Avatar billede bkdideriksen Nybegynder
11. august 2010 - 21:21 Der er 26 kommentarer og
1 løsning

Bankerfox.A,

Hej Eksperter.

Jeg tror at jeg har fået en virus der hedder Bankerfox.A
hvordan fjerner jeg den??

MVH BKK
11. august 2010 - 21:34 #1
Point ude: 1.500 ? ->
http://www.eksperten.dk/list/spoergsmaal/bkdideriksen (Dem der ikke er grønne) bør/skal du gøre noget ved / følge op på / afslutte...

Så får du måske proceduren...

PS:
Win98, ME, W2000, XP, Vista, Win7, OS/2, Unix, Linux, ... ?
Avatar billede bkdideriksen Nybegynder
12. august 2010 - 00:36 #2
holda op hvor det pyntede med alle de grønne lamper!!:-)
Avatar billede bkdideriksen Nybegynder
12. august 2010 - 00:48 #3
her er en log fra fejlsikkertilstand.
jeg kører xp.


ComboFix 10-08-11.04 - Administrator 12-08-2010  0:38.2.2 - x86 NETWORK
Microsoft Windows XP Home Edition  5.1.2600.3.1252.45.1030.18.2047.1620 [GMT 2:00]
Kører fra: F:\ComboFix.exe
.
ADS - WINDOWS: deleted 128 bytes in 1 streams.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\BKK\Lokale indstillinger\Application Data\awkcnafpl
c:\documents and settings\BKK\Lokale indstillinger\Application Data\awkcnafpl\agmboxxtssd.exe

.
(((((((((((((((((((((((((((((  Filer skabt fra 2010-07-11 til 2010-08-11  )))))))))))))))))))))))))))))))))))
.

2010-08-11 21:59 . 2006-10-18 21:02    --------    d--h--w-    c:\documents and settings\Administrator\Printere
2010-08-11 21:59 . 2006-10-18 21:02    --------    d-----w-    c:\documents and settings\Administrator\Skrivebord
2010-08-11 21:59 . 2006-10-18 21:02    --------    d-----r-    c:\documents and settings\Administrator\Menuen Start
2010-08-11 21:59 . 2006-10-18 20:06    --------    d--h--w-    c:\documents and settings\Administrator\Skabeloner
2010-08-11 20:23 . 2010-02-05 07:17    233136    ----a-w-    c:\windows\system32\drivers\pctgntdi.sys
2010-08-11 20:23 . 2010-03-29 08:06    218592    ----a-w-    c:\windows\system32\drivers\PCTCore.sys
2010-08-11 20:23 . 2009-11-23 11:54    88040    ----a-w-    c:\windows\system32\drivers\PCTAppEvent.sys
2010-08-11 20:23 . 2010-04-08 12:29    63360    ----a-w-    c:\windows\system32\drivers\pctplsg.sys
2010-08-11 20:23 . 2010-08-11 22:16    --------    d-----w-    c:\programmer\Spyware Doctor
2010-08-11 20:23 . 2010-08-11 20:24    --------    d-----w-    c:\programmer\Fælles filer\PC Tools
2010-08-11 20:23 . 2010-08-11 20:23    --------    d-----w-    c:\documents and settings\BKK\Application Data\PC Tools
2010-08-11 20:23 . 2010-08-11 20:23    --------    d-----w-    c:\documents and settings\All Users\Application Data\PC Tools
2010-07-27 19:35 . 2010-07-27 19:35    --------    d-----w-    c:\documents and settings\BKK\Lokale indstillinger\Application Data\ArcSoft
2010-07-27 19:34 . 2010-07-29 13:55    --------    d-----w-    c:\documents and settings\All Users\Application Data\ArcSoft
2010-07-27 19:34 . 2006-11-10 13:05    18688    ----a-w-    c:\windows\system32\drivers\afc.sys
2010-07-27 19:32 . 2010-07-27 19:34    --------    d-----w-    c:\programmer\Fælles filer\ArcSoft
2010-07-27 19:32 . 2010-07-27 19:32    --------    d-----w-    c:\programmer\ArcSoft
2010-07-27 19:31 . 2010-07-29 13:55    --------    d-----w-    c:\documents and settings\BKK\Application Data\ArcSoft
2010-07-27 19:14 . 2002-12-11 22:14    80896    -c--a-w-    c:\windows\system32\dllcache\dpvsetup.exe
2010-07-22 19:35 . 2010-07-22 19:35    1615200    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avgssie.dll
2010-07-22 19:35 . 2010-07-22 19:35    1107296    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avgxpl.dll
2010-07-22 19:35 . 2010-07-22 19:35    4368224    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-07-15 18:03 . 2010-07-15 18:03    242896    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2010-07-15 18:03 . 2010-07-15 18:03    216200    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avgldx86.sys
2010-07-15 18:03 . 2010-07-15 18:03    12536    ----a-w-    c:\windows\system32\avgrsstx.dll
2010-07-15 18:00 . 2010-07-15 18:00    1690464    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2010-07-15 18:00 . 2010-07-15 18:00    1038688    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
2010-07-15 18:00 . 2010-07-15 18:00    813336    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avginet.dll
2010-07-15 18:00 . 2010-07-15 18:00    624920    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avgiproxy.exe
2010-07-15 17:56 . 2010-06-14 14:31    744448    -c----w-    c:\windows\system32\dllcache\helpsvc.exe

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-11 22:26 . 2008-12-15 10:22    --------    d-----w-    c:\programmer\Keepit
2010-08-11 22:25 . 2009-12-05 09:12    --------    d-----w-    c:\documents and settings\BKK\Application Data\Dropbox
2010-08-11 22:16 . 2008-05-06 19:42    --------    d---a-w-    c:\documents and settings\All Users\Application Data\TEMP
2010-08-09 11:22 . 2008-11-18 10:11    0    -c--a-w-    c:\documents and settings\BKK\temp.dat
2010-08-07 18:33 . 2002-09-16 12:00    506472    ----a-w-    c:\windows\system32\perfh006.dat
2010-08-07 18:33 . 2002-09-16 12:00    101680    ----a-w-    c:\windows\system32\perfc006.dat
2010-07-27 19:36 . 2006-10-19 18:35    --------    d--h--w-    c:\programmer\InstallShield Installation Information
2010-07-15 20:09 . 2008-08-25 18:18    --------    d-----w-    c:\documents and settings\All Users\Application Data\Microsoft Help
2010-07-15 18:03 . 2008-11-13 10:12    243024    ----a-w-    c:\windows\system32\drivers\avgtdix.sys
2010-07-15 18:03 . 2008-11-13 10:12    216400    ----a-w-    c:\windows\system32\drivers\avgldx86.sys
2010-07-13 17:34 . 2008-05-14 17:33    --------    d-----w-    c:\programmer\AVS4YOU
2010-07-13 17:34 . 2008-05-14 17:34    --------    d-----w-    c:\programmer\Fælles filer\AVSMedia
2010-07-07 19:18 . 2010-07-07 19:14    --------    d-----w-    c:\documents and settings\BKK\Application Data\Nitro PDF
2010-07-07 19:10 . 2010-07-07 19:10    --------    d-----w-    c:\documents and settings\All Users\Application Data\Nitro PDF
2010-07-07 19:10 . 2010-07-07 19:10    --------    d-----w-    c:\programmer\Fælles filer\Nitro PDF
2010-07-07 19:10 . 2010-07-07 19:10    --------    d-----w-    c:\programmer\Nitro PDF
2010-07-07 18:51 . 2010-07-07 18:51    --------    d-----w-    c:\documents and settings\BKK\Application Data\Downloaded Installations
2010-07-07 18:40 . 2010-07-07 18:35    --------    d-----w-    c:\programmer\Movie Player
2010-07-05 19:27 . 2010-07-05 19:27    --------    d-----w-    c:\documents and settings\BKK\Application Data\Seagate
2010-07-03 10:25 . 2010-07-03 10:25    1256    ----a-w-    c:\windows\system32\SpoonUninstall-dBpoweramp m4b Audio book Encoder.dat
2010-07-03 10:22 . 2006-12-27 23:16    349048    ----a-w-    c:\windows\system32\SpoonUninstall.exe
2010-07-03 09:38 . 2010-03-21 19:16    439816    ----a-w-    c:\documents and settings\BKK\Application Data\Real\Update\setup3.10\setup.exe
2010-06-26 20:33 . 2010-06-26 20:33    501936    ----a-w-    c:\documents and settings\All Users\Application Data\Google\Google Toolbar\Update\gtb2F.tmp.exe
2010-06-24 09:09 . 2010-06-24 09:09    65856    ----a-w-    c:\windows\system32\NLSSRV32.EXE
2010-06-24 09:06 . 2010-07-07 19:11    17728    ----a-w-    c:\windows\system32\nitrolocalui.dll
2010-06-24 09:06 . 2010-07-07 19:11    26432    ----a-w-    c:\windows\system32\nitrolocalmon.dll
2010-06-14 18:55 . 2008-11-13 10:12    29584    ----a-w-    c:\windows\system32\drivers\avgmfx86.sys
2010-06-14 18:34 . 2008-11-13 10:12    --------    d-----w-    c:\programmer\AVG
2010-06-14 18:34 . 2010-06-14 18:33    --------    d-----w-    c:\documents and settings\All Users\Application Data\avg9
2010-06-14 18:33 . 2007-06-05 19:20    --------    d-----w-    c:\programmer\Folder Guard Pro
2010-06-14 14:31 . 2006-10-18 20:07    744448    ----a-w-    c:\windows\PCHealth\HelpCtr\Binaries\helpsvc.exe
2009-05-04 18:36 . 2008-11-30 18:20    12208    --sha-w-    c:\windows\system32\KGyGaAvL.sys
.

(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-03 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-03 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-03 118784]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 61952]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-17 16143872]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-09 7561216]
"nwiz"="nwiz.exe" [2006-03-09 1519616]
"BigDogPath"="c:\windows\VM_STI.EXE" [2005-11-30 53248]
"hpfsched"="c:\windows\hpfsched.exe" [1999-03-03 36352]
"PinnacleDriverCheck"="c:\windows\system32\\PSDrvCheck.exe" [2004-03-10 406016]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2002-08-30 188416]
"GrooveMonitor"="c:\programmer\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"TkBellExe"="c:\programmer\Fælles filer\Real\Update_OB\realsched.exe" [2009-10-03 198160]
"BlackArmorBackupMonitor.exe"="c:\programmer\Seagate\BlackArmorBackup\BlackArmorBackupMonitor.exe" [2009-07-23 4352960]
"AcronisTimounterMonitor"="c:\programmer\Seagate\BlackArmorBackup\TimounterMonitor.exe" [2009-07-23 963784]
"Seagate Scheduler2 Service"="c:\programmer\Fælles filer\Seagate\Schedule2\schedhlp.exe" [2009-07-23 376272]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-15 2065760]
"hpqSRMon"="c:\programmer\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"QuickTime Task"="c:\programmer\QuickTime\qttask.exe" [2006-10-30 98304]
"ArcSoft Connection Service"="c:\programmer\Fælles filer\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Menuen Start\Programmer\Start\
Keepit.lnk - c:\windows\Installer\{9C6FCA5D-F758-491E-9A69-F3E418C3784C}\KeepitIcon.exe [2008-12-15 87663]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmer\SUPERAntiSpyware\SASSEH.DLL" [2008-06-09 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-10-03 15:52    548352    ----a-w-    c:\programmer\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-15 18:03    12536    ----a-w-    c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\FolderGuard]
2006-04-19 22:00    94208    ----a-w-    c:\programmer\Folder Guard Pro\FGH32.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^CLS2009.01.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\CLS2009.01.lnk
backup=c:\windows\pss\CLS2009.01.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^EdgeCLS11.00.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\EdgeCLS11.00.lnk
backup=c:\windows\pss\EdgeCLS11.00.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Windows Search.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^BKK^Menuen Start^Programmer^Start^SpywareGuard.lnk]
path=c:\documents and settings\BKK\Menuen Start\Programmer\Start\SpywareGuard.lnk
backup=c:\windows\pss\SpywareGuard.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Watch]
2010-01-27 18:52    788880    ----a-w-    c:\programmer\Lavasoft\Ad-Aware\AAWTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 21:16    39792    -c--a-w-    c:\programmer\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 10:44    31072    ----a-w-    c:\programmer\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 14:24    54840    -c--a-w-    c:\programmer\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
2008-08-20 08:54    150016    -c--a-w-    c:\programmer\HP\Digital Imaging\bin\HpqSRmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-07-26 15:44    3883856    ----a-w-    c:\programmer\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 14:40    155648    ----a-w-    c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2006-03-09 07:29    86016    ----a-w-    c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
2004-03-10 23:26    406016    ----a-w-    c:\windows\system32\PSDrvCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSDrvCheck]
2003-09-12 14:08    406016    -c----w-    c:\programmer\Pinnacle\Instant PhotoAlbum\Programs\PSDrvCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2006-10-30 19:57    98304    -c--a-w-    c:\programmer\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2003-12-08 15:35    32768    -c--a-w-    c:\programmer\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-03-09 03:19    148888    -c--a-w-    c:\programmer\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2009-10-18 07:15    2000112    -c--a-w-    c:\programmer\SUPERAntiSpyware\SUPERANTISPYWARE.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-07-28 10:08    68856    ----a-w-    c:\programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-10-03 05:13    198160    -c--a-w-    c:\programmer\Fælles filer\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Programmer\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Programmer\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Programmer\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmer\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmer\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmer\\Caplio Software\\RGateLXP.exe"=
"c:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\programmer\Microsoft ActiveSync\rapimgr.exe"= c:\programmer\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\programmer\Microsoft ActiveSync\wcescomm.exe"= c:\programmer\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\programmer\Microsoft ActiveSync\WCESMgr.exe"= c:\programmer\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 iteraid;ITERAID_Service_Install;c:\windows\system32\drivers\iteraid.sys [24-10-2006 21:10 24971]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [12-05-2009 19:50 64288]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [11-08-2010 22:23 218592]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [13-11-2008 12:12 243024]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [26-03-2010 14:37 27632]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [13-11-2008 12:12 216400]
S1 SASDIFSV;SASDIFSV;c:\programmer\SUPERAntiSpyware\SASDIFSV.SYS [10-10-2006 13:53 9968]
S1 SASKUTIL;SASKUTIL;c:\programmer\SUPERAntiSpyware\SASKUTIL.SYS [09-01-2007 15:09 74480]
S2 avg9wd;AVG Free WatchDog;c:\programmer\AVG\AVG9\avgwdsvc.exe [15-07-2010 20:03 308136]
S2 FGUARD32;FGUARD32;c:\programmer\Folder Guard Pro\FGUARD32.SYS [05-06-2007 21:20 41472]
S2 gupdate;Tjenesten Google Update (gupdate);c:\programmer\Google\Update\GoogleUpdate.exe [31-01-2010 16:06 135664]
S2 Keepit;Keepit service;c:\programmer\Keepit\0S8F010K.ver\keepit.exe [08-06-2010 20:15 961912]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\programmer\Lavasoft\Ad-Aware\AAWService.exe [24-09-2009 13:17 1181328]
S2 MSSQL$ECSQLEXPRESS;SQL Server (ECSQLEXPRESS);c:\programmer\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [27-05-2009 04:27 29262680]
S2 NitroDriverReadSpool;NitroPDFDriverCreatorReadSpool;c:\programmer\Nitro PDF\Professional\NitroPDFDriverService.exe [24-06-2010 11:08 196928]
S2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [24-06-2010 11:09 65856]
S2 PDRJNDL;PDRJNDL;c:\programmer\Dekart\Private Disk Light\pdrjndl.sys [08-11-2002 09:42 16512]
S2 PRVDISK;PRVDISK;c:\programmer\Dekart\Private Disk Light\prvdisk.sys [08-11-2002 09:42 14080]
S2 SgtSch2Svc;Seagate Scheduler2 Service;c:\programmer\Fælles filer\Seagate\Schedule2\schedul2.exe [23-07-2009 15:31 617968]
S3 29a5472a-34d2-47dc-8861-c86c71dede5c;29a5472a-34d2-47dc-8861-c86c71dede5c;\??\d:\cds300\cds300.dll --> d:\cds300\cds300.dll [?]
S3 SASENUM;SASENUM;c:\programmer\SUPERAntiSpyware\SASENUM.SYS [16-02-2006 17:51 4096]
S3 sdAuxService;PC Tools Auxiliary Service;c:\programmer\Spyware Doctor\pctsAuxs.exe [11-08-2010 22:23 366840]
S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM);c:\windows\system32\drivers\sea1bus.sys [12-07-2010 20:49 61536]
S3 sea1mdfl;Sony Ericsson Device 0A1 USB WMC Modem Filter;c:\windows\system32\drivers\sea1mdfl.sys [12-07-2010 20:49 9360]
S3 sea1mdm;Sony Ericsson Device 0A1 USB WMC Modem Driver;c:\windows\system32\drivers\sea1mdm.sys [12-07-2010 20:49 97088]
S3 sea1mgmt;Sony Ericsson Device 0A1 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\sea1mgmt.sys [12-07-2010 20:49 88624]
S3 sea1nd5;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (NDIS);c:\windows\system32\drivers\sea1nd5.sys [12-07-2010 20:49 18704]
S3 sea1obex;Sony Ericsson Device 0A1 USB WMC OBEX Interface;c:\windows\system32\drivers\sea1obex.sys [12-07-2010 20:49 86432]
S3 sea1unic;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (WDM);c:\windows\system32\drivers\sea1unic.sys [12-07-2010 20:49 90800]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
S3 seusbser;Sony Ericsson USB Device for Legacy Serial Communication;c:\windows\system32\drivers\seusbser.sys [26-03-2010 14:37 113008]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12    REG_MULTI_SZ      Pml Driver HPZ12 Net Driver HPZ12
HPService    REG_MULTI_SZ      HPSLPSVC
hpdevmgmt    REG_MULTI_SZ      hpqcxs08 hpqddsvc
.
Indhold af mappen 'Planlagte Opgaver'

2010-08-11 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
- c:\programmer\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:52]

2010-08-11 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
- c:\programmer\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:52]

2010-08-11 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
- c:\programmer\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:52]

2010-08-11 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
- c:\programmer\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:52]

2010-08-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\programmer\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:52]

2010-08-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2010-01-31 14:06]

2010-08-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2010-01-31 14:06]

2010-08-11 c:\windows\Tasks\User_Feed_Synchronization-{39EDACD7-A621-45D1-A7DF-A060C4544B47}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
------- Yderligere scanning -------
.
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\programmer\Fe6,lles filer\PC Tools\Lsp\PCTLsp.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {9DF01F00-08E7-4DBE-9070-94841463B3FE} - hxxps://danid.dk/csp/authenticode/csp.exe
DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} - hxxps://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
.
.
------- Fil Associationer -------
.
.scr=AutoCADScript
.
- - - - TOMME GENVEJE FJERNET - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file)
HKLM-Run-lbkeqnct - c:\documents and settings\BKK\Lokale indstillinger\Application Data\awkcnafpl\agmboxxtssd.exe
MSConfigStartUp-Adobe Photo Downloader - c:\programmer\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
MSConfigStartUp-ExtraFilmHemmaAgent - c:\programmer\ExtraFilm Hjemme\Agent.exe
MSConfigStartUp-Lexmark X1100 Series - c:\programmer\Lexmark X1100 Series\lxbkbmgr.exe



**************************************************************************
scanner skjulte processer ... 

scanner skjulte autostarter ...

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer:

**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------

[HKEY_USERS\S-1-5-21-329068152-179605362-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
  d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,30,dc,54,ff,ce,17,c1,44,a0,94,54,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
  d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,30,dc,54,ff,ce,17,c1,44,a0,94,54,\

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"
@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"NoChange"="1"
"Installed"="1"
@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
@=""
.
--------------------- DLLs startet under kørende Processer ---------------------

- - - - - - - > 'winlogon.exe'(756)
c:\programmer\SUPERAntiSpyware\SASWINLO.DLL
.
Gennemført tid: 2010-08-12  00:43:36
ComboFix-quarantined-files.txt  2010-08-11 22:43
ComboFix2.txt  2007-11-01 18:47

Pre-Kørsel: 66.062.995.456 byte ledig
Post-Kørsel: 66.458.304.512 byte ledig

WindowsXP-KB310994-SP2-Home-BootDisk-DAN.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

- - End Of File - - 55C2B2E40E93729D31225B9BA6D9A167
Avatar billede bkdideriksen Nybegynder
12. august 2010 - 01:15 #4
her er lige en log efter normal opstart.



ComboFix 10-08-11.04 - BKK 12-08-2010  1:04.3.2 - x86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.45.1030.18.2047.1401 [GMT 2:00]
Kører fra: F:\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

(((((((((((((((((((((((((((((  Filer skabt fra 2010-07-11 til 2010-08-11  )))))))))))))))))))))))))))))))))))
.

2010-08-11 23:01 . 2010-08-11 23:01    --------    d-----w-    c:\documents and settings\BKK\Application Data\AVG9
2010-08-11 22:14 . 2010-08-11 22:14    --------    d-sh--w-    c:\documents and settings\Administrator\PrivacIE
2010-08-11 20:23 . 2010-02-05 07:17    233136    ----a-w-    c:\windows\system32\drivers\pctgntdi.sys
2010-08-11 20:23 . 2010-03-29 08:06    218592    ----a-w-    c:\windows\system32\drivers\PCTCore.sys
2010-08-11 20:23 . 2009-11-23 11:54    88040    ----a-w-    c:\windows\system32\drivers\PCTAppEvent.sys
2010-08-11 20:23 . 2010-04-08 12:29    63360    ----a-w-    c:\windows\system32\drivers\pctplsg.sys
2010-08-11 20:23 . 2010-08-11 22:16    --------    d-----w-    c:\programmer\Spyware Doctor
2010-08-11 20:23 . 2010-08-11 20:24    --------    d-----w-    c:\programmer\Fælles filer\PC Tools
2010-08-11 20:23 . 2010-08-11 20:23    --------    d-----w-    c:\documents and settings\BKK\Application Data\PC Tools
2010-08-11 20:23 . 2010-08-11 20:23    --------    d-----w-    c:\documents and settings\All Users\Application Data\PC Tools
2010-07-27 19:35 . 2010-07-27 19:35    --------    d-----w-    c:\documents and settings\BKK\Lokale indstillinger\Application Data\ArcSoft
2010-07-27 19:34 . 2010-07-29 13:55    --------    d-----w-    c:\documents and settings\All Users\Application Data\ArcSoft
2010-07-27 19:34 . 2006-11-10 13:05    18688    ----a-w-    c:\windows\system32\drivers\afc.sys
2010-07-27 19:32 . 2010-07-27 19:34    --------    d-----w-    c:\programmer\Fælles filer\ArcSoft
2010-07-27 19:32 . 2010-07-27 19:32    --------    d-----w-    c:\programmer\ArcSoft
2010-07-27 19:31 . 2010-07-29 13:55    --------    d-----w-    c:\documents and settings\BKK\Application Data\ArcSoft
2010-07-27 19:14 . 2002-12-11 22:14    80896    -c--a-w-    c:\windows\system32\dllcache\dpvsetup.exe
2010-07-22 19:35 . 2010-07-22 19:35    1615200    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avgssie.dll
2010-07-22 19:35 . 2010-07-22 19:35    1107296    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avgxpl.dll
2010-07-22 19:35 . 2010-07-22 19:35    4368224    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-07-15 18:03 . 2010-07-15 18:03    242896    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2010-07-15 18:03 . 2010-07-15 18:03    216200    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avgldx86.sys
2010-07-15 18:03 . 2010-07-15 18:03    12536    ----a-w-    c:\windows\system32\avgrsstx.dll
2010-07-15 18:00 . 2010-07-15 18:00    1690464    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2010-07-15 18:00 . 2010-07-15 18:00    1038688    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
2010-07-15 18:00 . 2010-07-15 18:00    813336    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avginet.dll
2010-07-15 18:00 . 2010-07-15 18:00    624920    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avgiproxy.exe
2010-07-15 17:56 . 2010-06-14 14:31    744448    -c----w-    c:\windows\system32\dllcache\helpsvc.exe

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-11 23:05 . 2008-12-15 10:22    --------    d-----w-    c:\programmer\Keepit
2010-08-11 22:55 . 2002-09-16 12:00    506472    ----a-w-    c:\windows\system32\perfh006.dat
2010-08-11 22:55 . 2002-09-16 12:00    101680    ----a-w-    c:\windows\system32\perfc006.dat
2010-08-11 22:51 . 2009-12-05 09:12    --------    d-----w-    c:\documents and settings\BKK\Application Data\Dropbox
2010-08-11 22:16 . 2008-05-06 19:42    --------    d---a-w-    c:\documents and settings\All Users\Application Data\TEMP
2010-08-09 11:22 . 2008-11-18 10:11    0    -c--a-w-    c:\documents and settings\BKK\temp.dat
2010-07-27 19:36 . 2006-10-19 18:35    --------    d--h--w-    c:\programmer\InstallShield Installation Information
2010-07-15 20:09 . 2008-08-25 18:18    --------    d-----w-    c:\documents and settings\All Users\Application Data\Microsoft Help
2010-07-15 18:03 . 2008-11-13 10:12    243024    ----a-w-    c:\windows\system32\drivers\avgtdix.sys
2010-07-15 18:03 . 2008-11-13 10:12    216400    ----a-w-    c:\windows\system32\drivers\avgldx86.sys
2010-07-13 17:34 . 2008-05-14 17:33    --------    d-----w-    c:\programmer\AVS4YOU
2010-07-13 17:34 . 2008-05-14 17:34    --------    d-----w-    c:\programmer\Fælles filer\AVSMedia
2010-07-07 19:18 . 2010-07-07 19:14    --------    d-----w-    c:\documents and settings\BKK\Application Data\Nitro PDF
2010-07-07 19:10 . 2010-07-07 19:10    --------    d-----w-    c:\documents and settings\All Users\Application Data\Nitro PDF
2010-07-07 19:10 . 2010-07-07 19:10    --------    d-----w-    c:\programmer\Fælles filer\Nitro PDF
2010-07-07 19:10 . 2010-07-07 19:10    --------    d-----w-    c:\programmer\Nitro PDF
2010-07-07 18:51 . 2010-07-07 18:51    --------    d-----w-    c:\documents and settings\BKK\Application Data\Downloaded Installations
2010-07-07 18:40 . 2010-07-07 18:35    --------    d-----w-    c:\programmer\Movie Player
2010-07-05 19:27 . 2010-07-05 19:27    --------    d-----w-    c:\documents and settings\BKK\Application Data\Seagate
2010-07-03 10:25 . 2010-07-03 10:25    1256    ----a-w-    c:\windows\system32\SpoonUninstall-dBpoweramp m4b Audio book Encoder.dat
2010-07-03 10:22 . 2006-12-27 23:16    349048    ----a-w-    c:\windows\system32\SpoonUninstall.exe
2010-07-03 09:38 . 2010-03-21 19:16    439816    ----a-w-    c:\documents and settings\BKK\Application Data\Real\Update\setup3.10\setup.exe
2010-06-26 20:33 . 2010-06-26 20:33    501936    ----a-w-    c:\documents and settings\All Users\Application Data\Google\Google Toolbar\Update\gtb2F.tmp.exe
2010-06-24 09:09 . 2010-06-24 09:09    65856    ----a-w-    c:\windows\system32\NLSSRV32.EXE
2010-06-24 09:06 . 2010-07-07 19:11    17728    ----a-w-    c:\windows\system32\nitrolocalui.dll
2010-06-24 09:06 . 2010-07-07 19:11    26432    ----a-w-    c:\windows\system32\nitrolocalmon.dll
2010-06-14 18:55 . 2008-11-13 10:12    29584    ----a-w-    c:\windows\system32\drivers\avgmfx86.sys
2010-06-14 18:34 . 2008-11-13 10:12    --------    d-----w-    c:\programmer\AVG
2010-06-14 18:34 . 2010-06-14 18:33    --------    d-----w-    c:\documents and settings\All Users\Application Data\avg9
2010-06-14 18:33 . 2007-06-05 19:20    --------    d-----w-    c:\programmer\Folder Guard Pro
2010-06-14 14:31 . 2006-10-18 20:07    744448    ----a-w-    c:\windows\PCHealth\HelpCtr\Binaries\helpsvc.exe
2009-05-04 18:36 . 2008-11-30 18:20    12208    --sha-w-    c:\windows\system32\KGyGaAvL.sys
.

(((((((((((((((((((((((((((((  SnapShot@2010-08-11_22.42.30  )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-08-11 22:51 . 2010-08-11 22:51    16384              c:\windows\temp\Perflib_Perfdata_6ac.dat
+ 2002-09-16 12:00 . 2010-08-11 22:55    90236              c:\windows\system32\perfc009.dat
- 2002-09-16 12:00 . 2010-08-07 18:33    90236              c:\windows\system32\perfc009.dat
+ 2002-09-16 12:00 . 2010-08-11 22:55    491306              c:\windows\system32\perfh009.dat
- 2002-09-16 12:00 . 2010-08-07 18:33    491306              c:\windows\system32\perfh009.dat
.
(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-28 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-03 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-03 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-03 118784]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 61952]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-17 16143872]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-09 7561216]
"nwiz"="nwiz.exe" [2006-03-09 1519616]
"BigDogPath"="c:\windows\VM_STI.EXE" [2005-11-30 53248]
"hpfsched"="c:\windows\hpfsched.exe" [1999-03-03 36352]
"PinnacleDriverCheck"="c:\windows\system32\\PSDrvCheck.exe" [2004-03-10 406016]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2002-08-30 188416]
"GrooveMonitor"="c:\programmer\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"TkBellExe"="c:\programmer\Fælles filer\Real\Update_OB\realsched.exe" [2009-10-03 198160]
"BlackArmorBackupMonitor.exe"="c:\programmer\Seagate\BlackArmorBackup\BlackArmorBackupMonitor.exe" [2009-07-23 4352960]
"AcronisTimounterMonitor"="c:\programmer\Seagate\BlackArmorBackup\TimounterMonitor.exe" [2009-07-23 963784]
"Seagate Scheduler2 Service"="c:\programmer\Fælles filer\Seagate\Schedule2\schedhlp.exe" [2009-07-23 376272]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-15 2065760]
"hpqSRMon"="c:\programmer\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"QuickTime Task"="c:\programmer\QuickTime\qttask.exe" [2006-10-30 98304]
"ArcSoft Connection Service"="c:\programmer\Fælles filer\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\BKK\Menuen Start\Programmer\Start\
Dropbox.lnk - c:\documents and settings\BKK\Application Data\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]

c:\documents and settings\All Users\Menuen Start\Programmer\Start\
Keepit.lnk - c:\windows\Installer\{9C6FCA5D-F758-491E-9A69-F3E418C3784C}\KeepitIcon.exe [2008-12-15 87663]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmer\SUPERAntiSpyware\SASSEH.DLL" [2008-06-09 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-10-03 15:52    548352    ----a-w-    c:\programmer\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-15 18:03    12536    ----a-w-    c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\FolderGuard]
2006-04-19 22:00    94208    ----a-w-    c:\programmer\Folder Guard Pro\FGH32.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^CLS2009.01.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\CLS2009.01.lnk
backup=c:\windows\pss\CLS2009.01.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^EdgeCLS11.00.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\EdgeCLS11.00.lnk
backup=c:\windows\pss\EdgeCLS11.00.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Windows Search.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^BKK^Menuen Start^Programmer^Start^SpywareGuard.lnk]
path=c:\documents and settings\BKK\Menuen Start\Programmer\Start\SpywareGuard.lnk
backup=c:\windows\pss\SpywareGuard.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Watch]
2010-01-27 18:52    788880    ----a-w-    c:\programmer\Lavasoft\Ad-Aware\AAWTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 21:16    39792    -c--a-w-    c:\programmer\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 10:44    31072    ----a-w-    c:\programmer\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 14:24    54840    -c--a-w-    c:\programmer\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
2008-08-20 08:54    150016    -c--a-w-    c:\programmer\HP\Digital Imaging\bin\HpqSRmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-07-26 15:44    3883856    ----a-w-    c:\programmer\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 14:40    155648    ----a-w-    c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2006-03-09 07:29    86016    ----a-w-    c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
2004-03-10 23:26    406016    ----a-w-    c:\windows\system32\PSDrvCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSDrvCheck]
2003-09-12 14:08    406016    -c----w-    c:\programmer\Pinnacle\Instant PhotoAlbum\Programs\PSDrvCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2006-10-30 19:57    98304    -c--a-w-    c:\programmer\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2003-12-08 15:35    32768    -c--a-w-    c:\programmer\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-03-09 03:19    148888    -c--a-w-    c:\programmer\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2009-10-18 07:15    2000112    -c--a-w-    c:\programmer\SUPERAntiSpyware\SUPERANTISPYWARE.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-07-28 10:08    68856    ----a-w-    c:\programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-10-03 05:13    198160    -c--a-w-    c:\programmer\Fælles filer\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Programmer\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Programmer\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Programmer\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmer\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmer\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmer\\Caplio Software\\RGateLXP.exe"=
"c:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\programmer\Microsoft ActiveSync\rapimgr.exe"= c:\programmer\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\programmer\Microsoft ActiveSync\wcescomm.exe"= c:\programmer\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\programmer\Microsoft ActiveSync\WCESMgr.exe"= c:\programmer\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Documents and Settings\\BKK\\Application Data\\Dropbox\\bin\\Dropbox.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 iteraid;ITERAID_Service_Install;c:\windows\system32\drivers\iteraid.sys [24-10-2006 21:10 24971]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [12-05-2009 19:50 64288]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [11-08-2010 22:23 218592]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [13-11-2008 12:12 216400]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [13-11-2008 12:12 243024]
R1 SASDIFSV;SASDIFSV;c:\programmer\SUPERAntiSpyware\SASDIFSV.SYS [10-10-2006 13:53 9968]
R1 SASKUTIL;SASKUTIL;c:\programmer\SUPERAntiSpyware\SASKUTIL.SYS [09-01-2007 15:09 74480]
R2 avg9wd;AVG Free WatchDog;c:\programmer\AVG\AVG9\avgwdsvc.exe [15-07-2010 20:03 308136]
R2 FGUARD32;FGUARD32;c:\programmer\Folder Guard Pro\FGUARD32.SYS [05-06-2007 21:20 41472]
R2 Keepit;Keepit service;c:\programmer\Keepit\0S8F010K.ver\keepit.exe [08-06-2010 20:15 961912]
R2 MSSQL$ECSQLEXPRESS;SQL Server (ECSQLEXPRESS);c:\programmer\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [27-05-2009 04:27 29262680]
R2 NitroDriverReadSpool;NitroPDFDriverCreatorReadSpool;c:\programmer\Nitro PDF\Professional\NitroPDFDriverService.exe [24-06-2010 11:08 196928]
R2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [24-06-2010 11:09 65856]
R2 PDRJNDL;PDRJNDL;c:\programmer\Dekart\Private Disk Light\pdrjndl.sys [08-11-2002 09:42 16512]
R2 PRVDISK;PRVDISK;c:\programmer\Dekart\Private Disk Light\prvdisk.sys [08-11-2002 09:42 14080]
R2 SgtSch2Svc;Seagate Scheduler2 Service;c:\programmer\Fælles filer\Seagate\Schedule2\schedul2.exe [23-07-2009 15:31 617968]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [26-03-2010 14:37 27632]
S2 gupdate;Tjenesten Google Update (gupdate);c:\programmer\Google\Update\GoogleUpdate.exe [31-01-2010 16:06 135664]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\programmer\Lavasoft\Ad-Aware\AAWService.exe [24-09-2009 13:17 1181328]
S3 29a5472a-34d2-47dc-8861-c86c71dede5c;29a5472a-34d2-47dc-8861-c86c71dede5c;\??\d:\cds300\cds300.dll --> d:\cds300\cds300.dll [?]
S3 SASENUM;SASENUM;c:\programmer\SUPERAntiSpyware\SASENUM.SYS [16-02-2006 17:51 4096]
S3 sdAuxService;PC Tools Auxiliary Service;c:\programmer\Spyware Doctor\pctsAuxs.exe [11-08-2010 22:23 366840]
S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM);c:\windows\system32\drivers\sea1bus.sys [12-07-2010 20:49 61536]
S3 sea1mdfl;Sony Ericsson Device 0A1 USB WMC Modem Filter;c:\windows\system32\drivers\sea1mdfl.sys [12-07-2010 20:49 9360]
S3 sea1mdm;Sony Ericsson Device 0A1 USB WMC Modem Driver;c:\windows\system32\drivers\sea1mdm.sys [12-07-2010 20:49 97088]
S3 sea1mgmt;Sony Ericsson Device 0A1 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\sea1mgmt.sys [12-07-2010 20:49 88624]
S3 sea1nd5;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (NDIS);c:\windows\system32\drivers\sea1nd5.sys [12-07-2010 20:49 18704]
S3 sea1obex;Sony Ericsson Device 0A1 USB WMC OBEX Interface;c:\windows\system32\drivers\sea1obex.sys [12-07-2010 20:49 86432]
S3 sea1unic;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (WDM);c:\windows\system32\drivers\sea1unic.sys [12-07-2010 20:49 90800]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
S3 seusbser;Sony Ericsson USB Device for Legacy Serial Communication;c:\windows\system32\drivers\seusbser.sys [26-03-2010 14:37 113008]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12    REG_MULTI_SZ      Pml Driver HPZ12 Net Driver HPZ12
HPService    REG_MULTI_SZ      HPSLPSVC
hpdevmgmt    REG_MULTI_SZ      hpqcxs08 hpqddsvc
.
Indhold af mappen 'Planlagte Opgaver'

2010-08-11 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
- c:\programmer\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:52]

2010-08-11 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
- c:\programmer\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:52]

2010-08-11 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
- c:\programmer\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:52]

2010-08-11 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
- c:\programmer\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:52]

2010-08-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\programmer\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:52]

2010-08-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2010-01-31 14:06]

2010-08-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2010-01-31 14:06]

2010-08-11 c:\windows\Tasks\User_Feed_Synchronization-{39EDACD7-A621-45D1-A7DF-A060C4544B47}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
------- Yderligere scanning -------
.
uStart Page = hxxp://www.google.dk/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyServer = http=127.0.0.1:6522
uInternet Settings,ProxyOverride = <local>
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki ... - c:\programmer\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
LSP: c:\programmer\Fe6,lles filer\PC Tools\Lsp\PCTLsp.dll
Trusted Zone: danid.dk
Trusted Zone: landbobanken.dk\portal4.erhverv
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {9DF01F00-08E7-4DBE-9070-94841463B3FE} - hxxps://danid.dk/csp/authenticode/csp.exe
DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} - hxxps://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
.
.
------- Fil Associationer -------
.
.scr=AutoCADScript
.
- - - - TOMME GENVEJE FJERNET - - - -

URLSearchHooks-CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
URLSearchHooks-b69a9db4-d0a1-4722-b56b-f20757a29cdf} - (no file)
HKCU-Run-lbkeqnct - c:\documents and settings\BKK\Lokale indstillinger\Application Data\awkcnafpl\agmboxxtssd.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-12 01:10
Windows 5.1.2600 Service Pack 3 NTFS

scanner skjulte processer ... 

scanner skjulte autostarter ...

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer: 0

**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"
@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"NoChange"="1"
"Installed"="1"
@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
@=""
.
--------------------- DLLs startet under kørende Processer ---------------------

- - - - - - - > 'winlogon.exe'(848)
c:\programmer\SUPERAntiSpyware\SASWINLO.DLL

- - - - - - - > 'lsass.exe'(904)
c:\programmer\Fælles filer\PC Tools\Lsp\PCTLsp.dll

- - - - - - - > 'explorer.exe'(2484)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Gennemført tid: 2010-08-12  01:12:48
ComboFix-quarantined-files.txt  2010-08-11 23:12
ComboFix2.txt  2010-08-11 22:43
ComboFix3.txt  2007-11-01 18:47

Pre-Kørsel: 66.311.319.552 byte ledig
Post-Kørsel: 66.345.697.280 byte ledig

- - End Of File - - 46CFB5AB8688E8A54A0EC43CE478045E
Avatar billede bkdideriksen Nybegynder
12. august 2010 - 01:18 #5
jeg har brugt denne træd så langt som til nu.....
http://www.eksperten.dk/spm/906483
12. august 2010 - 08:55 #6
... og MalwareBytes delen / loggen ?

Samt en Log fra HiJackThis ?
Avatar billede bkdideriksen Nybegynder
12. august 2010 - 21:43 #7
Det er jeg ved nu.
Jeg kan ikke bruge min explorer til at surfe på, så jeg henter det 2 programmer fra en anden pc.
Er lige ved at scanne med malwarebytes, den kan godt opdatere.
kan jeg godt lægge hijack this ind nu eller skal jeg vente til den er færdig med at scanne?
12. august 2010 - 21:57 #8
Efter MalwareBytes + evt. genstart...
Avatar billede bkdideriksen Nybegynder
12. august 2010 - 22:21 #9
her er malwarebtes
den kommer om lidt


Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4422

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

12-08-2010 22:17:08
mbam-log-2010-08-12 (22-17-08)the boss.txt

Skanningstype: Fuldstændig skanning (C:\|G:\|)
Objekter skannet: 265131
Tid gået: 1 time(e), 13 minut(ter), 57 sekund(er)

Hukommelses Processorer Inficeret: 0
Hukommelses Moduler Inficeret: 0
Registreringsdatabasenøgler Inficeret: 0
Registreringsdatabaseværdier Inficeret: 2
Registreringsdatabasedata Objekter Inficeret: 0
Inficerede Mapper: 0
Inficerede Filer: 4

Hukommelses Processorer Inficeret:
(Ingen skadelige objekter blev fundet)

Hukommelses Moduler Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabasenøgler Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabaseværdier Inficeret:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hpfsched (Trojan.FakeAlert.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3popularscreensavers (Adware.MyWebSearch) -> No action taken.

Registreringsdatabasedata Objekter Inficeret:
(Ingen skadelige objekter blev fundet)

Inficerede Mapper:
(Ingen skadelige objekter blev fundet)

Inficerede Filer:
C:\WINDOWS\hpfsched.exe (Trojan.FakeAlert.H) -> No action taken.
C:\qoobox\Quarantine\C\Documents and Settings\BKK\Lokale indstillinger\Application Data\awkcnafpl\agmboxxtssd.exe.vir (Malware.Packer.Gen) -> No action taken.
C:\WINDOWS\system32\fccrj8x.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\mi7xsq5.dll (Trojan.FakeAlert) -> No action taken.
Avatar billede bkdideriksen Nybegynder
12. august 2010 - 22:26 #10
så er det sidste, vil ZZZZZZZZZZZZz tak for nu


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:24:06, on 12-08-2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Lavasoft\Ad-Aware\AAWService.exe
C:\Programmer\AVG\AVG9\avgchsvx.exe
C:\Programmer\AVG\AVG9\avgrsx.exe
C:\Programmer\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\ArcSoft\Connection Service\Bin\ACService.exe
C:\Programmer\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\Programmer\Keepit\8EV6F5N.ver\keepit.exe
C:\Programmer\AVG\AVG9\avgnsx.exe
C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Nitro PDF\Professional\NitroPDFDriverService.exe
C:\WINDOWS\system32\NLSSRV32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Seagate\Schedule2\schedul2.exe
c:\Programmer\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\FOLDER~1\FGKey.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\VM_STI.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\Seagate\BlackArmorBackup\BlackArmorBackupMonitor.exe
C:\Programmer\Seagate\BlackArmorBackup\TimounterMonitor.exe
C:\Programmer\Fælles filer\Seagate\Schedule2\schedhlp.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Programmer\HP\Digital Imaging\bin\hpqSRMon.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Fælles filer\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Programmer\Fælles filer\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\Microsoft ActiveSync\Wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Documents and Settings\BKK\Application Data\Dropbox\bin\Dropbox.exe
C:\Programmer\Keepit\8EV6F5N.ver\gui.exe
C:\Programmer\Lavasoft\Ad-Aware\AAWTray.exe
C:\Programmer\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmer\AVG\AVG9\avgssie.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Programmer\SpywareGuard\dlprotect.dll
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programmer\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: Live TV Toolbar - {b69a9db4-d0a1-4722-b56b-f20757a29cdf} - C:\Programmer\Live_TV\tbLive.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmer\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Live TV Toolbar - {b69a9db4-d0a1-4722-b56b-f20757a29cdf} - C:\Programmer\Live_TV\tbLive.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programmer\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE USB PC Web Camera
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [BlackArmorBackupMonitor.exe] C:\Programmer\Seagate\BlackArmorBackup\BlackArmorBackupMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Programmer\Seagate\BlackArmorBackup\TimounterMonitor.exe
O4 - HKLM\..\Run: [Seagate Scheduler2 Service] "C:\Programmer\Fælles filer\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Programmer\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Programmer\Fælles filer\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKCU\..\Run: [swg] "C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Dropbox.lnk = C:\Documents and Settings\BKK\Application Data\Dropbox\bin\Dropbox.exe
O4 - Global Startup: Keepit.lnk = ?
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki ... - res://C:\Programmer\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart markering - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Programmer\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {01111C00-3E00-11D2-8470-0060089874ED} (Support.com ActionRunner Class) - https://netsupport2.tdconline.dk/sdccommon/download/tgctlar.cab
O16 - DPF: {01111E00-3E00-11D2-8470-0060089874ED} (Support.com SmartIssue) - https://netsupport2.tdconline.dk/sdccommon/download/tgctlsi.cab
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.extrafilm.dk/ImageUploader5.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1161885665921
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.click4foto.dk/aurigma/ImageUploader4.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9DF01F00-08E7-4DBE-9070-94841463B3FE} (Util Class) - https://danid.dk/csp/authenticode/csp.exe
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.0 Control) - https://ssl.extrafilm.org/upload/activex/ImageUploader3.cab
O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.dk/ImageUploader4.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programmer\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmer\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Programmer\Fælles filer\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Programmer\AVG\AVG9\avgwdsvc.exe
O23 - Service: Tjenesten Google Update (gupdate) (gupdate) - Google Inc. - C:\Programmer\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmer\Java\jre6\bin\jqs.exe
O23 - Service: Keepit service (Keepit) - Unknown owner - C:\Programmer\Keepit\8EV6F5N.ver\keepit.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Programmer\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
O23 - Service: NitroPDFDriverCreatorReadSpool (NitroDriverReadSpool) - Nitro PDF Software - C:\Programmer\Nitro PDF\Professional\NitroPDFDriverService.exe
O23 - Service: NLS Service (nlsX86cc) - Nalpeiron Ltd. - C:\WINDOWS\system32\NLSSRV32.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Programmer\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Programmer\Spyware Doctor\pctsSvc.exe
O23 - Service: Seagate Scheduler2 Service (SgtSch2Svc) - Seagate - C:\Programmer\Fælles filer\Seagate\Schedule2\schedul2.exe

--
End of file - 12851 bytes
12. august 2010 - 22:32 #11
Ifølge MalwareBytes loggen fra dig -> No action taken. !!!

Du glemte denne 'detalje' ->
Klik "Vis resultater" knappen når den er færdig og derefter klik på "Fjern det valgte". - - - så om igen med MalwareBytes ...
Avatar billede bkdideriksen Nybegynder
13. august 2010 - 18:05 #12
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4422

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

13-08-2010 16:58:14
mbam-log-2010-08-13 (16-58-14).txt

Skanningstype: Fuldstændig skanning (C:\|G:\|)
Objekter skannet: 264848
Tid gået: 1 time(e), 1 minut(ter), 26 sekund(er)

Hukommelses Processorer Inficeret: 0
Hukommelses Moduler Inficeret: 0
Registreringsdatabasenøgler Inficeret: 0
Registreringsdatabaseværdier Inficeret: 0
Registreringsdatabasedata Objekter Inficeret: 0
Inficerede Mapper: 0
Inficerede Filer: 0

Hukommelses Processorer Inficeret:
(Ingen skadelige objekter blev fundet)

Hukommelses Moduler Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabasenøgler Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabaseværdier Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabasedata Objekter Inficeret:
(Ingen skadelige objekter blev fundet)

Inficerede Mapper:
(Ingen skadelige objekter blev fundet)

Inficerede Filer:
(Ingen skadelige objekter blev fundet)
Avatar billede bkdideriksen Nybegynder
13. august 2010 - 18:05 #13
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:55:43, on 13-08-2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Lavasoft\Ad-Aware\AAWService.exe
C:\Programmer\AVG\AVG9\avgchsvx.exe
C:\Programmer\AVG\AVG9\avgrsx.exe
C:\Programmer\AVG\AVG9\avgcsrvx.exe
C:\PROGRA~1\FOLDER~1\FGKey.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Fælles filer\ArcSoft\Connection Service\Bin\ACService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programmer\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\VM_STI.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\Programmer\Seagate\BlackArmorBackup\BlackArmorBackupMonitor.exe
C:\Programmer\Keepit\8EV6F5N.ver\keepit.exe
C:\Programmer\Seagate\BlackArmorBackup\TimounterMonitor.exe
C:\Programmer\Fælles filer\Seagate\Schedule2\schedhlp.exe
C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
C:\Programmer\AVG\AVG9\avgnsx.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Programmer\HP\Digital Imaging\bin\hpqSRMon.exe
C:\Programmer\Fælles filer\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\Microsoft ActiveSync\Wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Programmer\Nitro PDF\Professional\NitroPDFDriverService.exe
C:\WINDOWS\system32\NLSSRV32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Seagate\Schedule2\schedul2.exe
c:\Programmer\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Programmer\Lavasoft\Ad-Aware\AAWTray.exe
C:\Programmer\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmer\AVG\AVG9\avgssie.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Programmer\SpywareGuard\dlprotect.dll
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programmer\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: Live TV Toolbar - {b69a9db4-d0a1-4722-b56b-f20757a29cdf} - C:\Programmer\Live_TV\tbLive.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmer\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Live TV Toolbar - {b69a9db4-d0a1-4722-b56b-f20757a29cdf} - C:\Programmer\Live_TV\tbLive.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programmer\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE USB PC Web Camera
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [BlackArmorBackupMonitor.exe] C:\Programmer\Seagate\BlackArmorBackup\BlackArmorBackupMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Programmer\Seagate\BlackArmorBackup\TimounterMonitor.exe
O4 - HKLM\..\Run: [Seagate Scheduler2 Service] "C:\Programmer\Fælles filer\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Programmer\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Programmer\Fælles filer\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKCU\..\Run: [swg] "C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Dropbox.lnk = C:\Documents and Settings\BKK\Application Data\Dropbox\bin\Dropbox.exe
O4 - Global Startup: Keepit.lnk = ?
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki ... - res://C:\Programmer\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart markering - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Programmer\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {01111C00-3E00-11D2-8470-0060089874ED} (Support.com ActionRunner Class) - https://netsupport2.tdconline.dk/sdccommon/download/tgctlar.cab
O16 - DPF: {01111E00-3E00-11D2-8470-0060089874ED} (Support.com SmartIssue) - https://netsupport2.tdconline.dk/sdccommon/download/tgctlsi.cab
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.extrafilm.dk/ImageUploader5.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1161885665921
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.click4foto.dk/aurigma/ImageUploader4.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9DF01F00-08E7-4DBE-9070-94841463B3FE} (Util Class) - https://danid.dk/csp/authenticode/csp.exe
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.0 Control) - https://ssl.extrafilm.org/upload/activex/ImageUploader3.cab
O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.dk/ImageUploader4.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programmer\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmer\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Programmer\Fælles filer\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Programmer\AVG\AVG9\avgwdsvc.exe
O23 - Service: Tjenesten Google Update (gupdate) (gupdate) - Google Inc. - C:\Programmer\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmer\Java\jre6\bin\jqs.exe
O23 - Service: Keepit service (Keepit) - Unknown owner - C:\Programmer\Keepit\8EV6F5N.ver\keepit.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Programmer\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
O23 - Service: NitroPDFDriverCreatorReadSpool (NitroDriverReadSpool) - Nitro PDF Software - C:\Programmer\Nitro PDF\Professional\NitroPDFDriverService.exe
O23 - Service: NLS Service (nlsX86cc) - Nalpeiron Ltd. - C:\WINDOWS\system32\NLSSRV32.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Programmer\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Programmer\Spyware Doctor\pctsSvc.exe
O23 - Service: Seagate Scheduler2 Service (SgtSch2Svc) - Seagate - C:\Programmer\Fælles filer\Seagate\Schedule2\schedul2.exe

--
End of file - 12668 bytes
Avatar billede bkdideriksen Nybegynder
13. august 2010 - 18:10 #14
det skulle vist være rigtigt denne gang..
13. august 2010 - 21:10 #15
Nemlig - og hvordan kører 'dyret' så nu ?
Avatar billede bkdideriksen Nybegynder
14. august 2010 - 09:21 #16
alting virker normalt på nær min internet Explor kommer ikke på nette, er det noget du ved noget om også??
14. august 2010 - 09:31 #17
Er det sket efter ovenstående procedure ?
Eller har det været sådan længe ?
Avatar billede sullep Nybegynder
14. august 2010 - 09:44 #18
Kør Hijackthis, på menuen der kommer op, klikker du på: Do a system scan only.
Scan, sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked.

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522


Åbn Internet Explorer, klik på Funktioner->Internetindstillinger->Fanebladet Forbindelser->LAN-indstillinger
Er der flueben ved Proxyserver, så fjern fluebenet, klik OK, klik OK, genstart.
14. august 2010 - 09:56 #19
(Nå ja - selvfølgelig - den har jeg jo set før *Doooooh*)
Avatar billede bkdideriksen Nybegynder
14. august 2010 - 11:00 #20
holda helt op hvor det virker.
hvordan gør vi lige med poiténe?? Skal jeg dele dem eller skal karise_larry have dem alle??


En ting mere, kan jeg finde ud af hvornår og hvordan jeg fik den ind på men pc??

MVH Den lyggelige
Avatar billede sullep Nybegynder
14. august 2010 - 11:33 #21
Point siger mig intet, så glem bare dem til mig.

Godt du fik dit net tilbage, forsat god dag.
14. august 2010 - 13:58 #22
Bingo Banko...

Tid til oprydning:

Klik på START derefter Kør

Skriv/kopier: Combofix  /Uninstall i boxen, og klik OK.

Ovennævnte procedure vil:
Slette følgende:
ComboFix og tilhørende filer og mapper.
Nulstille uret indstillinger.
Skjule filtypenavne, hvis det kræves.
Skjule System / Skjulte filer, hvis det kræves.

Du bør oprette et nyt gendannelsespunkt for at fjerne eventuelle infektioner fra et gammelt gendannelsespunkt.
Den nemmeste og sikreste måde at gøre dette på er:

Gå til Start> Alle programmer> Tilbehør> Systemværktøjer> Systemgendannelse
Vælg Opret et gendannelsespunkt, og tryk Ok.

CCleaner - værktøjer - systemgendannelse - Slet alle gamle Systemgendannelsespunkter...

Ta' en oprydning med CCleaner i samme omgange...
CCleaner har du set i http://www.eksperten.dk/spm/906483 ...
Avatar billede bkdideriksen Nybegynder
15. august 2010 - 10:47 #23
tusin mange tak for hjælpen.
Skal jeg stille et nyt spørgsmål for at komme frem til hvornår og hvordan virusén kom ind på pc'en??

MVH. BKK
15. august 2010 - 22:56 #24
Takker for Point...

Et hurtigt gæt: ? f3popularscreensavers ?
Du har mere eller mindre frivilligt kigget efter en eller anden fanzy ScreenSaver; jo der er MANGE ude i verden. Men i mange tilfælde følger der lidt extra Uønskede elementer med i pakken. Nogle gange bare ved at besøge hjemmesiden...
Avatar billede bkdideriksen Nybegynder
16. august 2010 - 20:32 #25
Så kan det godt passe at den er kommet ind sammen med et besøg på FCM s hjemmeside, ved at klikke på et link til youtube??
16. august 2010 - 20:39 #26
(Måske - de 'skjuler' sig godt...)
Avatar billede bkdideriksen Nybegynder
16. august 2010 - 20:41 #27
ok manget tak for denne gang
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester