Jeg kørte alle de der ting og fandt en masse inficerede ting
her er mine rapporter:
-----------------------------------------------------------------------------
Scan statistics
-----------------------------------------------------------------------------
Objects scanned: 117499
Infected objects found: 6
Objects with modifications found: 1
Suspicious objects found: 0
Adware programs found: 4
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 4
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 7
Objects renamed: 8
Objects moved: 0
Objects ignored: 0
Scan speed: 559 Kb/s
Scan time: 01:30:53
-----------------------------------------------------------------------------
---------------------------------------------------------
ewido anti-malware - Scanningsrapport
---------------------------------------------------------
+ Oprettet den: 14:20:28, 07-04-2006
+ Rapport-Checksum: 14724A13
+ Scanningsresultat:
HKLM\SOFTWARE\Classes\CLSID\{B54BFA47-D897-49CA-9657-05EC9F80A32B} -> Adware.QuickMetaSearch : Renset med backup
HKLM\SOFTWARE\Classes\STLinks.STLinksCtrl -> Adware.QuickMetaSearch : Renset med backup
HKLM\SOFTWARE\Classes\STLinks.STLinksCtrl\CLSID -> Adware.QuickMetaSearch : Renset med backup
HKLM\SOFTWARE\Classes\STLinks.STLinksCtrl\CurVer -> Adware.QuickMetaSearch : Renset med backup
HKLM\SOFTWARE\Classes\STLinks.STLinksCtrl.1 -> Adware.QuickMetaSearch : Renset med backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B54BFA47-D897-49CA-9657-05EC9F80A32B} -> Adware.QuickMetaSearch : Renset med backup
HKU\S-1-5-21-854245398-1645522239-682003330-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B54BFA47-D897-49CA-9657-05EC9F80A32B} -> Adware.QuickMetaSearch : Renset med backup
C:\Documents and Settings\Administrator\Cookies\administrator@2o7[2].txt -> TrackingCookie.2o7 : Renset med backup
C:\Documents and Settings\Administrator\Cookies\administrator@adtech[1].txt -> TrackingCookie.Adtech : Renset med backup
C:\Documents and Settings\Administrator\Cookies\administrator@as1.falkag[1].txt -> TrackingCookie.Falkag : Renset med backup
C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt -> TrackingCookie.Atdmt : Renset med backup
C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[1].txt -> TrackingCookie.Mediaplex : Renset med backup
C:\Documents and Settings\Administrator\Cookies\administrator@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : Renset med backup
C:\Documents and Settings\Administrator\Cookies\administrator@statcounter[1].txt -> TrackingCookie.Statcounter : Renset med backup
C:\Documents and Settings\Administrator\Dokumenter\Modtagne filer\Messenger Plus! - Setup(1).exe/sponsor.exe -> Downloader.Swizzor.ag : Renset med backup
C:\Documents and Settings\Administrator\Dokumenter\Modtagne filer\Messenger Plus! - Setup.exe/sponsor.exe -> Downloader.Swizzor.ag : Renset med backup
C:\Programmer\STLinks\STLinks.#ll -> Adware.MetaSearch : Renset med backup
C:\WINDOWS\Downloaded Program Files\gsda.#ll -> Not-A-Virus.Downloader.Win32.SpyGame : Renset med backup
F:\Backup\Dokumenter\Download\vnc-4.0-x86_win32_viewer.#xe -> Not-A-Virus.RemoteAdmin.Win32.WinVNC.4 : Renset med backup
F:\Backup\Dokumenter\Download\vnc-4.0-x86_win32_viewer.zip/vnc-4.0-x86_win32_viewer.exe -> Not-A-Virus.RemoteAdmin.Win32.WinVNC.4 : Renset med backup
::Rapport slut
-------------------------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 14:21:01, on 07-04-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Administrator\Skrivebord\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.dk/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O4 - HKLM\..\Run: [ShStatEXE] "C:\Programmer\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Programmer\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [IMONTRAY] C:\Programmer\Intel\Intel(R) Active Monitor\imontray.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmer\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Programmer\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmer\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: BitTorrent.lnk = C:\Programmer\BitTorrent\bittorrent.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&ksporter til Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by110fd.bay110.hotmail.msn.com/resources/MsnPUpld.cabO16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) -
http://launch.gamespyarcade.com/software/launch/alaunch.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{824A6A8E-C7E4-4F79-AE42-FA313C21D30C}: NameServer = 193.162.153.164,194.239.134.83
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel(R) Active Monitor (imonNT) - Intel Corp. - C:\Programmer\Intel\Intel(R) Active Monitor\imonnt.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Programmer\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Programmer\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Programmer\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe
-------------------------------------------------------------------------------------