Avatar billede dj-bmw Nybegynder
19. juli 2010 - 15:25 Der er 38 kommentarer

Hijack this logfile

Hej,

Har muligvis fået en trojan/virus.
Norton Internet Security 2010 sagde den havde taget dem, men computeren kører meget langsomt, og den går selv ind på diverse hjemmesider engang i mellem.

Håber nogen kan hjælpe med logfilen her:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:25:18, on 19-07-2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Atheros\ACU.exe
C:\Programmer\SPAMfighter\SFAgent.exe
C:\WINDOWS\cndrive32.exe
C:\Programmer\Fælles filer\Autodata Limited Shared\Service\ADCDLicSvc.exe
C:\WINDOWS\system32\crypserv.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\Programmer\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe
C:\Programmer\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe
C:\Programmer\SPAMfighter\sfus.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\TomTom HOME 2\TomTomHOMEService.exe
C:\WINDOWS\system32\msiexec.exe
C:\Programmer\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Outlook Express\msimn.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\Programmer\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Administrator\Skrivebord\deer hunter 2005 maps\iexplore.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Programmer\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Programmer\Norton Internet Security\Engine\17.0.0.136\IPSBHO.DLL
O2 - BHO: Street-Ads Browser Enhancer qlbgp - {8FFC4DB3-CC1A-4F54-AFF8-38AAA652CCFF} - C:\WINDOWS\system32\qlbgp.dll
O2 - BHO: Sky-Banners Browser Enhancer ulbgp - {9B3D231A-F4F7-4B94-83D1-73157596F3CF} - C:\WINDOWS\system32\ulbgp.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmer\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\DAP\DAPIEL~1.DLL
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programmer\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll
O4 - HKLM\..\Run: [StartCCC] C:\Programmer\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [ACU] C:\Programmer\Atheros\ACU.exe -nogui
O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Programmer\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKLM\..\Run: [sta] rundll32 "ulbgp.dll",,Run
O4 - HKLM\..\Run: [MChk] C:\WINDOWS\system32\hlbgp.exe
O4 - HKLM\..\Run: [utneipym] C:\Documents and Settings\Administrator\Lokale indstillinger\Application Data\rikwkmcpo\ipvuvbmtssd.exe
O4 - HKCU\..\Run: [12CFG214-K641-12SF-N85P] C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe
O4 - HKCU\..\Run: [utneipym] C:\Documents and Settings\Administrator\Lokale indstillinger\Application Data\rikwkmcpo\ipvuvbmtssd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKLM\..\Policies\Explorer\Run: [Microsoft Driver Setup] C:\WINDOWS\cndrive32.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = ?
O4 - Startup: PowerReg Scheduler V3.exe
O8 - Extra context menu item: &Clean Traces - C:\Programmer\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Programmer\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Programmer\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Programmer\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} (ActiveX sikkerhedssoftware Control) - https://www.portalbank.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.30.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2A402FDB-2814-4B8E-BEB1-104BEF3FB5DA}: NameServer = 208.67.222.222,208.67.220.220
O23 - Service: Atheros konfigureringsservice (ACS) - Atheros - C:\WINDOWS\system32\acs.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmer\Fælles filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodata Limited License Service - Autodata Limited - C:\Programmer\Fælles filer\Autodata Limited Shared\Service\ADCDLicSvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programmer\Fælles filer\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programmer\Fælles filer\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmer\Java\jre6\bin\jqs.exe
O23 - Service: mental ray 3.7 Satellite for Autodesk 3ds Max 2010 32-bit 32-bit (mi-raysat_3dsmax2010_32) - Unknown owner - C:\Programmer\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Programmer\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - Unknown owner - C:\Programmer\SiSoftware\SiSoftware Sandra Lite XI\Win32\RpcDataSrv.exe (file missing)
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - Unknown owner - C:\Programmer\SiSoftware\SiSoftware Sandra Lite XI\RpcSandraSrv.exe (file missing)
O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Programmer\SPAMfighter\sfus.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Programmer\TomTom HOME 2\TomTomHOMEService.exe

--
End of file - 7817 bytes
Avatar billede f-arn Guru
19. juli 2010 - 16:17 #1
Hent "Malwarebytes' Anti-Malware" her: http://www.besttechie.net/tools/mbam-setup.exe

Eller her ->
http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?tag=mncol;pop&cdlPid=10878968

Installer og start programmet, klik på fanen opdater, klik Tjek for opdatering, lav "Hurtig skan" under fanebladet "skanner"
Bagefter klik på "vis resultater", tryk på "Fjern det valgte" og send loggen herind sammen med en log fra DDS som du finder her: http://download.bleepingcomputer.com/sUBs/dds.scr

eller her: http://www.forospyware.com/sUBs/dds

Den laver to logs,(DDS.txt og Attach.txt) gem dem på skrivebordet og kopier indholdet af DDS.txt  herind.

OBS - DDS skal gemmes på computeren og ikke køres fra nettet

NB Når du opdaterer Malwarebytes, så klik på Tjek for opdatering til den skriver at der ikke er flere opdateringer.
Avatar billede f-arn Guru
19. juli 2010 - 16:23 #2
Hvorfor er der ikke SP 3 på maskinen
Hvorfor kører du med Internet Explorer v6.00
Hvor har du fundet Norton Internet Security 17.0.0.136
Seneste er 17.7.0.12
Avatar billede dj-bmw Nybegynder
19. juli 2010 - 17:20 #3
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4326

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

19-07-2010 17:13:54
mbam-log-2010-07-19 (17-13-54).txt

Skanningstype: Hurtig skanning
Objekter skannet: 131004
Tid gået: 9 minut(ter), 40 sekund(er)

Hukommelses Processorer Inficeret: 1
Hukommelses Moduler Inficeret: 0
Registreringsdatabasenøgler Inficeret: 7
Registreringsdatabaseværdier Inficeret: 3
Registreringsdatabasedata Objekter Inficeret: 0
Inficerede Mapper: 8
Inficerede Filer: 21

Hukommelses Processorer Inficeret:
C:\WINDOWS\cndrive32.exe (Backdoor.IRCBot) -> Unloaded process successfully.

Hukommelses Moduler Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabasenøgler Inficeret:
HKEY_CLASSES_ROOT\AppID\{84c3c236-f588-4c93-84f4-147b2abbe67b} (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{38061edc-40bb-4618-a8da-e56353347e6d} (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{7b6a2552-e65b-4a9e-add4-c45577ffd8fd} (Adware.EZLife) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Sky-Banners (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.TryMedia) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Sky-Banners (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\AVSolution (Trojan.Agent) -> Quarantined and deleted successfully.

Registreringsdatabaseværdier Inficeret:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\12cfg214-k641-12sf-n85p (Worm.Rimecud) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\microsoft driver setup (Backdoor.IRCBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> Quarantined and deleted successfully.

Registreringsdatabasedata Objekter Inficeret:
(Ingen skadelige objekter blev fundet)

Inficerede Mapper:
C:\Documents and Settings\Administrator\Application Data\Sky-Banners (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Application Data\Sky-Banners\skb (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Application Data\Street-Ads (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Programmer\RelevantKnowledge (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\Programmer\RelevantKnowledge\components (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Menuen Start\Programmer\RelevantKnowledge (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811 (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\$NtUninstallMTF1011$ (Adware.Adrotator) -> Quarantined and deleted successfully.

Inficerede Filer:
C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe (Worm.Rimecud) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Skrivebord\RapalaProFishing-dm.exe (Adware.TryMedia) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-0167746187-6368685648-194858223-9857\mgrls32.exe (Worm.Autorun.B) -> Delete on reboot.
C:\Documents and Settings\Administrator\Lokale indstillinger\Temp\joujbvje.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Lokale indstillinger\Temp\odyot.exe (Adware.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Lokale indstillinger\Temp\153.exe (Worm.Rimecud) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Lokale indstillinger\Temp\279.exe (Worm.Rimecud) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Lokale indstillinger\Temp\318.exe (Worm.Rimecud) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Lokale indstillinger\Temp\372.exe (Worm.Rimecud) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Lokale indstillinger\Temp\texn.exe (Adware.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Lokale indstillinger\Temp\593.exe (Worm.Rimecud) -> Quarantined and deleted successfully.
C:\Programmer\RelevantKnowledge\chrome.manifest (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\Programmer\RelevantKnowledge\install.rdf (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\Programmer\RelevantKnowledge\rloci.bin (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Menuen Start\Programmer\RelevantKnowledge\About RelevantKnowledge.lnk (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Menuen Start\Programmer\RelevantKnowledge\Privacy Policy and User License Agreement.lnk (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Menuen Start\Programmer\RelevantKnowledge\Support.lnk (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\Desktop.ini (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\Drivers\ntndis.sys (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\ipsecndis.sys (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\cndrive32.exe (Backdoor.IRCBot) -> Quarantined and deleted successfully.


DDS åbner bare notepad og laver en masse sjove tegn?

Vidste ikke der var en service pack 3, derfor har jeg hellere ikke installeret den :(
Jeg bruger ikke internet explorer, men firefox, derfor er explorer ikke opdateret
Norton'en har jeg fået af min bror, så kender ikke så meget til det.
Avatar billede f-arn Guru
19. juli 2010 - 17:42 #4
DDS åbner bare notepad og laver en masse sjove tegn

Hent en ny. Virker fint her.

Har du slået Windows Update fra, siden du ikke har opdateret IE og Windows.

Du skal ikke opdatere nu. Det må vente til PCen er renset.
Avatar billede dj-bmw Nybegynder
19. juli 2010 - 18:42 #5
Nu fik jeg det endelig til at virke:

DDS (Ver_10-03-17.01) - NTFSx86 
Run by Administrator at 18:29:47,75 on 19-07-2010
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional  5.1.2600.2.1252.45.1030.18.3071.2483 [GMT 2:00]

AV: Norton Internet Security *On-access scanning enabled* (Updated)  {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled*  {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\acs.exe
svchost.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Programmer\Fælles filer\Autodata Limited Shared\Service\ADCDLicSvc.exe
svchost.exe
C:\WINDOWS\system32\crypserv.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\Programmer\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe
C:\Programmer\SPAMfighter\sfus.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Programmer\TomTom HOME 2\TomTomHOMEService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Atheros\ACU.exe
C:\Programmer\SPAMfighter\SFAgent.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\DAP\DAP.EXE
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Programmer\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Documents and Settings\Administrator\Skrivebord\dds.pif

============== Pseudo HJT Report ===============

uStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage
mWinlogon: Userinit=c:\windows\system32\userinit.exe
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\programmer\fælles filer\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\programmer\norton internet security\engine\17.0.0.136\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\programmer\norton internet security\engine\17.0.0.136\IPSBHO.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\programmer\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\programmer\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: DAPIELoader Class: {ff6c3cf0-4b15-11d1-abed-709549c10000} - c:\progra~1\dap\DAPIEL~1.DLL
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\programmer\norton internet security\engine\17.0.0.136\coIEPlg.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [MSMSGS] "c:\programmer\messenger\msmsgs.exe" /background
uRun: [DownloadAccelerator] "c:\programmer\dap\DAP.EXE" /STARTUP
mRun: [StartCCC] c:\programmer\ati technologies\ati.ace\core-static\CLIStart.exe
mRun: [ACU] c:\programmer\atheros\ACU.exe -nogui
mRun: [SPAMfighter Agent] "c:\programmer\spamfighter\SFAgent.exe" update delay 60
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\admini~1\menuen~1\progra~1\start\adobeg~1.lnk - c:\programmer\fælles filer\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\documents and settings\administrator\menuen start\programmer\start\PowerReg Scheduler V3.exe
IE: &Clean Traces - c:\programmer\dap\privacy package\dapcleanerie.htm
IE: &Download with &DAP - c:\programmer\dap\dapextie.htm
IE: Download &all with DAP - c:\programmer\dap\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\programmer\pokerstars\PokerStarsUpdate.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\programmer\messenger\msmsgs.exe
Trusted Zone: danid.dk
DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} - hxxps://www.portalbank.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.30.cab
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
TCP: {2A402FDB-2814-4B8E-BEB1-104BEF3FB5DA} = 208.67.222.222,208.67.220.220
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} -
Notify: AtiExtEvent - Ati2evxx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\cz60s7nv.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://eu.ask.com?o=15458&l=dis
FF - prefs.js: keyword.URL - hxxp://dk.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_dk&p=
FF - prefs.js: network.proxy.type - 4
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

---- FIREFOX POLICIES ----
c:\programmer\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programmer\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\programmer\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\programmer\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\programmer\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\programmer\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency",  1600);
c:\programmer\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\programmer\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\programmer\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\programmer\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\programmer\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\programmer\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\programmer\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\programmer\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programmer\mozilla firefox\greprefs\all.js - pref("network.proxy.type",                  5);
c:\programmer\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\programmer\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programmer\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\programmer\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug",            false);
c:\programmer\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight",      2);
c:\programmer\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize",      1);
c:\programmer\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\programmer\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\programmer\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight",  25);
c:\programmer\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight",    5);
c:\programmer\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\programmer\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\programmer\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\programmer\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programmer\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programmer\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
c:\programmer\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\programmer\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\programmer\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\programmer\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\programmer\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nis\1100000.088\SymDS.sys [2010-7-19 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nis\1100000.088\SymEFA.sys [2010-7-19 169008]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.0.0.136\definitions\bashdefs\20100709.001\BHDrvx86.sys [2010-7-19 691248]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nis\1100000.088\ccHPx86.sys [2010-7-19 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nis\1100000.088\Ironx86.sys [2010-7-19 114736]
R2 mi-raysat_3dsmax2010_32;mental ray 3.7 Satellite for Autodesk 3ds Max 2010 32-bit 32-bit;c:\programmer\autodesk\3ds max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe [2009-3-12 86016]
R2 NIS;Norton Internet Security;c:\programmer\norton internet security\engine\17.0.0.136\ccSvcHst.exe [2010-7-19 126392]
R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\programmer\spamfighter\sfus.exe [2009-3-12 184968]
R2 TomTomHOMEService;TomTomHOMEService;c:\programmer\tomtom home 2\TomTomHOMEService.exe [2009-11-13 92008]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\programmer\fælles filer\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-7-19 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.0.0.136\definitions\ipsdefs\20100716.001\IDSXpx86.sys [2010-7-19 331640]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.0.0.136\definitions\virusdefs\20100718.003\NAVENG.SYS [2010-7-19 85424]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.0.0.136\definitions\virusdefs\20100718.003\NAVEX15.SYS [2010-7-19 1362608]
S0 uavnc;uavnc; [x]
S3 RenameMe;RenameMe;c:\windows\system32\RenameMe.sys [2010-5-1 8320]

============== File Associations ===============

.scr=AutoCADScriptFile

=============== Created Last 30 ================

2010-07-19 14:59:08    0    d-----w-    c:\docume~1\admini~1\applic~1\Malwarebytes
2010-07-19 14:58:17    38224    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-19 14:58:16    0    d-----w-    c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-07-19 14:58:15    20952    ----a-w-    c:\windows\system32\drivers\mbam.sys
2010-07-19 14:58:09    0    d-----w-    c:\programmer\Malwarebytes' Anti-Malware
2010-07-19 14:15:25    0    d-----w-    c:\programmer\ReviverSoft
2010-07-19 14:14:55    0    d-----w-    c:\docume~1\alluse~1\applic~1\ReviverSoft
2010-07-19 11:07:37    805    ----a-w-    c:\windows\system32\drivers\SYMEVENT.INF
2010-07-19 11:07:37    7443    ----a-w-    c:\windows\system32\drivers\SYMEVENT.CAT
2010-07-19 11:07:37    60808    ----a-w-    c:\windows\system32\S32EVNT1.DLL
2010-07-19 11:07:37    124976    ----a-w-    c:\windows\system32\drivers\SYMEVENT.SYS
2010-07-19 11:07:36    0    d-----w-    c:\programmer\Symantec
2010-07-19 11:07:36    0    d-----w-    c:\programmer\fælles filer\Symantec Shared
2010-07-19 11:06:52    0    d-----w-    c:\windows\system32\drivers\NIS
2010-07-19 11:06:47    0    d-----w-    c:\programmer\Norton Internet Security
2010-07-19 11:06:33    0    d-----w-    c:\docume~1\alluse~1\applic~1\Norton
2010-07-19 11:06:05    0    d-----w-    c:\programmer\NortonInstaller
2010-07-19 11:06:05    0    d-----w-    c:\docume~1\alluse~1\applic~1\NortonInstaller
2010-07-18 21:44:04    0    d-----w-    c:\programmer\Enigma Software Group
2010-07-18 21:43:43    0    d-----w-    c:\windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP
2010-07-18 19:48:50    150    ----a-w-    C:\zrpt.xml
2010-06-25 21:43:09    107888    ----a-w-    c:\windows\system32\CmdLineExt.dll
2010-06-25 21:39:44    0    d-----w-    c:\programmer\Deer Hunter Tournament
2010-06-25 20:52:05    0    d-----w-    c:\programmer\Atari

==================== Find3M  ====================

2010-07-19 13:10:28    211072    ----a-w-    c:\windows\system32\drivers\ndis.sys
2010-06-29 21:31:03    0    ----a-w-    c:\documents and settings\administrator\temp.dat
2010-06-23 17:10:26    83058    ----a-w-    c:\windows\system32\perfc006.dat
2010-06-23 17:10:26    456936    ----a-w-    c:\windows\system32\perfh006.dat
2010-05-02 08:26:15    1850880    ----a-w-    c:\windows\system32\win32k.sys

============= FINISH: 18:38:00,37 ===============


Nyeste log fra malware:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4326

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

19-07-2010 17:13:35
mbam-log-2010-07-19 (17-13-35).txt

Skanningstype: Hurtig skanning
Objekter skannet: 131004
Tid gået: 9 minut(ter), 40 sekund(er)

Hukommelses Processorer Inficeret: 1
Hukommelses Moduler Inficeret: 0
Registreringsdatabasenøgler Inficeret: 7
Registreringsdatabaseværdier Inficeret: 3
Registreringsdatabasedata Objekter Inficeret: 0
Inficerede Mapper: 8
Inficerede Filer: 21

Hukommelses Processorer Inficeret:
C:\WINDOWS\cndrive32.exe (Backdoor.IRCBot) -> No action taken.

Hukommelses Moduler Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabasenøgler Inficeret:
HKEY_CLASSES_ROOT\AppID\{84c3c236-f588-4c93-84f4-147b2abbe67b} (Adware.Adrotator) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{38061edc-40bb-4618-a8da-e56353347e6d} (Adware.EZlife) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{7b6a2552-e65b-4a9e-add4-c45577ffd8fd} (Adware.EZLife) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Sky-Banners (Adware.Adrotator) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.TryMedia) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Sky-Banners (Adware.Adrotator) -> No action taken.
HKEY_CURRENT_USER\Software\AVSolution (Trojan.Agent) -> No action taken.

Registreringsdatabaseværdier Inficeret:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\12cfg214-k641-12sf-n85p (Worm.Rimecud) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\microsoft driver setup (Backdoor.IRCBot) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> No action taken.

Registreringsdatabasedata Objekter Inficeret:
(Ingen skadelige objekter blev fundet)

Inficerede Mapper:
C:\Documents and Settings\Administrator\Application Data\Sky-Banners (Adware.Adrotator) -> No action taken.
C:\Documents and Settings\Administrator\Application Data\Sky-Banners\skb (Adware.Adrotator) -> No action taken.
C:\Documents and Settings\Administrator\Application Data\Street-Ads (Adware.Adrotator) -> No action taken.
C:\Programmer\RelevantKnowledge (Spyware.MarketScore) -> No action taken.
C:\Programmer\RelevantKnowledge\components (Spyware.MarketScore) -> No action taken.
C:\Documents and Settings\All Users\Menuen Start\Programmer\RelevantKnowledge (Spyware.MarketScore) -> No action taken.
C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811 (Trojan.Agent) -> No action taken.
C:\WINDOWS\$NtUninstallMTF1011$ (Adware.Adrotator) -> No action taken.

Inficerede Filer:
C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe (Worm.Rimecud) -> No action taken.
C:\Documents and Settings\Administrator\Skrivebord\RapalaProFishing-dm.exe (Adware.TryMedia) -> No action taken.
C:\RECYCLER\S-1-5-21-0167746187-6368685648-194858223-9857\mgrls32.exe (Worm.Autorun.B) -> No action taken.
C:\Documents and Settings\Administrator\Lokale indstillinger\Temp\joujbvje.exe (Trojan.Dropper) -> No action taken.
C:\Documents and Settings\Administrator\Lokale indstillinger\Temp\odyot.exe (Adware.BHO) -> No action taken.
C:\Documents and Settings\Administrator\Lokale indstillinger\Temp\153.exe (Worm.Rimecud) -> No action taken.
C:\Documents and Settings\Administrator\Lokale indstillinger\Temp\279.exe (Worm.Rimecud) -> No action taken.
C:\Documents and Settings\Administrator\Lokale indstillinger\Temp\318.exe (Worm.Rimecud) -> No action taken.
C:\Documents and Settings\Administrator\Lokale indstillinger\Temp\372.exe (Worm.Rimecud) -> No action taken.
C:\Documents and Settings\Administrator\Lokale indstillinger\Temp\texn.exe (Adware.BHO) -> No action taken.
C:\Documents and Settings\Administrator\Lokale indstillinger\Temp\593.exe (Worm.Rimecud) -> No action taken.
C:\Programmer\RelevantKnowledge\chrome.manifest (Spyware.MarketScore) -> No action taken.
C:\Programmer\RelevantKnowledge\install.rdf (Spyware.MarketScore) -> No action taken.
C:\Programmer\RelevantKnowledge\rloci.bin (Spyware.MarketScore) -> No action taken.
C:\Documents and Settings\All Users\Menuen Start\Programmer\RelevantKnowledge\About RelevantKnowledge.lnk (Spyware.MarketScore) -> No action taken.
C:\Documents and Settings\All Users\Menuen Start\Programmer\RelevantKnowledge\Privacy Policy and User License Agreement.lnk (Spyware.MarketScore) -> No action taken.
C:\Documents and Settings\All Users\Menuen Start\Programmer\RelevantKnowledge\Support.lnk (Spyware.MarketScore) -> No action taken.
C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\Desktop.ini (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\Drivers\ntndis.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\ipsecndis.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\cndrive32.exe (Backdoor.IRCBot) -> No action taken.
Avatar billede dj-bmw Nybegynder
19. juli 2010 - 18:59 #6
se bort fra den sidste log fra malware...
Avatar billede johnstigers Seniormester
20. juli 2010 - 00:31 #7
Vidste ikke der var en service pack 3, derfor har jeg hellere ikke installeret den :(


Bare slå automatisk opdatering til.
Avatar billede f-arn Guru
20. juli 2010 - 01:55 #8
Find og upload nedenstående hos Jotti eller Virustotal:

c:\windows\system32\RenameMe.sys

http://virusscan.jotti.org/ - http://www.virustotal.com/en/indexf.html

Kopier resultatet herind
Avatar billede dj-bmw Nybegynder
20. juli 2010 - 09:23 #9
Virustotal scan:
Antivirus     Version     Last Update     Result
a-squared     4.5.0.43     2009.12.24     -
AhnLab-V3     5.0.0.2     2009.12.24     -
AntiVir     7.9.1.122     2009.12.24     -
Antiy-AVL     2.0.3.7     2009.12.24     -
Authentium     5.2.0.5     2009.12.23     W32/SYStroj.N.gen!Eldorado
Avast     4.8.1351.0     2009.12.24     -
AVG     8.5.0.430     2009.12.24     -
BitDefender     7.2     2009.12.24     -
CAT-QuickHeal     10.00     2009.12.24     -
ClamAV     0.94.1     2009.12.24     -
Comodo     3352     2009.12.24     -
DrWeb     5.0.1.12222     2009.12.24     -
eSafe     7.0.17.0     2009.12.23     -
eTrust-Vet     35.1.7195     2009.12.24     -
F-Prot     4.5.1.85     2009.12.23     W32/SYStroj.N.gen!Eldorado
F-Secure     9.0.15370.0     2009.12.24     -
Fortinet     4.0.14.0     2009.12.24     -
GData     19     2009.12.24     -
Ikarus     T3.1.1.79.0     2009.12.24     -
Jiangmin     13.0.900     2009.12.23     -
K7AntiVirus     7.10.926     2009.12.22     -
Kaspersky     7.0.0.125     2009.12.24     -
McAfee     5841     2009.12.23     -
McAfee+Artemis     5841     2009.12.23     -
McAfee-GW-Edition     6.8.5     2009.12.24     Heuristic.BehavesLike.Win32.Rootkit.L
Microsoft     1.5302     2009.12.24     -
NOD32     4714     2009.12.24     -
Norman     6.04.03     2009.12.24     -
nProtect     2009.1.8.0     2009.12.24     -
Panda     10.0.2.2     2009.12.15     -
PCTools     7.0.3.5     2009.12.24     -
Prevx     3.0     2009.12.24     -
Rising     22.27.03.04     2009.12.24     -
Sophos     4.49.0     2009.12.24     -
Sunbelt     3.2.1858.2     2009.12.23     -
Symantec     1.4.4.12     2009.12.24     -
TheHacker     6.5.0.3.109     2009.12.23     -
TrendMicro     9.120.0.1004     2009.12.24     -
VBA32     3.12.12.0     2009.12.24     -
ViRobot     2009.12.24.2107     2009.12.24     -
VirusBuster     5.0.21.0     2009.12.23     -
Additional information
File size: 8320 bytes
MD5  : 6cac435da6c6450ba120216af21ba07d
SHA1  : 5b855331538740f26bf3618f01f470ea5a724565
SHA256: 6b7caf555bf4ea7398548e0404b4046f621cf379c9296dd6b6a5414e7fdfe006
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0xE52
timedatestamp.....: 0x44DE0E22 (Sat Aug 12 19:21:38 2006)
machinetype.......: 0x14C (Intel I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x300 0xC68 0xC80 6.14 1b005c5d117b14837c3485c3d23e08ac
.rdata 0xF80 0xE9 0x100 4.37 c08af07cdf8f229fa590d3fcb5c2bc9d
.data 0x1080 0xB74 0xB80 0.00 47f96153e0352d49b3dba2814524bd43
INIT 0x1C00 0x252 0x280 4.84 5fd237c685b11556aeb2dbea856272d0
.reloc 0x1E80 0x1A2 0x200 4.86 b3b31d490ba03d734b8a5939cc1f163f

( 1 imports )

> ntoskrnl.exe: KeServiceDescriptorTable, MmIsAddressValid, KeAddSystemServiceTable, strncmp, IoGetCurrentProcess, strncpy, IofCompleteRequest, IoDeleteDevice, IoDeleteSymbolicLink, RtlInitUnicodeString, KeSetEvent, KeWaitForSingleObject, strrchr, strstr, ObfDereferenceObject, RtlFreeAnsiString, RtlUnicodeStringToAnsiString, ObReferenceObjectByHandle, KeInitializeEvent, IoCreateSymbolicLink, IoCreateDevice, _except_handler3

( 0 exports )
TrID  : File type identification
Generic Win/DOS Executable (49.9%)
DOS Executable Generic (49.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
ssdeep: 96:4dQtMmMmbx9i7dDxq46odp/XWpehTy2D82ccjLhjtMjtzrPM1gNv:40/Di71EtYp/WehTy2w5OjtMjFrlN
PEiD  : -
CWSandbox: http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=6cac435da6c6450ba120216af21ba07d
RDS  : NSRL Reference Data Set
-

Jotti scan:

Filename:     RenameMe.sys
Status:    
Scan finished. 1 out of 19 scanners reported malware.
Scan taken on:      Tue 20 Jul 2010 09:18:34 (CET) Permalink
           
Additional info
File size:     8320 bytes
Filetype:     PE32 executable for MS Windows (native) Intel 80386 32-bit
MD5:     6cac435da6c6450ba120216af21ba07d
SHA1:     5b855331538740f26bf3618f01f470ea5a724565




Scanners
[ArcaVir]    
2010-07-20 Found nothing
    [G DATA]    
2010-07-20 Found nothing
[Avast! antivirus]    
2010-07-19 Found nothing
    [Ikarus]    
2010-07-20 Found nothing
[Grisoft AVG Anti-Virus]    
2010-07-19 Found nothing
    [Kaspersky Anti-Virus]    
2010-07-19 Found nothing
[Avira AntiVir]    
2010-07-19 Found nothing
    [ESET NOD32]    
2010-07-19 Found nothing
[Softwin BitDefender]    
2010-07-20 Found nothing
    [Panda Antivirus]    
2010-07-19 Found nothing
[ClamAV]    
2010-07-20 Found nothing
    [Quick Heal]    
2010-07-20 Found nothing
[CPsecure]    
2010-07-20 Found nothing
    [Sophos]    
2010-07-20 Found nothing
[Dr.Web]    
2010-07-20 Found nothing
    [VirusBlokAda VBA32]    
2010-07-19 Found nothing
[Frisk F-Prot Antivirus]    
2010-07-19 W32/SYStroj.N.gen!Eldorado
    [VirusBuster]    
2010-07-19 Found nothing
[F-Secure Anti-Virus]    
2010-07-20 Found nothing
Avatar billede f-arn Guru
20. juli 2010 - 13:16 #10
Hent og gem Combofix på dit skrivebord:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Højreklik på skrivebordet og vælg ny->tekstdokument og kopier det fremhævede ind og gem filen som CFScript

Killall::
Snapshot::


Da Combofix kan konflikte med dine sikkerhedsprogrammer er det vigtigt at du deaktiverer dem.

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen.
http://www.fromsej.saknet.dk/billeder/cfscript.gif

Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når Combofix er færdig, og efter det (muligvis) har genstartet, skulle der gerne åbnes en logfil: combofix.txt som ligger her C:\Combofix.txt

Indholdet af denne fil må du gerne lægge herind.
Avatar billede dj-bmw Nybegynder
20. juli 2010 - 13:56 #11
Logfil fra Combofix:

ComboFix 10-07-19.02 - Administrator 20-07-2010  13:35:04.1.2 - x86
Microsoft Windows XP Professional  5.1.2600.2.1252.45.1030.18.3071.2663 [GMT 2:00]
Kører fra: c:\documents and settings\Administrator\Skrivebord\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\Administrator\Skrivebord\CFScript.txt
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator\Dokumenter\cc_20100719_162634.reg
c:\windows\Downloaded Program Files\IDropPTB.dll

.
(((((((((((((((((((((((((((((  Filer skabt fra 2010-06-20 til 2010-07-20  )))))))))))))))))))))))))))))))))))
.

2010-07-19 17:37 . 2010-05-06 04:01    361904    ----a-w-    c:\windows\system32\drivers\symtdi.sys
2010-07-19 17:37 . 2010-04-22 03:02    173104    ----a-w-    c:\windows\system32\drivers\symefa.sys
2010-07-19 17:37 . 2010-04-22 02:29    43696    ----a-w-    c:\windows\system32\drivers\srtspx.sys
2010-07-19 17:37 . 2009-08-30 00:17    328752    ----a-r-    c:\windows\system32\drivers\symds.sys
2010-07-19 17:37 . 2010-04-29 05:03    116784    ----a-w-    c:\windows\system32\drivers\ironx86.sys
2010-07-19 17:37 . 2010-02-26 00:22    501888    ----a-w-    c:\windows\system32\drivers\cchpx86.sys
2010-07-19 14:59 . 2010-07-19 14:59    --------    d-----w-    c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-07-19 14:58 . 2010-04-29 13:39    38224    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-19 14:58 . 2010-07-19 14:58    --------    d-----w-    c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-19 14:58 . 2010-04-29 13:39    20952    ----a-w-    c:\windows\system32\drivers\mbam.sys
2010-07-19 14:58 . 2010-07-19 14:58    --------    d-----w-    c:\programmer\Malwarebytes' Anti-Malware
2010-07-19 13:20 . 2010-07-19 13:20    --------    d-----w-    c:\documents and settings\LocalService\Dokumenter
2010-07-19 13:10 . 2010-07-19 13:18    --------    d-----w-    c:\documents and settings\Administrator\Lokale indstillinger\Application Data\rikwkmcpo
2010-07-19 11:07 . 2010-07-19 11:07    60808    ----a-w-    c:\windows\system32\S32EVNT1.DLL
2010-07-19 11:07 . 2010-07-19 11:07    124976    ----a-w-    c:\windows\system32\drivers\SYMEVENT.SYS
2010-07-19 11:07 . 2010-07-19 11:12    --------    d-----w-    c:\programmer\Fælles filer\Symantec Shared
2010-07-19 11:07 . 2010-07-19 11:07    --------    d-----w-    c:\programmer\Symantec
2010-07-19 11:06 . 2010-07-19 19:17    --------    d-----w-    c:\windows\system32\drivers\NIS
2010-07-19 11:06 . 2010-07-19 11:06    --------    d-----w-    c:\programmer\Windows Sidebar
2010-07-19 11:06 . 2010-07-19 11:06    --------    d-----w-    c:\programmer\Norton Internet Security
2010-07-19 11:06 . 2010-07-19 11:07    --------    d-----w-    c:\documents and settings\All Users\Application Data\Norton
2010-07-19 11:06 . 2010-07-19 11:06    --------    d-----w-    c:\documents and settings\All Users\Application Data\NortonInstaller
2010-07-19 11:06 . 2010-07-19 11:06    --------    d-----w-    c:\programmer\NortonInstaller
2010-07-18 21:44 . 2010-07-18 21:44    --------    d-----w-    c:\programmer\Enigma Software Group
2010-07-18 21:43 . 2010-07-19 11:19    --------    d-----w-    c:\windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP
2010-07-18 19:48 . 2010-07-19 12:12    --------    d-----w-    c:\documents and settings\Administrator\Lokale indstillinger\Application Data\hlmajwykf
2010-06-25 21:43 . 2010-06-25 21:43    107888    ----a-w-    c:\windows\system32\CmdLineExt.dll
2010-06-25 21:39 . 2010-06-25 21:44    --------    d-----w-    c:\programmer\Deer Hunter Tournament
2010-06-25 20:52 . 2010-06-25 20:52    --------    d-----w-    c:\programmer\Atari

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-20 11:47 . 2009-03-05 18:57    --------    d---a-w-    c:\documents and settings\All Users\Application Data\TEMP
2010-07-19 21:18 . 2009-05-14 13:45    --------    d-----w-    c:\programmer\SPAMfighter
2010-07-19 14:40 . 2010-03-31 18:39    --------    d-----w-    c:\programmer\Illusion
2010-07-19 14:39 . 2010-03-08 17:59    --------    d-----w-    c:\programmer\John Deere American Builder Deluxe
2010-07-19 14:37 . 2010-03-10 17:55    --------    d-----w-    c:\programmer\Forklift Truck Simulator 2009
2010-07-19 14:36 . 2009-12-19 18:43    --------    d-----w-    c:\programmer\Activision Value
2010-07-19 14:18 . 2010-05-25 18:24    --------    d-----w-    c:\programmer\CCleaner
2010-07-19 13:10 . 2004-08-03 21:14    211072    ----a-w-    c:\windows\system32\drivers\ndis.sys
2010-07-19 11:17 . 2010-03-12 18:07    --------    d-----w-    c:\documents and settings\All Users\Application Data\avg9
2010-07-19 11:07 . 2010-07-19 11:07    805    ----a-w-    c:\windows\system32\drivers\SYMEVENT.INF
2010-07-19 11:07 . 2010-07-19 11:07    7443    ----a-w-    c:\windows\system32\drivers\SYMEVENT.CAT
2010-07-18 21:43 . 2010-03-09 17:45    --------    d-----w-    c:\programmer\Fælles filer\Wise Installation Wizard
2010-07-15 17:27 . 2010-05-03 19:32    --------    d-----w-    c:\programmer\Microsoft Silverlight
2010-06-29 21:31 . 2009-03-09 18:30    0    ----a-w-    c:\documents and settings\Administrator\temp.dat
2010-06-25 20:53 . 2009-03-06 14:39    --------    d-----w-    c:\documents and settings\All Users\Application Data\Trymedia
2010-06-23 17:10 . 2002-09-16 11:00    83058    ----a-w-    c:\windows\system32\perfc006.dat
2010-06-23 17:10 . 2002-09-16 11:00    456936    ----a-w-    c:\windows\system32\perfh006.dat
2010-06-14 15:24 . 2009-03-05 18:58    95744    ----a-w-    c:\documents and settings\All Users\Application Data\SpeedBit\DAP\SDCondition.dll
2010-06-14 14:30 . 2009-02-04 23:56    743936    ----a-w-    c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-05-21 17:23 . 2009-09-09 20:00    --------    d-----w-    c:\programmer\PokerStars
2010-05-02 08:26 . 2004-08-26 15:49    1850880    ----a-w-    c:\windows\system32\win32k.sys
2009-04-15 20:24 . 2009-04-15 20:24    1044480    ----a-w-    c:\programmer\mozilla firefox\plugins\libdivx.dll
2009-04-15 20:24 . 2009-04-15 20:24    200704    ----a-w-    c:\programmer\mozilla firefox\plugins\ssldivx.dll
.

------- Sigcheck -------

  • 2010-07-19 13:10 . !HASH: COULD NOT OPEN FILE !!!!! . 211072 . . [------] . . c:\windows\system32\drivers\ndis.sys
  • 2010-07-19 13:10 . !HASH: COULD NOT OPEN FILE !!!!! . 211072 . . [------] . . c:\windows\system32\dllcache\ndis.sys
  • 2008-04-13 19:20 . !HASH: COULD NOT OPEN FILE !!!!! . 182656 . . [------] . . c:\windows\SoftwareDistribution\Download\0a7e2be7ce3e791e393ff6250f4b2685\ndis.sys

  • 2008-04-14 . 9C88478DFAFF22089045EE3B166C7809 . 1571840 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\0a7e2be7ce3e791e393ff6250f4b2685\sfcfiles.dll
  • 2006-06-05 . 88E0C1E507D1B447EA1FBB31AFFF2735 . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DownloadAccelerator"="c:\programmer\DAP\DAP.EXE" [2009-03-05 2807296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\programmer\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"ACU"="c:\programmer\Atheros\ACU.exe" [2007-05-03 376921]
"SPAMfighter Agent"="c:\programmer\SPAMfighter\SFAgent.exe" [2009-03-12 326792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-26 15360]

c:\documents and settings\Administrator\Menuen Start\Programmer\Start\
Adobe Gamma.lnk - c:\programmer\F‘lles filer\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
PowerReg Scheduler V3.exe [2010-3-7 225280]

[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Menuen Start^Programmer^Start^MagicDisc.lnk]
path=c:\documents and settings\Administrator\Menuen Start\Programmer\Start\MagicDisc.lnk
backup=c:\windows\pss\MagicDisc.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^AutoCAD Startup Accelerator.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\AutoCAD Startup Accelerator.lnk
backup=c:\windows\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 00:04    39792    ----a-w-    c:\programmer\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 10:43    69632    ------r-    c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2004-08-26 16:53    110592    ----a-w-    c:\windows\system32\bthprops.cpl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2004-08-26 15:53    15360    ----a-w-    c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2008-12-29 10:40    687560    ----a-w-    c:\programmer\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator]
2009-03-05 18:56    2807296    ----a-w-    c:\programmer\DAP\DAP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-08-26 17:02    1667584    ------w-    c:\programmer\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2007-07-05 08:08    16380416    ------r-    c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-03-09 18:29    148888    ----a-w-    c:\programmer\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2009-11-13 11:31    247144    ----a-w-    c:\programmer\TomTom HOME 2\TomTomHOMERunner.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\BitLord\\BitLord.exe"=
"c:\\Programmer\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Programmer\\TomTom HOME 2\\xulrunner\\TomTomHOMERuntime.exe"=
"c:\\Programmer\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Programmer\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Programmer\\Autodesk\\Backburner\\manager.exe"=
"c:\\Programmer\\Autodesk\\Backburner\\server.exe"=
"c:\\Programmer\\Autodesk\\3ds Max 2010\\3dsmax.exe"=
"c:\\Programmer\\Autodesk\\3ds Max 2010\\mentalray\\satellite\\raysat_3dsmax2010_32server.exe"=
"c:\\Programmer\\Autodesk\\3ds Max 2010\\mentalray\\satellite\\raysat_3dsmax2010_32.exe"=
"c:\\Documents and Settings\\Administrator\\Skrivebord\\Spil\\Valve\\hl.exe"=
"c:\\Programmer\\Counter-Strike 1.6\\hl.exe"=
"c:\\Programmer\\Atari\\Deer Hunter 2005\\DH2005.exe"=
"c:\\Programmer\\Deer Hunter Tournament\\DHT.exe"=
"c:\\Programmer\\Deer Hunter Tournament\\Updater.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=

R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1107000.00C\symds.sys [19-07-2010 19:37 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1107000.00C\symefa.sys [19-07-2010 19:37 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20100709.001\BHDrvx86.sys [19-07-2010 13:12 691248]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1107000.00C\cchpx86.sys [19-07-2010 19:37 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1107000.00C\ironx86.sys [19-07-2010 19:37 116784]
R2 mi-raysat_3dsmax2010_32;mental ray 3.7 Satellite for Autodesk 3ds Max 2010 32-bit 32-bit;c:\programmer\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe [12-03-2009 18:36 86016]
R2 NIS;Norton Internet Security;c:\programmer\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe [19-07-2010 19:36 126392]
R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\programmer\SPAMfighter\sfus.exe [12-03-2009 10:44 184968]
R2 TomTomHOMEService;TomTomHOMEService;c:\programmer\TomTom HOME 2\TomTomHOMEService.exe [13-11-2009 13:31 92008]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\programmer\Fælles filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [19-07-2010 13:11 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100719.001\IDSXpx86.sys [20-07-2010 09:24 331640]
S0 uavnc;uavnc; [x]
S3 RenameMe;RenameMe;c:\windows\system32\RenameMe.sys [01-05-2010 20:36 8320]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10-02-2009 20:31 717296]
.
Indhold af mappen 'Planlagte Opgaver'

2010-07-20 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-02-28 21:18]
.
.
------- Yderligere scanning -------
.
uStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage
IE: &Clean Traces - c:\programmer\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\programmer\DAP\dapextie.htm
IE: Download &all with DAP - c:\programmer\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: danid.dk
TCP: {2A402FDB-2814-4B8E-BEB1-104BEF3FB5DA} = 208.67.222.222,208.67.220.220
DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} - hxxps://www.portalbank.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.30.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cz60s7nv.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://eu.ask.com?o=15458&l=dis
FF - prefs.js: keyword.URL - hxxp://dk.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_dk&p=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\IPSFFPlgn\components\IPSFFPl.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLITIKKER ----
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type",                  5);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\programmer\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\programmer\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programmer\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programmer\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
c:\programmer\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - TOMME GENVEJE FJERNET - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
MSConfigStartUp-12CFG214-K641-12SF-N85P - c:\recycler\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe
MSConfigStartUp-ewrgetuj - c:\docume~1\ADMINI~1\LOKALE~1\Temp\geurge.exe
MSConfigStartUp-Microsoft Driver Setup - c:\windows\cndrive32.exe
MSConfigStartUp-sta - ulbgp.dll
AddRemove-V-Ray for 3dsmax 2010 for x86 - c:\programmer\Chaos Group\V-Ray\3dsmax 2010 for x86\uninstall\wininstaller.exe-uninstall=c:\programmer\Chaos Group\V-Ray\3dsmax 2010 for x86\uninstall\install.log



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-20 13:47
Windows 5.1.2600 Service Pack 2 NTFS

scanner skjulte processer ... 

scanner skjulte autostarter ...

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe >>UNKNOWN [0x8AD280E0]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba10cfc3
\Driver\ACPI -> ACPI.sys @ 0xb9f7fcb8
\Driver\atapi -> atapi.sys @ 0xb9f117b4
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80582414
ParseProcedure -> ntkrnlpa.exe @ 0x80581554
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80582414
ParseProcedure -> ntkrnlpa.exe @ 0x80581554
NDIS: Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0x8ad0fba0
PacketIndicateHandler -> NDIS.sys @ 0x8acfea0b
SendHandler -> NDIS.sys @ 0x8ad12b31
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NIS]
"ImagePath"="\"c:\programmer\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe\" /s \"NIS\" /m \"c:\programmer\Norton Internet Security\Engine\17.7.0.12\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs startet under kørende Processer ---------------------

- - - - - - - > 'winlogon.exe'(1252)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(1392)
c:\windows\system32\msi.dll
c:\programmer\Fælles filer\Adobe\Acrobat\ActiveX\PDFShell.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\brss01a.exe
c:\windows\system32\acs.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\agrsmsvc.exe
c:\programmer\Fælles filer\Autodata Limited Shared\Service\ADCDLicSvc.exe
c:\windows\system32\crypserv.exe
c:\programmer\Java\jre6\bin\jqs.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Gennemført tid: 2010-07-20  13:52:19 - maskinen blev genstartet
ComboFix-quarantined-files.txt  2010-07-20 11:52

Pre-Kørsel: 148.574.265.344 byte ledig
Post-Kørsel: 148.754.657.280 byte ledig

- - End Of File - - FC077B5F5851EEFEBD53600AABB139F3
Avatar billede f-arn Guru
20. juli 2010 - 16:33 #12
Har du brugt CCleaner i går? Jeg tænker på denne:
c:\documents and settings\Administrator\Dokumenter\cc_20100719_162634.reg
Den slettede Combofix.

------

Har du en Windows XP Installation CD?

------

Højreklik på skrivebordet og vælg ny->tekstdokument og kopier det fremhævede ind og gem filen som CFScript

Killall::
Snapshot::
Folder::
c:\documents and settings\Administrator\Lokale indstillinger\Application Data\rikwkmcpo
c:\documents and settings\Administrator\Lokale indstillinger\Application Data\hlmajwykf
Dirlook::
c:\windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP
Driver::
uavnc


Da Combofix kan konflikte med dine sikkerhedsprogrammer er det vigtigt at du deaktiverer dem.

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen.
http://www.fromsej.saknet.dk/billeder/swfcombo.gif

Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når Combofix er færdig, og efter det (muligvis) har genstartet, skulle der gerne åbnes en logfil combofix.txt som ligger her C:\Combofix.txt

Indholdet af denne fil må du gerne lægge herind.
Avatar billede dj-bmw Nybegynder
20. juli 2010 - 21:30 #13
Ja brugte CCleaner igår.

Har desværre ikke nogen cd, da computeren blev købt med windows installeret.

Skal jeg stadig kører combofix, med det nye tekst?
Avatar billede f-arn Guru
21. juli 2010 - 06:53 #14
Start Stifinder og find:
C:\Qoobox\Quarantine
Kopier c:\documents and settings\Administrator\Dokumenter\cc_20100719_162634.reg.vir et andet sted hen. Omdøb den til c:\documents and settings\Administrator\Dokumenter\cc_20100719_162634.reg.txt

------

Hent en af disse filer. (husk at vælge sproget svarende til sproget på dit styresystem):

UK: http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=535d248d-5e10-49b5-b80c-0a0205368124

DK: http://www.microsoft.com/downloads/details.aspx?displaylang=da&FamilyID=535D248D-5E10-49B5-B80C-0A0205368124

Træk så med musen den nye fil hen over combofix, og giv slip. Herefter skulle Combofix gerne give sig til at installere Gendannelseskonsollen.
Avatar billede f-arn Guru
21. juli 2010 - 06:55 #15
Skal jeg stadig kører combofix, med det nye tekst

Vent lige med det.
Avatar billede dj-bmw Nybegynder
21. juli 2010 - 12:58 #16
øh her ikke lige med..
Skal jeg trække cc_20100719_162634.reg.vir som jeg har kopiret og omdøbt til .txt over i combofix, eller filen som jeg har downloadet fra microsoft over i combofix?
Avatar billede f-arn Guru
21. juli 2010 - 13:23 #17
Den fra Microsoft - lad den fortsætte med en skanning, og kopier den nye Combofix.txt herind.
Avatar billede dj-bmw Nybegynder
21. juli 2010 - 13:54 #18
Den nye combofix.txt:

ComboFix 10-07-19.02 - Administrator 21-07-2010  13:36:40.2.2 - x86
Microsoft Windows XP Professional  5.1.2600.2.1252.45.1030.18.3071.2614 [GMT 2:00]
Kører fra: c:\documents and settings\Administrator\Skrivebord\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\Administrator\Skrivebord\WindowsXP-KB310994-SP2-Pro-BootDisk-DAN.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
* Dannede nyt systemgendannelsespunkt
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.

Inficeret kopi af c:\windows\system32\drivers\ndis.sys blev fundet og desinficeret
Genskabt kopi fra - c:\system volume information\_restore{C09A8A9D-B7AD-4B58-BEC6-984C7A87633A}\RP1\A0001006.sys
.
(((((((((((((((((((((((((((((  Filer skabt fra 2010-06-21 til 2010-07-21  )))))))))))))))))))))))))))))))))))
.

2010-07-19 17:37 . 2010-05-06 04:01    361904    ----a-w-    c:\windows\system32\drivers\symtdi.sys
2010-07-19 17:37 . 2010-04-22 03:02    173104    ----a-w-    c:\windows\system32\drivers\symefa.sys
2010-07-19 17:37 . 2010-04-22 02:29    43696    ----a-w-    c:\windows\system32\drivers\srtspx.sys
2010-07-19 17:37 . 2009-08-30 00:17    328752    ----a-r-    c:\windows\system32\drivers\symds.sys
2010-07-19 17:37 . 2010-04-29 05:03    116784    ----a-w-    c:\windows\system32\drivers\ironx86.sys
2010-07-19 17:37 . 2010-02-26 00:22    501888    ----a-w-    c:\windows\system32\drivers\cchpx86.sys
2010-07-19 14:59 . 2010-07-19 14:59    --------    d-----w-    c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-07-19 14:58 . 2010-04-29 13:39    38224    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-19 14:58 . 2010-07-19 14:58    --------    d-----w-    c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-19 14:58 . 2010-04-29 13:39    20952    ----a-w-    c:\windows\system32\drivers\mbam.sys
2010-07-19 14:58 . 2010-07-19 14:58    --------    d-----w-    c:\programmer\Malwarebytes' Anti-Malware
2010-07-19 13:20 . 2010-07-19 13:20    --------    d-----w-    c:\documents and settings\LocalService\Dokumenter
2010-07-19 13:10 . 2010-07-19 13:18    --------    d-----w-    c:\documents and settings\Administrator\Lokale indstillinger\Application Data\rikwkmcpo
2010-07-19 11:07 . 2010-07-19 11:07    60808    ----a-w-    c:\windows\system32\S32EVNT1.DLL
2010-07-19 11:07 . 2010-07-19 11:07    124976    ----a-w-    c:\windows\system32\drivers\SYMEVENT.SYS
2010-07-19 11:07 . 2010-07-19 11:12    --------    d-----w-    c:\programmer\Fælles filer\Symantec Shared
2010-07-19 11:07 . 2010-07-19 11:07    --------    d-----w-    c:\programmer\Symantec
2010-07-19 11:06 . 2010-07-19 19:17    --------    d-----w-    c:\windows\system32\drivers\NIS
2010-07-19 11:06 . 2010-07-19 11:06    --------    d-----w-    c:\programmer\Windows Sidebar
2010-07-19 11:06 . 2010-07-19 11:06    --------    d-----w-    c:\programmer\Norton Internet Security
2010-07-19 11:06 . 2010-07-19 11:07    --------    d-----w-    c:\documents and settings\All Users\Application Data\Norton
2010-07-19 11:06 . 2010-07-19 11:06    --------    d-----w-    c:\documents and settings\All Users\Application Data\NortonInstaller
2010-07-19 11:06 . 2010-07-19 11:06    --------    d-----w-    c:\programmer\NortonInstaller
2010-07-18 21:44 . 2010-07-18 21:44    --------    d-----w-    c:\programmer\Enigma Software Group
2010-07-18 21:43 . 2010-07-19 11:19    --------    d-----w-    c:\windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP
2010-07-18 19:48 . 2010-07-19 12:12    --------    d-----w-    c:\documents and settings\Administrator\Lokale indstillinger\Application Data\hlmajwykf
2010-06-25 21:43 . 2010-06-25 21:43    107888    ----a-w-    c:\windows\system32\CmdLineExt.dll
2010-06-25 21:39 . 2010-06-25 21:44    --------    d-----w-    c:\programmer\Deer Hunter Tournament
2010-06-25 20:52 . 2010-06-25 20:52    --------    d-----w-    c:\programmer\Atari

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-21 11:47 . 2009-03-05 18:57    --------    d---a-w-    c:\documents and settings\All Users\Application Data\TEMP
2010-07-19 21:18 . 2009-05-14 13:45    --------    d-----w-    c:\programmer\SPAMfighter
2010-07-19 14:40 . 2010-03-31 18:39    --------    d-----w-    c:\programmer\Illusion
2010-07-19 14:39 . 2010-03-08 17:59    --------    d-----w-    c:\programmer\John Deere American Builder Deluxe
2010-07-19 14:37 . 2010-03-10 17:55    --------    d-----w-    c:\programmer\Forklift Truck Simulator 2009
2010-07-19 14:36 . 2009-12-19 18:43    --------    d-----w-    c:\programmer\Activision Value
2010-07-19 14:18 . 2010-05-25 18:24    --------    d-----w-    c:\programmer\CCleaner
2010-07-19 11:17 . 2010-03-12 18:07    --------    d-----w-    c:\documents and settings\All Users\Application Data\avg9
2010-07-19 11:07 . 2010-07-19 11:07    805    ----a-w-    c:\windows\system32\drivers\SYMEVENT.INF
2010-07-19 11:07 . 2010-07-19 11:07    7443    ----a-w-    c:\windows\system32\drivers\SYMEVENT.CAT
2010-07-18 21:43 . 2010-03-09 17:45    --------    d-----w-    c:\programmer\Fælles filer\Wise Installation Wizard
2010-07-15 17:27 . 2010-05-03 19:32    --------    d-----w-    c:\programmer\Microsoft Silverlight
2010-06-29 21:31 . 2009-03-09 18:30    0    ----a-w-    c:\documents and settings\Administrator\temp.dat
2010-06-25 20:53 . 2009-03-06 14:39    --------    d-----w-    c:\documents and settings\All Users\Application Data\Trymedia
2010-06-23 17:10 . 2002-09-16 11:00    83058    ----a-w-    c:\windows\system32\perfc006.dat
2010-06-23 17:10 . 2002-09-16 11:00    456936    ----a-w-    c:\windows\system32\perfh006.dat
2010-06-14 15:24 . 2009-03-05 18:58    95744    ----a-w-    c:\documents and settings\All Users\Application Data\SpeedBit\DAP\SDCondition.dll
2010-06-14 14:30 . 2009-02-04 23:56    743936    ----a-w-    c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-05-02 08:26 . 2004-08-26 15:49    1850880    ----a-w-    c:\windows\system32\win32k.sys
2009-04-15 20:24 . 2009-04-15 20:24    1044480    ----a-w-    c:\programmer\mozilla firefox\plugins\libdivx.dll
2009-04-15 20:24 . 2009-04-15 20:24    200704    ----a-w-    c:\programmer\mozilla firefox\plugins\ssldivx.dll
.

------- Sigcheck -------

  • 2008-04-14 . 9C88478DFAFF22089045EE3B166C7809 . 1571840 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\0a7e2be7ce3e791e393ff6250f4b2685\sfcfiles.dll
  • 2006-06-05 . 88E0C1E507D1B447EA1FBB31AFFF2735 . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((  SnapShot@2010-07-20_11.48.34  )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-07-21 11:47 . 2010-07-21 11:47    16384              c:\windows\system32\config\systemprofile\Lokale indstillinger\Temp\Perflib_Perfdata_7dc.dat
+ 2010-07-21 11:46 . 2010-07-21 11:46    16384              c:\windows\system32\config\systemprofile\Lokale indstillinger\Temp\Perflib_Perfdata_79c.dat
+ 2004-08-03 21:14 . 2004-08-03 21:14    182912              c:\windows\system32\drivers\ndis.sys
+ 2004-08-03 21:14 . 2004-08-03 21:14    182912              c:\windows\system32\dllcache\ndis.sys
.
(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DownloadAccelerator"="c:\programmer\DAP\DAP.EXE" [2009-03-05 2807296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\programmer\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"ACU"="c:\programmer\Atheros\ACU.exe" [2007-05-03 376921]
"SPAMfighter Agent"="c:\programmer\SPAMfighter\SFAgent.exe" [2009-03-12 326792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-26 15360]

c:\documents and settings\Administrator\Menuen Start\Programmer\Start\
Adobe Gamma.lnk - c:\programmer\F‘lles filer\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
PowerReg Scheduler V3.exe [2010-3-7 225280]

[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Menuen Start^Programmer^Start^MagicDisc.lnk]
path=c:\documents and settings\Administrator\Menuen Start\Programmer\Start\MagicDisc.lnk
backup=c:\windows\pss\MagicDisc.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^AutoCAD Startup Accelerator.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\AutoCAD Startup Accelerator.lnk
backup=c:\windows\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 00:04    39792    ----a-w-    c:\programmer\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 10:43    69632    ------r-    c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2004-08-26 16:53    110592    ----a-w-    c:\windows\system32\bthprops.cpl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2004-08-26 15:53    15360    ----a-w-    c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2008-12-29 10:40    687560    ----a-w-    c:\programmer\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator]
2009-03-05 18:56    2807296    ----a-w-    c:\programmer\DAP\DAP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-08-26 17:02    1667584    ------w-    c:\programmer\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2007-07-05 08:08    16380416    ------r-    c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-03-09 18:29    148888    ----a-w-    c:\programmer\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2009-11-13 11:31    247144    ----a-w-    c:\programmer\TomTom HOME 2\TomTomHOMERunner.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\BitLord\\BitLord.exe"=
"c:\\Programmer\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Programmer\\TomTom HOME 2\\xulrunner\\TomTomHOMERuntime.exe"=
"c:\\Programmer\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Programmer\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Programmer\\Autodesk\\Backburner\\manager.exe"=
"c:\\Programmer\\Autodesk\\Backburner\\server.exe"=
"c:\\Programmer\\Autodesk\\3ds Max 2010\\3dsmax.exe"=
"c:\\Programmer\\Autodesk\\3ds Max 2010\\mentalray\\satellite\\raysat_3dsmax2010_32server.exe"=
"c:\\Programmer\\Autodesk\\3ds Max 2010\\mentalray\\satellite\\raysat_3dsmax2010_32.exe"=
"c:\\Documents and Settings\\Administrator\\Skrivebord\\Spil\\Valve\\hl.exe"=
"c:\\Programmer\\Counter-Strike 1.6\\hl.exe"=
"c:\\Programmer\\Atari\\Deer Hunter 2005\\DH2005.exe"=
"c:\\Programmer\\Deer Hunter Tournament\\DHT.exe"=
"c:\\Programmer\\Deer Hunter Tournament\\Updater.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=

R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1107000.00C\symds.sys [19-07-2010 19:37 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1107000.00C\symefa.sys [19-07-2010 19:37 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20100709.001\BHDrvx86.sys [19-07-2010 13:12 691248]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1107000.00C\cchpx86.sys [19-07-2010 19:37 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1107000.00C\ironx86.sys [19-07-2010 19:37 116784]
R2 mi-raysat_3dsmax2010_32;mental ray 3.7 Satellite for Autodesk 3ds Max 2010 32-bit 32-bit;c:\programmer\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe [12-03-2009 18:36 86016]
R2 NIS;Norton Internet Security;c:\programmer\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe [19-07-2010 19:36 126392]
R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\programmer\SPAMfighter\sfus.exe [12-03-2009 10:44 184968]
R2 TomTomHOMEService;TomTomHOMEService;c:\programmer\TomTom HOME 2\TomTomHOMEService.exe [13-11-2009 13:31 92008]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\programmer\Fælles filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [19-07-2010 13:11 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100720.001\IDSXpx86.sys [21-07-2010 10:05 331640]
S0 uavnc;uavnc; [x]
S3 RenameMe;RenameMe;c:\windows\system32\RenameMe.sys [01-05-2010 20:36 8320]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10-02-2009 20:31 717296]
.
Indhold af mappen 'Planlagte Opgaver'

2010-07-21 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-02-28 21:18]
.
.
------- Yderligere scanning -------
.
uStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage
IE: &Clean Traces - c:\programmer\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\programmer\DAP\dapextie.htm
IE: Download &all with DAP - c:\programmer\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: danid.dk
TCP: {2A402FDB-2814-4B8E-BEB1-104BEF3FB5DA} = 208.67.222.222,208.67.220.220
DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} - hxxps://www.portalbank.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.30.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cz60s7nv.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://eu.ask.com?o=15458&l=dis
FF - prefs.js: keyword.URL - hxxp://dk.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_dk&p=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\IPSFFPlgn\components\IPSFFPl.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLITIKKER ----
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type",                  5);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\programmer\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\programmer\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programmer\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programmer\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
c:\programmer\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
.
------- Fil Associationer -------
.
.scr=AutoCADScriptFile
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-21 13:47
Windows 5.1.2600 Service Pack 2 NTFS

scanner skjulte processer ... 

scanner skjulte autostarter ...

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NIS]
"ImagePath"="\"c:\programmer\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe\" /s \"NIS\" /m \"c:\programmer\Norton Internet Security\Engine\17.7.0.12\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs startet under kørende Processer ---------------------

- - - - - - - > 'winlogon.exe'(1252)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3312)
c:\windows\system32\msi.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\brss01a.exe
c:\windows\system32\acs.exe
c:\windows\system32\agrsmsvc.exe
c:\programmer\Fælles filer\Autodata Limited Shared\Service\ADCDLicSvc.exe
c:\windows\system32\crypserv.exe
c:\programmer\Java\jre6\bin\jqs.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Gennemført tid: 2010-07-21  13:52:19 - maskinen blev genstartet
ComboFix-quarantined-files.txt  2010-07-21 11:52
ComboFix2.txt  2010-07-20 11:52

Pre-Kørsel: 148.691.464.192 byte ledig
Post-Kørsel: 148.688.986.112 byte ledig

WindowsXP-KB310994-SP2-Pro-BootDisk-DAN.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

- - End Of File - - A35EBB691FB769A246C9CF6717A8E832
Avatar billede f-arn Guru
21. juli 2010 - 14:55 #19
1. Hent dette lille værktøj:

http://jpshortstuff.247fixes.com/SystemLook.exe
http://images.malwareremoval.com/jpshortstuff/SystemLook.exe (alternativ adresse)

2. Dobbeltklik på systemlook.exe - nu dukker der et lille vindue op, hvor du skal kopiere HELE indholdet med fed skrift ind:

:filefind
sfcfiles.dll


3. Klik på knappen Look. Programmet vil nu lede på din computer.

4. Når programmet er færdig med at lede, vil der dukke et notepad-vindue op, med en log fra SystemLook. Den skal du kopiere herind i forum i dit næste svar. Log'en kan også findes på dit Skrivebord med navnet: SystemLook.txt.
Avatar billede dj-bmw Nybegynder
21. juli 2010 - 18:48 #20
Log fra Systemlook:

SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 18:47 on 21/07/2010 by Administrator (Administrator - Elevation successful)

========== filefind ==========

Searching for "sfcfiles.dll"
C:\WINDOWS\SoftwareDistribution\Download\0a7e2be7ce3e791e393ff6250f4b2685\sfcfiles.dll    --a--- 1571840 bytes    [16:05 14/04/2008]    [16:05 14/04/2008] 9C88478DFAFF22089045EE3B166C7809
C:\WINDOWS\system32\sfcfiles.dll    --a--- 1548288 bytes    [18:19 05/06/2006]    [18:19 05/06/2006] 88E0C1E507D1B447EA1FBB31AFFF2735

-=End Of File=-
Avatar billede f-arn Guru
21. juli 2010 - 21:41 #21
Find og upload nedenstående hos Jotti eller Virustotal:

C:\WINDOWS\SoftwareDistribution\Download\0a7e2be7ce3e791e393ff6250f4b2685\sfcfiles.dll
C:\WINDOWS\system32\sfcfiles.dll


http://virusscan.jotti.org/ - http://www.virustotal.com/en/indexf.html

Kopier resultatet herind
Avatar billede dj-bmw Nybegynder
21. juli 2010 - 21:52 #22
C:\WINDOWS\SoftwareDistribution\Download\0a7e2be7ce3e791e393ff6250f4b2685\sfcfiles.dll

Filename:     sfcfiles.dll
Status:    
Scan finished. 0 out of 19 scanners reported malware.
Scan taken on:      Wed 21 Jul 2010 21:47:13 (CET) Permalink
           
Additional info
File size:     1571840 bytes
Filetype:     PE32 executable for MS Windows (DLL) (console) Intel 80386 32-bit
MD5:     9c88478dfaff22089045ee3b166c7809
SHA1:     e7448f9e2106777409f0329096b0a99b0bebc609




Scanners
[ArcaVir]    
2010-07-21 Found nothing
    [G DATA]    
2010-07-21 Found nothing
[Avast! antivirus]    
2010-07-21 Found nothing
    [Ikarus]    
2010-07-21 Found nothing
[Grisoft AVG Anti-Virus]    
2010-07-21 Found nothing
    [Kaspersky Anti-Virus]    
2010-07-21 Found nothing
[Avira AntiVir]    
2010-07-21 Found nothing
    [ESET NOD32]    
2010-07-21 Found nothing
[Softwin BitDefender]    
2010-07-21 Found nothing
    [Panda Antivirus]    
2010-07-21 Found nothing
[ClamAV]    
2010-07-21 Found nothing
    [Quick Heal]    
2010-07-21 Found nothing
[CPsecure]    
2010-07-21 Found nothing
    [Sophos]    
2010-07-21 Found nothing
[Dr.Web]    
2010-07-21 Found nothing
    [VirusBlokAda VBA32]    
2010-07-21 Found nothing
[Frisk F-Prot Antivirus]    
2010-07-21 Found nothing
    [VirusBuster]    
2010-07-21 Found nothing
[F-Secure Anti-Virus]    
2010-07-21 Found nothing
     

C:\WINDOWS\system32\sfcfiles.dll

Filename:     sfcfiles.dll
Status:    
Scan finished. 0 out of 19 scanners reported malware.
Scan taken on:      Wed 21 Jul 2010 21:50:45 (CET) Permalink
           
Additional info
File size:     1548288 bytes
Filetype:     PE32 executable for MS Windows (DLL) (console) Intel 80386 32-bit
MD5:     88e0c1e507d1b447ea1fbb31afff2735
SHA1:     4d3b1b2675040dcdabf652b128ca7efec53a2811




Scanners
[ArcaVir]    
2010-07-21 Found nothing
    [G DATA]    
2010-07-21 Found nothing
[Avast! antivirus]    
2010-07-21 Found nothing
    [Ikarus]    
2010-07-21 Found nothing
[Grisoft AVG Anti-Virus]    
2010-07-21 Found nothing
    [Kaspersky Anti-Virus]    
2010-07-21 Found nothing
[Avira AntiVir]    
2010-07-21 Found nothing
    [ESET NOD32]    
2010-07-21 Found nothing
[Softwin BitDefender]    
2010-07-21 Found nothing
    [Panda Antivirus]    
2010-07-21 Found nothing
[ClamAV]    
2010-07-21 Found nothing
    [Quick Heal]    
2010-07-21 Found nothing
[CPsecure]    
2010-07-21 Found nothing
    [Sophos]    
2010-07-21 Found nothing
[Dr.Web]    
2010-07-21 Found nothing
    [VirusBlokAda VBA32]    
2010-07-21 Found nothing
[Frisk F-Prot Antivirus]    
2010-07-21 Found nothing
    [VirusBuster]    
2010-07-21 Found nothing
[F-Secure Anti-Virus]    
2010-07-21 Found nothing
Avatar billede f-arn Guru
22. juli 2010 - 10:21 #23
Hent sfcfiles.dll her: http://www.dlldump.com/download-dll-files_new.php/dllfiles/S/sfcfiles.dll/5.1.2600.2180/download.html

Gem den i C:\. Det er vigtigt du gemmer den der, da det ellers vil virke!

------

Højreklik på skrivebordet og vælg ny->tekstdokument og kopier det fremhævede ind og gem filen som CFScript

Killall::
Snapshot::
FCopy::
c:\sfcfiles.dll | c:\windows\system32\sfcfiles.dll
Folder::
c:\documents and settings\Administrator\Lokale indstillinger\Application Data\rikwkmcpo
c:\documents and settings\Administrator\Lokale indstillinger\Application Data\hlmajwykf
Dirlook::
c:\windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP
Driver::
uavnc


Da Combofix kan konflikte med dine sikkerhedsprogrammer er det vigtigt at du deaktiverer dem.

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen.
http://www.fromsej.saknet.dk/billeder/swfcombo.gif

Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når Combofix er færdig, og efter det (muligvis) har genstartet, skulle der gerne åbnes en logfil combofix.txt som ligger her C:\Combofix.txt

Indholdet af denne fil må du gerne lægge herind.
Avatar billede f-arn Guru
22. juli 2010 - 10:24 #24
Og der skulle selvfølgelig stå:
Gem den i C:\. Det er vigtigt du gemmer den der, da det ellers ikke vil virke!
Avatar billede dj-bmw Nybegynder
22. juli 2010 - 11:09 #25
ComboFix 10-07-19.02 - Administrator 22-07-2010  10:48:07.3.2 - x86
Microsoft Windows XP Professional  5.1.2600.2.1252.45.1030.18.3071.2266 [GMT 2:00]
Kører fra: c:\documents and settings\Administrator\Skrivebord\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\Administrator\Skrivebord\CFScript.txt
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator\Lokale indstillinger\Application Data\hlmajwykf
c:\documents and settings\Administrator\Lokale indstillinger\Application Data\rikwkmcpo

.
--------------- FCopy ---------------

c:\sfcfiles.dll --> c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((((((((  Drivers/Tjenester  )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_uavnc


(((((((((((((((((((((((((((((  Filer skabt fra 2010-06-22 til 2010-07-22  )))))))))))))))))))))))))))))))))))
.

2010-07-22 08:43 . 2010-07-22 08:43    1580544    ------w-    C:\sfcfiles.dll
2010-07-19 17:37 . 2010-05-06 04:01    361904    ----a-w-    c:\windows\system32\drivers\symtdi.sys
2010-07-19 17:37 . 2010-04-22 03:02    173104    ----a-w-    c:\windows\system32\drivers\symefa.sys
2010-07-19 17:37 . 2010-04-22 02:29    43696    ----a-w-    c:\windows\system32\drivers\srtspx.sys
2010-07-19 17:37 . 2009-08-30 00:17    328752    ----a-r-    c:\windows\system32\drivers\symds.sys
2010-07-19 17:37 . 2010-04-29 05:03    116784    ----a-w-    c:\windows\system32\drivers\ironx86.sys
2010-07-19 17:37 . 2010-02-26 00:22    501888    ----a-w-    c:\windows\system32\drivers\cchpx86.sys
2010-07-19 14:59 . 2010-07-19 14:59    --------    d-----w-    c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-07-19 14:58 . 2010-04-29 13:39    38224    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-19 14:58 . 2010-07-19 14:58    --------    d-----w-    c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-19 14:58 . 2010-04-29 13:39    20952    ----a-w-    c:\windows\system32\drivers\mbam.sys
2010-07-19 14:58 . 2010-07-19 14:58    --------    d-----w-    c:\programmer\Malwarebytes' Anti-Malware
2010-07-19 13:20 . 2010-07-19 13:20    --------    d-----w-    c:\documents and settings\LocalService\Dokumenter
2010-07-19 11:07 . 2010-07-19 11:07    60808    ----a-w-    c:\windows\system32\S32EVNT1.DLL
2010-07-19 11:07 . 2010-07-19 11:07    124976    ----a-w-    c:\windows\system32\drivers\SYMEVENT.SYS
2010-07-19 11:07 . 2010-07-19 11:12    --------    d-----w-    c:\programmer\Fælles filer\Symantec Shared
2010-07-19 11:07 . 2010-07-19 11:07    --------    d-----w-    c:\programmer\Symantec
2010-07-19 11:06 . 2010-07-19 19:17    --------    d-----w-    c:\windows\system32\drivers\NIS
2010-07-19 11:06 . 2010-07-19 11:06    --------    d-----w-    c:\programmer\Windows Sidebar
2010-07-19 11:06 . 2010-07-19 11:06    --------    d-----w-    c:\programmer\Norton Internet Security
2010-07-19 11:06 . 2010-07-19 11:07    --------    d-----w-    c:\documents and settings\All Users\Application Data\Norton
2010-07-19 11:06 . 2010-07-19 11:06    --------    d-----w-    c:\documents and settings\All Users\Application Data\NortonInstaller
2010-07-19 11:06 . 2010-07-19 11:06    --------    d-----w-    c:\programmer\NortonInstaller
2010-07-18 21:44 . 2010-07-18 21:44    --------    d-----w-    c:\programmer\Enigma Software Group
2010-07-18 21:43 . 2010-07-19 11:19    --------    d-----w-    c:\windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP
2010-06-25 21:43 . 2010-06-25 21:43    107888    ----a-w-    c:\windows\system32\CmdLineExt.dll
2010-06-25 21:39 . 2010-06-25 21:44    --------    d-----w-    c:\programmer\Deer Hunter Tournament
2010-06-25 20:52 . 2010-06-25 20:52    --------    d-----w-    c:\programmer\Atari

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-22 08:55 . 2009-03-05 18:57    --------    d---a-w-    c:\documents and settings\All Users\Application Data\TEMP
2010-07-22 08:43 . 2006-06-05 18:19    1580544    ----a-w-    c:\windows\system32\sfcfiles.dll
2010-07-21 17:37 . 2009-05-14 13:45    --------    d-----w-    c:\programmer\SPAMfighter
2010-07-19 14:40 . 2010-03-31 18:39    --------    d-----w-    c:\programmer\Illusion
2010-07-19 14:39 . 2010-03-08 17:59    --------    d-----w-    c:\programmer\John Deere American Builder Deluxe
2010-07-19 14:37 . 2010-03-10 17:55    --------    d-----w-    c:\programmer\Forklift Truck Simulator 2009
2010-07-19 14:36 . 2009-12-19 18:43    --------    d-----w-    c:\programmer\Activision Value
2010-07-19 14:18 . 2010-05-25 18:24    --------    d-----w-    c:\programmer\CCleaner
2010-07-19 11:17 . 2010-03-12 18:07    --------    d-----w-    c:\documents and settings\All Users\Application Data\avg9
2010-07-19 11:07 . 2010-07-19 11:07    805    ----a-w-    c:\windows\system32\drivers\SYMEVENT.INF
2010-07-19 11:07 . 2010-07-19 11:07    7443    ----a-w-    c:\windows\system32\drivers\SYMEVENT.CAT
2010-07-18 21:43 . 2010-03-09 17:45    --------    d-----w-    c:\programmer\Fælles filer\Wise Installation Wizard
2010-07-15 17:27 . 2010-05-03 19:32    --------    d-----w-    c:\programmer\Microsoft Silverlight
2010-06-29 21:31 . 2009-03-09 18:30    0    ----a-w-    c:\documents and settings\Administrator\temp.dat
2010-06-25 20:53 . 2009-03-06 14:39    --------    d-----w-    c:\documents and settings\All Users\Application Data\Trymedia
2010-06-23 17:10 . 2002-09-16 11:00    83058    ----a-w-    c:\windows\system32\perfc006.dat
2010-06-23 17:10 . 2002-09-16 11:00    456936    ----a-w-    c:\windows\system32\perfh006.dat
2010-06-14 15:24 . 2009-03-05 18:58    95744    ----a-w-    c:\documents and settings\All Users\Application Data\SpeedBit\DAP\SDCondition.dll
2010-06-14 14:30 . 2009-02-04 23:56    743936    ----a-w-    c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-05-02 08:26 . 2004-08-26 15:49    1850880    ----a-w-    c:\windows\system32\win32k.sys
2009-04-15 20:24 . 2009-04-15 20:24    1044480    ----a-w-    c:\programmer\mozilla firefox\plugins\libdivx.dll
2009-04-15 20:24 . 2009-04-15 20:24    200704    ----a-w-    c:\programmer\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((((((((((  Look  )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP ----

2010-07-19 11:19 . 2010-07-19 11:19    7069    ----a-w-    c:\windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP\WiseData.ini
2010-07-19 11:19 . 2010-07-19 11:19    131991    ----a-w-    c:\windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP\WiseCustomCalla11.dll
2010-07-19 11:19 . 2010-07-19 11:19    130755    ----a-w-    c:\windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP\WiseCustomCalla3.dll
2010-07-19 11:19 . 2010-07-19 11:19    130193    ----a-w-    c:\windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP\WiseCustomCalla4.dll
2010-07-19 11:19 . 2010-07-19 11:19    130112    ----a-w-    c:\windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP\WiseCustomCalla2.dll
2010-07-19 11:19 . 2010-07-19 11:19    131039    ----a-w-    c:\windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP\WiseCustomCalla.exe
2010-07-19 11:19 . 2010-07-19 11:19    27494    ----a-w-    c:\windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP\WiseCustomCall.dll
2010-07-18 21:43 . 2010-07-18 21:43    131991    ----a-w-    c:\windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP\WiseCustomCalla11.exe


------- Sigcheck -------

  • 2010-07-22 . 30A609E00BD1D4FFC49D6B5A432BE7F2 . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
  • 2008-04-14 . 9C88478DFAFF22089045EE3B166C7809 . 1571840 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\0a7e2be7ce3e791e393ff6250f4b2685\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DownloadAccelerator"="c:\programmer\DAP\DAP.EXE" [2009-03-05 2807296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\programmer\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"ACU"="c:\programmer\Atheros\ACU.exe" [2007-05-03 376921]
"SPAMfighter Agent"="c:\programmer\SPAMfighter\SFAgent.exe" [2009-03-12 326792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-26 15360]

c:\documents and settings\Administrator\Menuen Start\Programmer\Start\
Adobe Gamma.lnk - c:\programmer\F‘lles filer\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
PowerReg Scheduler V3.exe [2010-3-7 225280]

[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Menuen Start^Programmer^Start^MagicDisc.lnk]
path=c:\documents and settings\Administrator\Menuen Start\Programmer\Start\MagicDisc.lnk
backup=c:\windows\pss\MagicDisc.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^AutoCAD Startup Accelerator.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\AutoCAD Startup Accelerator.lnk
backup=c:\windows\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 00:04    39792    ----a-w-    c:\programmer\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 10:43    69632    ------r-    c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2004-08-26 16:53    110592    ----a-w-    c:\windows\system32\bthprops.cpl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2004-08-26 15:53    15360    ----a-w-    c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2008-12-29 10:40    687560    ----a-w-    c:\programmer\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator]
2009-03-05 18:56    2807296    ----a-w-    c:\programmer\DAP\DAP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-08-26 17:02    1667584    ------w-    c:\programmer\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2007-07-05 08:08    16380416    ------r-    c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-03-09 18:29    148888    ----a-w-    c:\programmer\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2009-11-13 11:31    247144    ----a-w-    c:\programmer\TomTom HOME 2\TomTomHOMERunner.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\BitLord\\BitLord.exe"=
"c:\\Programmer\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Programmer\\TomTom HOME 2\\xulrunner\\TomTomHOMERuntime.exe"=
"c:\\Programmer\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Programmer\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Programmer\\Autodesk\\Backburner\\manager.exe"=
"c:\\Programmer\\Autodesk\\Backburner\\server.exe"=
"c:\\Programmer\\Autodesk\\3ds Max 2010\\3dsmax.exe"=
"c:\\Programmer\\Autodesk\\3ds Max 2010\\mentalray\\satellite\\raysat_3dsmax2010_32server.exe"=
"c:\\Programmer\\Autodesk\\3ds Max 2010\\mentalray\\satellite\\raysat_3dsmax2010_32.exe"=
"c:\\Documents and Settings\\Administrator\\Skrivebord\\Spil\\Valve\\hl.exe"=
"c:\\Programmer\\Counter-Strike 1.6\\hl.exe"=
"c:\\Programmer\\Atari\\Deer Hunter 2005\\DH2005.exe"=
"c:\\Programmer\\Deer Hunter Tournament\\DHT.exe"=
"c:\\Programmer\\Deer Hunter Tournament\\Updater.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10-02-2009 20:31 717296]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1107000.00C\symds.sys [19-07-2010 19:37 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1107000.00C\symefa.sys [19-07-2010 19:37 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20100709.001\BHDrvx86.sys [19-07-2010 13:12 691248]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1107000.00C\cchpx86.sys [19-07-2010 19:37 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1107000.00C\ironx86.sys [19-07-2010 19:37 116784]
R2 mi-raysat_3dsmax2010_32;mental ray 3.7 Satellite for Autodesk 3ds Max 2010 32-bit 32-bit;c:\programmer\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe [12-03-2009 18:36 86016]
R2 NIS;Norton Internet Security;c:\programmer\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe [19-07-2010 19:36 126392]
R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\programmer\SPAMfighter\sfus.exe [12-03-2009 10:44 184968]
R2 TomTomHOMEService;TomTomHOMEService;c:\programmer\TomTom HOME 2\TomTomHOMEService.exe [13-11-2009 13:31 92008]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\programmer\Fælles filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [19-07-2010 13:11 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100720.001\IDSXpx86.sys [21-07-2010 10:05 331640]
S3 RenameMe;RenameMe;c:\windows\system32\RenameMe.sys [01-05-2010 20:36 8320]
.
Indhold af mappen 'Planlagte Opgaver'

2010-07-22 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-02-28 21:18]
.
.
------- Yderligere scanning -------
.
uStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage
IE: &Clean Traces - c:\programmer\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\programmer\DAP\dapextie.htm
IE: Download &all with DAP - c:\programmer\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: danid.dk
TCP: {2A402FDB-2814-4B8E-BEB1-104BEF3FB5DA} = 208.67.222.222,208.67.220.220
DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} - hxxps://www.portalbank.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.30.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cz60s7nv.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://eu.ask.com?o=15458&l=dis
FF - prefs.js: keyword.URL - hxxp://dk.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_dk&p=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\IPSFFPlgn\components\IPSFFPl.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLITIKKER ----
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type",                  5);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\programmer\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\programmer\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programmer\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programmer\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
c:\programmer\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-22 10:55
Windows 5.1.2600 Service Pack 2 NTFS

scanner skjulte processer ... 

scanner skjulte autostarter ...

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8ADA81F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba10cfc3
\Driver\ACPI -> ACPI.sys @ 0xb9e67cb8
\Driver\atapi -> 0x8ada81f8
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80582414
ParseProcedure -> ntkrnlpa.exe @ 0x80581554
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80582414
ParseProcedure -> ntkrnlpa.exe @ 0x80581554
NDIS: Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xb9c83ba0
PacketIndicateHandler -> NDIS.sys @ 0xb9c72a0b
SendHandler -> NDIS.sys @ 0xb9c86b31
Warning: possible MBR rootkit infection !
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NIS]
"ImagePath"="\"c:\programmer\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe\" /s \"NIS\" /m \"c:\programmer\Norton Internet Security\Engine\17.7.0.12\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs startet under kørende Processer ---------------------

- - - - - - - > 'winlogon.exe'(1272)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2764)
c:\windows\system32\msi.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\brss01a.exe
c:\windows\system32\acs.exe
c:\windows\system32\agrsmsvc.exe
c:\programmer\Fælles filer\Autodata Limited Shared\Service\ADCDLicSvc.exe
c:\windows\system32\crypserv.exe
c:\programmer\Java\jre6\bin\jqs.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Gennemført tid: 2010-07-22  11:00:52 - maskinen blev genstartet
ComboFix-quarantined-files.txt  2010-07-22 09:00
ComboFix2.txt  2010-07-21 11:52
ComboFix3.txt  2010-07-20 11:52

Pre-Kørsel: 148.271.394.816 byte ledig
Post-Kørsel: 148.569.337.856 byte ledig

- - End Of File - - C8EFD9886D4C45DCB490351DF02CA544
Avatar billede f-arn Guru
22. juli 2010 - 22:06 #26
1. Download MBRCheck.exe til dit Skrivebord:

http://ad13.geekstogo.com/MBRCheck.exe

XP brugere -> dobbeltklik på MBRCheck.exe for at køre programmet..
Vista og Windows 7 brugere -> højreklik på MBRCheck.exe og vælg Kør som Administrator.

2. MBRCheck vil nu køre og lægge en log på dit Skrivebord (MBRCheck_dato_tid.txt) som du skal kopiere ind i dit næste indlæg.

3. Hvis MBRCheck finder noget unormalt, så skal du vælge "Y" (for Yes) og herefter vælge Option 1 (for at dumpe mbr koden til fil). Luk herefter programmet ved at taste Enter.

4. Kopier indholdet af log-filen (MBRCheck_dato_tid.txt) ind i dit næste indlæg - så vil vi give videre instruktioner.
Avatar billede dj-bmw Nybegynder
22. juli 2010 - 22:42 #27
MBRCheck, version 1.1.1

(c) 2010, AD



\\.\C: --> \\.\PhysicalDrive0



      Size  Device Name          MBR Status

  --------------------------------------------

    232 GB  \\.\PhysicalDrive0  Unknown MBR code





Found non-standard or infected MBR.

Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Options:

  [1] Dump the MBR of a physical disk to file.

  [2] Restore the MBR of a physical disk with a standard boot code.

  [3] Exit.



Enter your choice: Enter the physical disk number to dump (0-99, -1 to exit):



Done!  Press ENTER to exit...
Avatar billede f-arn Guru
23. juli 2010 - 01:39 #28
Præcis hvilken Computer er det. (mærke og model)
Avatar billede dj-bmw Nybegynder
23. juli 2010 - 09:32 #29
MSI EX610
Avatar billede f-arn Guru
23. juli 2010 - 10:26 #30
Prøv lige at uploade det MBR dump til Jotti eller Virustotal. Jeg vil gerne vide hvad de mener.
Avatar billede dj-bmw Nybegynder
23. juli 2010 - 10:34 #31
altså txt filen?
Avatar billede f-arn Guru
23. juli 2010 - 10:43 #32
3. Hvis MBRCheck finder noget unormalt, så skal du vælge "Y" (for Yes) og herefter vælge Option 1 (for at dumpe mbr koden til fil).

Du lavede vel det MBR dump?
Avatar billede dj-bmw Nybegynder
23. juli 2010 - 10:50 #33
Nå jo..min fejl:

Filename:     dennis
Status:    
Scan finished. 0 out of 19 scanners reported malware.
Scan taken on:      Fri 23 Jul 2010 10:48:06 (CET) Permalink
           
Additional info
File size:     512 bytes
Filetype:     x86 boot sector
MD5:     bab3eaaec543f8d39256b1249f1e8391
SHA1:     763802cac41333e345453b3c57996df824449bd5




Scanners
[ArcaVir]    
2010-07-23 Found nothing
    [G DATA]    
2010-07-23 Found nothing
[Avast! antivirus]    
2010-07-22 Found nothing
    [Ikarus]    
2010-07-23 Found nothing
[Grisoft AVG Anti-Virus]    
2010-07-22 Found nothing
    [Kaspersky Anti-Virus]    
2010-07-23 Found nothing
[Avira AntiVir]    
2010-07-23 Found nothing
    [ESET NOD32]    
2010-07-23 Found nothing
[Softwin BitDefender]    
2010-07-23 Found nothing
    [Panda Antivirus]    
2010-07-22 Found nothing
[ClamAV]    
2010-07-23 Found nothing
    [Quick Heal]    
2010-07-23 Found nothing
[CPsecure]    
2010-07-23 Found nothing
    [Sophos]    
2010-07-23 Found nothing
[Dr.Web]    
2010-07-23 Found nothing
    [VirusBlokAda VBA32]    
2010-07-22 Found nothing
[Frisk F-Prot Antivirus]    
2010-07-22 Found nothing
    [VirusBuster]    
2010-07-22 Found nothing
[F-Secure Anti-Virus]    
2010-07-23 Found nothing
Avatar billede f-arn Guru
23. juli 2010 - 16:32 #34
Fint nok.
Prøv så at slå automatisk opdatering til.
Lad os vide om det virker.

Bemærk at Pr. 13/7 udsendes der ikke længere sikkerhedsopdateringer til XP SP2.
Avatar billede dj-bmw Nybegynder
23. juli 2010 - 17:00 #35
Automatisk opdatering er slået til...skal jeg bruge windows update?
Avatar billede f-arn Guru
23. juli 2010 - 17:14 #36
Ja - gør det.
Avatar billede dj-bmw Nybegynder
23. juli 2010 - 17:15 #37
Og skal jeg opdatere til SP3?
Avatar billede f-arn Guru
23. juli 2010 - 17:31 #38
Ja
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester