Avatar billede cepoo Nybegynder
26. marts 2006 - 11:26 Der er 12 kommentarer

har jeg virus og spyware liggende

hej jeg ville høre om i kunne hjælpe mig med at finde ud af om jeg har nogen form for virus eller andet snavs liggende på min computer , her tænker jeg også på spyware og evt. virus i hukommelsen , kan ikke selv finde noget andet end at spybot ikke kan fjerne noget der ligger i min hukommelse selvom den prøver kommer det samme op hver gang , der ligger aktive filer i hukommelsen , om den ved næste genstart må reparerer dem hvilket ikke lykkedes

med venlig hilsen steen
Avatar billede fromsej Praktikant
26. marts 2006 - 11:29 #1
Hej.*S*
Følg vejledningen i denne artikel:
http://www.eksperten.dk/artikler/755
Avatar billede cepoo Nybegynder
26. marts 2006 - 20:10 #2
ved ikke hvordan jeg kopierer den log fil herind
Avatar billede fromsej Praktikant
26. marts 2006 - 20:18 #3
Loggen åbner i Notesblok, klik en gang på musen, så vinduet er aktivt, tryk så på <Ctrl><A> så teksten bliver markeret, tryk på <Ctrl><C> for at kopiere, klik en gang med musen i svarfeltet herinde, tryk på <Ctrl><V> så er teksten sat ind.
Avatar billede cepoo Nybegynder
27. marts 2006 - 14:45 #4
[Scan path] C:\WINDOWS\system32\smss.exe
Master Boot Record HDD1 - Ok
Active OS/2 or WinNT Boot Sector HDD1 - Ok
C:\WINDOWS\system32\smss.exe - Ok

[Scan path] C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\csrss.exe - Ok

[Scan path] C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe - Ok

[Scan path] C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\services.exe - Ok

[Scan path] C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\lsass.exe - Ok

[Scan path] C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe - Ok

[Scan path] C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Explorer.EXE - Ok

[Scan path] C:\DOCUME~1\ADMINI~1\LOKALE~1\Temp\RarSFX0\drw_start.exe
C:\DOCUME~1\ADMINI~1\LOKALE~1\Temp\RarSFX0\drw_start.exe - Ok

[Scan path] C:\DOCUME~1\ADMINI~1\LOKALE~1\Temp\RarSFX0\drweb32w.exe
>>C:\DOCUME~1\ADMINI~1\LOKALE~1\Temp\RarSFX0\drweb32w.exe - Ok

[Scan path] C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxtray.exe - Ok

[Scan path] C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\hkcmd.exe - Ok

[Scan path] C:\WINDOWS\system32\HDAudPropShortcut.exe
C:\WINDOWS\system32\HDAudPropShortcut.exe - Ok

[Scan path] C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\SOUNDMAN.EXE - Ok

[Scan path] C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\ALCWZRD.EXE - Ok

[Scan path] C:\WINDOWS\system32\NeroCheck.exe
C:\WINDOWS\system32\NeroCheck.exe - Ok

[Scan path] C:\Programmer\Diskeeper Corporation\Diskeeper\DkIcon.exe
C:\Programmer\Diskeeper Corporation\Diskeeper\DkIcon.exe - Ok

[Scan path] C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxpers.exe - Ok

[Scan path] C:\Programmer\Gigabyte\ET5\GUI.exe
C:\Programmer\Gigabyte\ET5\GUI.exe - Ok

[Scan path] C:\Programmer\Network Mechanic\NetworkMechanic.exe
>C:\Programmer\Network Mechanic\NetworkMechanic.exe - Ok

[Scan path] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe - Ok

[Scan path] C:\WINDOWS\System32\CTFMON.EXE
C:\WINDOWS\System32\CTFMON.EXE - Ok

[Scan path] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe - Ok

[Scan path] C:\Documents and Settings\Administrator\Menuen Start\Programmer\Start\desktop.ini
C:\Documents and Settings\Administrator\Menuen Start\Programmer\Start\desktop.ini - Ok

[Scan path] D:\Programmer\Reader\reader_sl.exe
D:\Programmer\Reader\reader_sl.exe - Ok

[Scan path] C:\Documents and Settings\All Users.WINDOWS\Menuen Start\Programmer\Start\desktop.ini
C:\Documents and Settings\All Users.WINDOWS\Menuen Start\Programmer\Start\desktop.ini - Ok

[Scan path] C:\WINDOWS\system32\mmsys.cpl
C:\WINDOWS\system32\mmsys.cpl - Ok

[Scan path] C:\WINDOWS\system32\icmui.dll
C:\WINDOWS\system32\icmui.dll - Ok

[Scan path] C:\WINDOWS\system32\rshx32.dll
C:\WINDOWS\system32\rshx32.dll - Ok

[Scan path] C:\WINDOWS\system32\docprop.dll
C:\WINDOWS\system32\docprop.dll - Ok

[Scan path] C:\WINDOWS\system32\ntshrui.dll
C:\WINDOWS\system32\ntshrui.dll - Ok

[Scan path] C:\WINDOWS\System32\themeui.dll
C:\WINDOWS\System32\themeui.dll - Ok

[Scan path] C:\WINDOWS\system32\deskadp.dll
C:\WINDOWS\system32\deskadp.dll - Ok

[Scan path] C:\WINDOWS\system32\deskmon.dll
C:\WINDOWS\system32\deskmon.dll - Ok

[Scan path] C:\WINDOWS\system32\dssec.dll
C:\WINDOWS\system32\dssec.dll - Ok

[Scan path] C:\WINDOWS\system32\SlayerXP.dll
C:\WINDOWS\system32\SlayerXP.dll - Ok

[Scan path] C:\WINDOWS\system32\shscrap.dll
C:\WINDOWS\system32\shscrap.dll - Ok

[Scan path] C:\WINDOWS\system32\diskcopy.dll
C:\WINDOWS\system32\diskcopy.dll - Ok

[Scan path] C:\WINDOWS\system32\ntlanui2.dll
C:\WINDOWS\system32\ntlanui2.dll - Ok

[Scan path] C:\WINDOWS\system32\printui.dll
C:\WINDOWS\system32\printui.dll - Ok

[Scan path] C:\WINDOWS\system32\dskquoui.dll
C:\WINDOWS\system32\dskquoui.dll - Ok

[Scan path] C:\WINDOWS\system32\syncui.dll
C:\WINDOWS\system32\syncui.dll - Ok

[Scan path] C:\WINDOWS\System32\hticons.dll
C:\WINDOWS\System32\hticons.dll - Ok

[Scan path] C:\WINDOWS\system32\fontext.dll
C:\WINDOWS\system32\fontext.dll - Ok

[Scan path] C:\WINDOWS\system32\deskperf.dll
C:\WINDOWS\system32\deskperf.dll - Ok

[Scan path] C:\WINDOWS\system32\cryptext.dll
C:\WINDOWS\system32\cryptext.dll - Ok

[Scan path] C:\WINDOWS\system32\NETSHELL.dll
C:\WINDOWS\system32\NETSHELL.dll - Ok

[Scan path] C:\WINDOWS\system32\wiashext.dll
C:\WINDOWS\system32\wiashext.dll - Ok

[Scan path] C:\WINDOWS\System32\remotepg.dll
C:\WINDOWS\System32\remotepg.dll - Ok

[Scan path] C:\WINDOWS\system32\wuaucpl.cpl
C:\WINDOWS\system32\wuaucpl.cpl - Ok

[Scan path] C:\WINDOWS\system32\wshext.dll
C:\WINDOWS\system32\wshext.dll - Ok

[Scan path] C:\Programmer\Fælles filer\System\Ole DB\oledb32.dll
C:\Programmer\Fælles filer\System\Ole DB\oledb32.dll - Ok

[Scan path] C:\WINDOWS\System32\mstask.dll
C:\WINDOWS\System32\mstask.dll - Ok

[Scan path] C:\WINDOWS\system32\shdocvw.dll
C:\WINDOWS\system32\shdocvw.dll - Ok

[Scan path] C:\WINDOWS\System32\shmedia.dll
C:\WINDOWS\System32\shmedia.dll - Ok

[Scan path] C:\WINDOWS\System32\browseui.dll
C:\WINDOWS\System32\browseui.dll - Ok

[Scan path] C:\WINDOWS\System32\sendmail.dll
C:\WINDOWS\System32\sendmail.dll - Ok

[Scan path] C:\WINDOWS\System32\occache.dll
C:\WINDOWS\System32\occache.dll - Ok

[Scan path] C:\WINDOWS\System32\webcheck.dll
C:\WINDOWS\System32\webcheck.dll - Ok

[Scan path] C:\WINDOWS\System32\appwiz.cpl
C:\WINDOWS\System32\appwiz.cpl - Ok

[Scan path] C:\WINDOWS\System32\shimgvw.dll
C:\WINDOWS\System32\shimgvw.dll - Ok

[Scan path] C:\WINDOWS\System32\netplwiz.dll
C:\WINDOWS\System32\netplwiz.dll - Ok

[Scan path] C:\WINDOWS\System32\zipfldr.dll
C:\WINDOWS\System32\zipfldr.dll - Ok

[Scan path] C:\WINDOWS\System32\cdfview.dll
C:\WINDOWS\System32\cdfview.dll - Ok

[Scan path] C:\WINDOWS\System32\msieftp.dll
C:\WINDOWS\System32\msieftp.dll - Ok

[Scan path] C:\WINDOWS\System32\docprop2.dll
C:\WINDOWS\System32\docprop2.dll - Ok

[Scan path] C:\WINDOWS\System32\dsquery.dll
C:\WINDOWS\System32\dsquery.dll - Ok

[Scan path] C:\WINDOWS\System32\dsuiext.dll
C:\WINDOWS\System32\dsuiext.dll - Ok

[Scan path] C:\WINDOWS\System32\mydocs.dll
C:\WINDOWS\System32\mydocs.dll - Ok

[Scan path] C:\WINDOWS\System32\cscui.dll
C:\WINDOWS\System32\cscui.dll - Ok

[Scan path] C:\WINDOWS\msagent\agentpsh.dll
C:\WINDOWS\msagent\agentpsh.dll - Ok

[Scan path] C:\WINDOWS\System32\dfsshlex.dll
C:\WINDOWS\System32\dfsshlex.dll - Ok

[Scan path] C:\WINDOWS\System32\photowiz.dll
C:\WINDOWS\System32\photowiz.dll - Ok

[Scan path] C:\WINDOWS\System32\mmcshext.dll
C:\WINDOWS\System32\mmcshext.dll - Ok

[Scan path] C:\WINDOWS\system32\cabview.dll
C:\WINDOWS\system32\cabview.dll - Ok

[Scan path] C:\Programmer\Outlook Express\wabfind.dll
C:\Programmer\Outlook Express\wabfind.dll - Ok

[Scan path] C:\WINDOWS\system32\wmpshell.dll
C:\WINDOWS\system32\wmpshell.dll - Ok

[Scan path] C:\WINDOWS\System32\twext.dll
C:\WINDOWS\System32\twext.dll - Ok

[Scan path] C:\WINDOWS\System32\extmgr.dll
C:\WINDOWS\System32\extmgr.dll - Ok

[Scan path] C:\WINDOWS\system32\Audiodev.dll
C:\WINDOWS\system32\Audiodev.dll - Ok

[Scan path] D:\sten2\programmer\WinRAR\rarext.dll
D:\sten2\programmer\WinRAR\rarext.dll - Ok

[Scan path] C:\WINDOWS\system32\upnpui.dll
C:\WINDOWS\system32\upnpui.dll - Ok

[Scan path] C:\Programmer\Grisoft\AVG Free\avgse.dll
C:\Programmer\Grisoft\AVG Free\avgse.dll - Ok

[Scan path] C:\PROGRA~1\SPYBOT~1\SDHelper.dll
C:\PROGRA~1\SPYBOT~1\SDHelper.dll - Ok

-----------------------------------------------------------------------------
Scan statistics
-----------------------------------------------------------------------------
Objects scanned: 85
Infected objects found: 0
Objects with modifications found: 0
Suspicious objects found: 0
Adware programs found: 0
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 0
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 0
Objects renamed: 0
Objects moved: 0
Objects ignored: 0
Scan speed: 1732 Kb/s
Scan time: 00:00:13
-----------------------------------------------------------------------------
Avatar billede cepoo Nybegynder
27. marts 2006 - 15:49 #5
ovenover er loggen fra doctor web og nedenstående er så fra ewido anti malware
Avatar billede cepoo Nybegynder
27. marts 2006 - 15:50 #6
---------------------------------------------------------
ewido anti-malware - Scanningsrapport
---------------------------------------------------------

+ Oprettet den:            15:42:16, 27-03-2006
+ Rapport-Checksum:        3FEADDC0

+ Scanningsresultat:
    C:\Documents and Settings\Cepo.CEPO-02I2D14AU9\Cookies\cepo@adtech[1].txt -> TrackingCookie.Adtech : Renset med backup
    C:\Documents and Settings\Cepo.CEPO-02I2D14AU9\Cookies\cepo@statcounter[1].txt -> TrackingCookie.Statcounter : Renset med backup


::Rapport slut
Avatar billede cepoo Nybegynder
27. marts 2006 - 15:55 #7
og her kommer så loggen fra hijackthis
Avatar billede cepoo Nybegynder
27. marts 2006 - 15:56 #8
Logfile of HijackThis v1.99.1
Scan saved at 15:53:42, on 27-03-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\Programmer\Gigabyte\ET5\GUI.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\Creative\Shared Files\CamTray.exe
C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Programmer\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Programmer\ewido anti-malware\ewidoctrl.exe
C:\Programmer\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Genvej til egenskabsside for High Definition Audio] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Programmer\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [EasyTuneV] C:\Programmer\Gigabyte\ET5\GUI.exe
O4 - HKLM\..\Run: [NetworkMechanic] C:\Programmer\Network Mechanic\NetworkMechanic.exe /startup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Creative WebCam Tray] C:\Programmer\Creative\Shared Files\CamTray.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Diskeeper 10 Professional Edition Registration.lnk = C:\Programmer\Diskeeper Corporation\Diskeeper\ESIRegister.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Programmer\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} (Dldrv2 Control) - http://download.gigabyte.com.tw/object/Dldrv.ocx
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37680.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Programmer\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido anti-malware\ewidoguard.exe
Avatar billede cepoo Nybegynder
27. marts 2006 - 15:57 #9
håber jeg har gjort det hele korrekt. hvad så nu ?
Avatar billede fromsej Praktikant
27. marts 2006 - 20:03 #10
Det har du.

Der er ikke noget i loggen, din maskine er ren.

For at holde den ren kan du kigge på vores pakke til formålet.
http://www.spywarefri.dk/manualer/sikkerhedspakke.htm
Som minimum anbefaler jeg Spywareguard, Spywareblaster, IE-Spyad og IE Privacy Keeper.
Et par artikler om sikker surfing finder du her:
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=14414
http://fromsej.dk/html/avoid.html
Mvh:
Fromsej/Team Spywarefri.
Avatar billede cepoo Nybegynder
27. marts 2006 - 20:10 #11
mange tak fromsej , jeg kigger lige på dine forslag kan helt sikkert nok bruge en af dem da jeg kun kører med avg antivirus og spybot sd permanent
Avatar billede fromsej Praktikant
27. marts 2006 - 23:32 #12
Velbekomme.*S*
Hvis du så lige klikker på mit navn i boxen og klikker på accepter, så er spørgsmålet lukket rigtigt.
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester