:\windows\System32\IgrsSvcs.exe -k IgrsSvcs [?]
S3 RRNetCap;RRNetCap Service;c:\windows\System32\drivers\rrnetcap.sys [16-02-2010 11:44 27752]
S3 SMServer;SMServer;c:\windows\System32\snmvtsvc.exe [20-02-2010 18:04 245760]
S3 STSService;STSService;"c:\program files\SoundTaxi Media Suite\STSService.exe" --> c:\program files\SoundTaxi Media Suite\STSService.exe [?]
S3 USBAAPL;Apple Mobile USB Driver;c:\windows\System32\drivers\usbaapl.sys [28-08-2009 19:42 40448]
S3 WSVD;WSVD;c:\windows\System32\drivers\WSVD.sys [07-07-2009 07:24 81192]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs    REG_MULTI_SZ      BthServ
IgrsSvcs    REG_MULTI_SZ      ReadyComm.DirectRouter PS_MDP
BullGuard    REG_MULTI_SZ      BgMainSvc BsFileScan BsMailProxy BsFire
LocalServiceAndNoImpersonation    REG_MULTI_SZ      FontCache

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9C450606-ED24-4958-92BA-B8940C99D441}]
2009-03-04 15:32    8192    ----a-w-    c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Indhold af mappen 'Planlagte Opgaver'

2010-03-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-186105711-3158523747-2434017840-1005Core.job
- c:\users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-05 16:02]

2010-03-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-186105711-3158523747-2434017840-1005UA.job
- c:\users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-05 16:02]

2010-03-02 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2010-02-23 23:20]

2010-03-02 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2010-02-23 23:20]
.
.
------- Yderligere scanning -------
.
uStart Page = hxxp://www.nixat.com/
mStart Page = hxxp://www.nixat.com/
uInternet Settings,ProxyOverride = *.local
IE: Download all by YouTube Robot - c:\program files\YouTubeRobot\downall.htm
IE: Download by YouTube Robot - c:\program files\YouTubeRobot\downlink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send billede til &Bluetooth-enhed... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send siden til &Bluetooth-enhed... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie.htm
LSP: c:\windows\system32\bglsp.dll
.
- - - - TOMME GENVEJE FJERNET - - - -

MSConfigStartUp-Skype - c:\program files\Skype\Phone\Skype.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-02 16:19
Windows 6.0.6002 Service Pack 2 NTFS

scanner skjulte processer ... 

scanner skjulte autostarter ...

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer: 0

**************************************************************************
.
Gennemført tid: 2010-03-02  16:31:26
ComboFix-quarantined-files.txt  2010-03-02 15:31

Pre-Kørsel: 166.390.378.496 byte ledig
Post-Kørsel: 166.684.585.984 byte ledig

- - End Of File - - 4A50F54F61AC9AFB255C23B8F8E9653A
02. marts 2010 - 19:05 #6
c:\program files\LimeWire -> *SUK*
Avatar billede johnstigers Seniormester
02. marts 2010 - 19:19 #7
f-arn + patrick14>
Kan i egentlig selv finde ud af at få fixet div. ting nu når i er 2?
Er der ikke en chance for at de ting i sidder og foreslår kan modarbejde hinanden?
Avatar billede f-arn Guru
02. marts 2010 - 20:05 #8
@ThomasBojsen93
Har du en Windøws DVD?

Find og upload nedenstående hos Jotti eller Virustotal:

c:\windows\System32\shsvcs.dll

http://virusscan.jotti.org/ - http://www.virustotal.com/en/indexf.html

Kopier resultatet herind
Avatar billede ThomasBojsen93 Nybegynder
03. marts 2010 - 19:21 #9
Mit problem er vist afklaret nu. Combofix klarede ærterne. Mange tak for hjælpen folkens.
Avatar billede f-arn Guru
03. marts 2010 - 21:21 #10
1. Læs venligst dette: http://www.eksperten.dk/faq#faq-3

2. Jeg tvivler meget stærkt på at den PC er "ren" men det mener du jo åbenbart!
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester