Vil lige nævne at jeg downloadede AVG antivirus free og dermed forsvandt aktiveringen af opdateringsikonet i startmenuen. Hvilket var dejligt. Men til gengæld blev opstarten med AVG endnu langsommere, så AVG er slettet igen og update-ikonet lyser atter. Altså tilbage cero.
Jeg orker ikke de lange scanninger som antivirusprogrammerne medfører og har en idé om at jeg kan klare mig med Microsoft Security Essentials - er det helt i skoven?
Nå, men det var loggene vi kom fra, her er de:
Malwarebytes Anti-Malware
www.malwarebytes.orgScan Date: 19-11-2014
Scan Time: 20:40:25
Logfile: Malwarebytes Anti-Malware.lnk log.txt
Administrator: Yes
Version: 2.00.3.1025
Malware Database: v2014.11.19.06
Rootkit Database: v2014.11.18.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows Vista Service Pack 2
CPU: x86
File System: NTFS
User: Søren
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 343742
Time Elapsed: 34 min, 9 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 1
PUP.Optional.MindSpark.A, HKU\S-1-5-21-3502369812-1322381677-3577233532-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\VideoDownloadConverter_4z, Quarantined, [148e1924ed8f6acc2e0566f4f211aa56],
Registry Values: 1
Trojan.Ransom, HKU\S-1-5-21-3502369812-1322381677-3577233532-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON|shell, Quarantined, [1a882419d5a76cca623c9bed8d779868],
Registry Data: 0
(No malicious items detected)
Folders: 4
PUP.Optional.Zapp.A, C:\Program Files\Zapp, Quarantined, [b6ec6ad3c2ba61d5ecc32c238380926e],
PUP.Optional.Zapp.A, C:\Program Files\Zapp\chrome, Quarantined, [b6ec6ad3c2ba61d5ecc32c238380926e],
PUP.Optional.Zapp.A, C:\Program Files\Zapp\support@Zapp.com, Quarantined, [b6ec6ad3c2ba61d5ecc32c238380926e],
PUP.Optional.Zapp.A, C:\Program Files\Zapp\support@Zapp.com\chrome, Quarantined, [b6ec6ad3c2ba61d5ecc32c238380926e],
Files: 6
PUP.Optional.Zapp.A, C:\Program Files\Zapp\Microsoft.Win32.TaskScheduler.xml, Quarantined, [b6ec6ad3c2ba61d5ecc32c238380926e],
PUP.Optional.Zapp.A, C:\Program Files\Zapp\unins000.dat, Quarantined, [b6ec6ad3c2ba61d5ecc32c238380926e],
PUP.Optional.Zapp.A, C:\Program Files\Zapp\chrome\Zapp.crx, Quarantined, [b6ec6ad3c2ba61d5ecc32c238380926e],
PUP.Optional.Zapp.A, C:\Program Files\Zapp\support@Zapp.com\install.rdf, Quarantined, [b6ec6ad3c2ba61d5ecc32c238380926e],
PUP.Optional.Zapp.A, C:\Program Files\Zapp\support@Zapp.com\pop.htm, Quarantined, [b6ec6ad3c2ba61d5ecc32c238380926e],
PUP.Optional.Zapp.A, C:\Program Files\Zapp\support@Zapp.com\chrome\Zapp_18268.jar, Quarantined, [b6ec6ad3c2ba61d5ecc32c238380926e],
Physical Sectors: 0
(No malicious items detected)
(end)
HijackThis:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:04:11, on 20-11-2014
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16592)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\Søren\AppData\Local\Google\Update\1.3.25.11\GoogleCrashHandler.exe
C:\Users\SREN~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Windows\system32\wuauclt.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Users\Søren\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Søren\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Søren\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Søren\Downloads\HijackThis (3).exe
C:\Windows\system32\DllHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.dk/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://da.intl.acer.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://da.intl.acer.yahoo.comR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: Shell=
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Søren\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (file missing)
O9 - Extra button: Danske Spil Poker - {831FA997-206D-433e-9D9D-9F629D61ECA1} - C:\Users\Søren\Desktop\Danske Spil Poker.lnk
O9 - Extra 'Tools' menuitem: Danske Spil Poker - {831FA997-206D-433e-9D9D-9F629D61ECA1} - C:\Users\Søren\Desktop\Danske Spil Poker.lnk
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Programs\PartyGaming\PartyCasino\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Programs\PartyGaming\PartyCasino\RunApp.exe (file missing)
O9 - Extra button: (no name) - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - (no file)
O9 - Extra button: InterCasino USD - {909AAEB6-C2CB-4AB5-A7BB-C33B72AB4BFB} -
http://www.intercasino.com/?utm_source=download-ca (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: InterCasino USD - {909AAEB6-C2CB-4AB5-A7BB-C33B72AB4BFB} -
http://www.intercasino.com/?utm_source=download-ca (file missing) (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.danskebank.dk
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444552440000} -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cabO22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: Tjenesten Google Update (gupdate1c9bde73b7fa570) (gupdate1c9bde73b7fa570) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Tjeneste (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HASP License Manager (hasplms) - Aladdin Knowledge Systems Ltd. - C:\Windows\system32\hasplms.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
--
End of file - 7326 bytes