Avatar billede faus Praktikant
06. februar 2007 - 16:16 Der er 5 kommentarer og
2 løsninger

Problem med online scanner. måske snavs/rootkits!!

Først og fremmest har jeg køret de scanner jeg har på computeren, og de finder ikke noget( Tdc sikkerhedspakke, ad-aware, windows defender).  Har så prøvet: Trent micro og panda online scan for at være helt sikker. Men efter 2-5 minutters scanning lukker den browseren ned.
Kan det være at der er noget snavs som er skyld i at den gør det, eller er det noget andet.  Har tænkt lidt på rootkits.  Men den "gemer" kan jeg ikke helt finde ud af. 
Nogen der kan hjælpe?
Avatar billede ejvindh Ekspert
08. februar 2007 - 15:05 #1
Det lyder nu ikke som typisk rootkit-aktivitet. Prøv lige følgende først:

-- Hent "SuperAntiSpyware free" herfra:
http://www.spywarefri.dk/downloads1.htm
Installer, og opdater scannereren.

-- Hent Dr. Web, og gem det på skrivebordet:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

-- Genstart i fejlsikret, hvis du ikke ved hvordan så kig her:
http://www.ctrlaltdel.dk/forum/forum_posts.asp?TID=23&PN=1

-- Dobbeltklik på drweb-cureit.exe, den vil køre en expressscan, det siger du ja til. Lad den slette hvad den finder (say Yes to all). Undervejs i scanningen vil der dukke en grøn popup som tilbyder dig at købe Dr.Web, hvor du får mulighederne "Buy" eller "50% discount". Her skal du bare lukke popuppen, ved at klikke på krydset øverst til højre.

Når den skriver "Select object for Scanning" nederst til venstre, skal du klikke på Options->Change settings.
Skift til fanebladet Scan, fjern fluebenet ved Heuristic analysis.
Skift til fanebladet - File Types, prik i - All Files
Skift til fanebladet Actions, her skal alle punkter under Malware sættes til Move.
Fjern flueben ved "Prompt on action"
Ved "Move path", skriver du i tekstboksen "c:\" Så der kommer til at stå "c:\infected".
Skift til fanbladet Log File. Der fjerner du flueben ved: "Scanned objects" og "Archivers name".
Tryk på Anvend

Klik så på det eller de drev du vil have scannet, der kommer en rød prik for at vise det/de er valgt.
Tryk så på den grønne pil nederst til højre, så scanner den.
Lad den slette/move hvad den finder (Say yes to all)

Når scanningen er færdig, gå op i file – Tryk på- Save Report list.

Så ligger der en en fil der her hedder "drweb.csv" på skrivebordet. Luk Programmet

-- Start herefter SuperAntispyware, klik "Scan your computer", sæt flueben i dine drev, ovre til venstre i vinduet. Ovre til højre i vinduet, sætter du prik i "Perform Complete Scan". Klik "næste", nu scanner den. Når den er færdig, så markerer du det den finder, og lader scannereren fjerne det.

-- Genstart til normal tilstand (scannereren tilbyder måske at gøre det).
Åbn scannereren igen, og klik "preferences"-> "stastics/logs". Marker loggen, og klik "View log". Kopier loggen her ind i tråden, sammen med indholdet af drweb.csv.

-- Hent så dette værktøj, og gem det på dit skrivebord:
http://www.uploads.ejvindh.net/rootchk.exe
Kør programmet. Efter kort tid vil der dukke en logfil op. Kopier indholdet af denne log herind i tråden.
Avatar billede faus Praktikant
12. februar 2007 - 13:48 #2
okey.  så er jeg hjemme igen. Har tænkt lidt over om det kan være min firewall der blockere for onlinescanner når de er igang.  kan dette være en mulighed?
Her er logfilerne..

Cureit:
[Scan path] c:\documents and settings\all users\menuen start\programmer\start\desktop.ini
[Scan path] c:\documents and settings\hp_ejer\lokale indstillinger\temp\rarsfx0\_start.exe
[Scan path] c:\documents and settings\hp_ejer\lokale indstillinger\temp\rarsfx0\cureit.exe
[Scan path] c:\documents and settings\hp_ejer\menuen start\programmer\start\desktop.ini
[Scan path] c:\hp\kbd\kbd.exe
[Scan path] c:\programmer\creative\sound blaster x-fi\volume panel\volpanlu.exe
[Scan path] c:\programmer\fælles filer\adobe\acrobat\activex\acroiehelper.dll
[Scan path] c:\programmer\fælles filer\adobe\acrobat\activex\pdfshell.dll
[Scan path] c:\programmer\fælles filer\ahead\lib\nerodigitalext.dll
[Scan path] c:\programmer\fælles filer\ahead\lib\nmindexingservice.exe
[Scan path] c:\programmer\fælles filer\microsoft shared\dw\dwtrig20.exe
[Scan path] c:\programmer\fælles filer\microsoft shared\web folders\msonsext.dll
[Scan path] c:\programmer\fælles filer\skype\skype4com.dll
[Scan path] c:\programmer\fælles filer\system\ole db\oledb32.dll
[Scan path] c:\programmer\hitman pro\hitmanpro2.sys
[Scan path] c:\programmer\microsoft lifecam\lifeexp.exe
[Scan path] c:\programmer\microsoft lifecam\mscams32.exe
[Scan path] c:\programmer\msn messenger\fsshext.8.0.0812.00.dll
[Scan path] c:\programmer\msn messenger\msgrapp.8.0.0812.00.dll
[Scan path] c:\programmer\nero\nero 7\nero backitup\nbservice.exe
[Scan path] c:\programmer\nvidia corporation\ntune\ntunecmd.exe
[Scan path] c:\programmer\nvidia corporation\ntune\ntuneservice.exe
[Scan path] c:\programmer\outlook express\setup50.exe
[Scan path] c:\programmer\outlook express\wabfind.dll
[Scan path] c:\programmer\panda software\panda antivirus 2007\psimsvc.exe
[Scan path] c:\programmer\superantispyware\sasdifsv.sys
[Scan path] c:\programmer\superantispyware\sasenum.sys
[Scan path] c:\programmer\superantispyware\saskutil.sys
[Scan path] c:\programmer\superantispyware\sasseh.dll
[Scan path] c:\programmer\superantispyware\saswinlo.dll
[Scan path] c:\programmer\superantispyware\superantispyware.exe
[Scan path] c:\programmer\tdc kabel tv sikkerhedspakke\anti-virus\fsgk32st.exe
[Scan path] c:\programmer\tdc kabel tv sikkerhedspakke\anti-virus\win2k\fsfilter.sys
[Scan path] c:\programmer\tdc kabel tv sikkerhedspakke\anti-virus\win2k\fsgk.sys
[Scan path] c:\programmer\tdc kabel tv sikkerhedspakke\anti-virus\win2k\fsrec.sys
[Scan path] c:\programmer\tdc kabel tv sikkerhedspakke\backweb\7791805\program\fsbwsys.exe
[Scan path] c:\programmer\tdc kabel tv sikkerhedspakke\backweb\7791805\program\servicewrapper-7791805.exe
[Scan path] c:\programmer\tdc kabel tv sikkerhedspakke\common\fsm32.exe
[Scan path] c:\programmer\tdc kabel tv sikkerhedspakke\common\fsma32.exe
[Scan path] c:\programmer\tdc kabel tv sikkerhedspakke\fsgui\fssw.exe
[Scan path] c:\programmer\tdc kabel tv sikkerhedspakke\fwes\program\fsdfwd.exe
c:\programmer\tdc kabel tv sikkerhedspakke\fwes\program\fsdfwd.exe probably infected with BACKDOOR.Trojan

[Scan path] c:\programmer\tdc kabel tv sikkerhedspakke\tnb\tnbutil.exe
[Scan path] c:\programmer\windows defender\mpshhook.dll
[Scan path] c:\programmer\windows defender\msascui.exe
[Scan path] c:\programmer\windows defender\msmpeng.exe
[Scan path] c:\programmer\windows media player\wmpnetwk.exe
[Scan path] c:\programmer\winrar\rarext.dll
[Scan path] c:\programmer\zmatrix\matrix.exe
[Scan path] c:\windows\explorer.exe
[Scan path] c:\windows\inf\unregmp2.exe
[Scan path] c:\windows\logi_mwx.exe
[Scan path] c:\windows\matrix code.scr
[Scan path] c:\windows\microsoft.net\framework\v2.0.50727\aspnet_state.exe
[Scan path] c:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.exe
[Scan path] c:\windows\msagent\agentpsh.dll
[Scan path] c:\windows\nvoclock.sys
[Scan path] c:\windows\sminst\recguard.exe
[Scan path] c:\windows\system32\advapi32.dll
[Scan path] c:\windows\system32\advpack.dll
[Scan path] c:\windows\system32\alg.exe
[Scan path] c:\windows\system32\appwiz.cpl
[Scan path] c:\windows\system32\audiodev.dll
[Scan path] c:\windows\system32\autochk.exe
[Scan path] c:\windows\system32\avldr.dll
[Scan path] c:\windows\system32\browseui.dll
[Scan path] c:\windows\system32\cabview.dll
[Scan path] c:\windows\system32\cisvc.exe
[Scan path] c:\windows\system32\clipsrv.exe
[Scan path] c:\windows\system32\cnbjmon.dll
[Scan path] c:\windows\system32\comdlg32.dll
[Scan path] c:\windows\system32\crypt32.dll
[Scan path] c:\windows\system32\cryptext.dll
[Scan path] c:\windows\system32\cryptnet.dll
[Scan path] c:\windows\system32\cscdll.dll
[Scan path] c:\windows\system32\cscui.dll
[Scan path] c:\windows\system32\csrss.exe
[Scan path] c:\windows\system32\ctfmon.exe
[Scan path] c:\windows\system32\ctxfihlp.exe
[Scan path] c:\windows\system32\deskadp.dll
[Scan path] c:\windows\system32\deskmon.dll
[Scan path] c:\windows\system32\deskperf.dll
[Scan path] c:\windows\system32\dfshim.dll
[Scan path] c:\windows\system32\dfsshlex.dll
[Scan path] c:\windows\system32\diskcopy.dll
[Scan path] c:\windows\system32\dllhost.exe
[Scan path] c:\windows\system32\dmadmin.exe
[Scan path] c:\windows\system32\docprop.dll
[Scan path] c:\windows\system32\docprop2.dll
[Scan path] c:\windows\system32\drivers\acpi.sys
[Scan path] c:\windows\system32\drivers\aec.sys
[Scan path] c:\windows\system32\drivers\afd.sys
[Scan path] c:\windows\system32\drivers\amdk8.sys
[Scan path] c:\windows\system32\drivers\arp1394.sys
[Scan path] c:\windows\system32\drivers\asyncmac.sys
[Scan path] c:\windows\system32\drivers\atapi.sys
[Scan path] c:\windows\system32\drivers\atmarpc.sys
[Scan path] c:\windows\system32\drivers\audstub.sys
[Scan path] c:\windows\system32\drivers\ccdecode.sys
[Scan path] c:\windows\system32\drivers\cdrom.sys
[Scan path] c:\windows\system32\drivers\co_mon.sys
[Scan path] c:\windows\system32\drivers\ctac32k.sys
[Scan path] c:\windows\system32\drivers\ctaud2k.sys
[Scan path] c:\windows\system32\drivers\ctdvda2k.sys
[Scan path] c:\windows\system32\drivers\ctoss2k.sys
[Scan path] c:\windows\system32\drivers\ctprxy2k.sys
[Scan path] c:\windows\system32\drivers\ctsfm2k.sys
[Scan path] c:\windows\system32\drivers\disk.sys
[Scan path] c:\windows\system32\drivers\dmboot.sys
[Scan path] c:\windows\system32\drivers\dmio.sys
[Scan path] c:\windows\system32\drivers\dmload.sys
[Scan path] c:\windows\system32\drivers\dmusic.sys
[Scan path] c:\windows\system32\drivers\drmkaud.sys
[Scan path] c:\windows\system32\drivers\emupia2k.sys
[Scan path] c:\windows\system32\drivers\fdc.sys
[Scan path] c:\windows\system32\drivers\flpydisk.sys
[Scan path] c:\windows\system32\drivers\fltmgr.sys
[Scan path] c:\windows\system32\drivers\fsdfw.sys
[Scan path] c:\windows\system32\drivers\ftdisk.sys
[Scan path] c:\windows\system32\drivers\gmer.sys
[Scan path] c:\windows\system32\drivers\ha20x2k.sys
[Scan path] c:\windows\system32\drivers\hidusb.sys
[Scan path] c:\windows\system32\drivers\http.sys
[Scan path] c:\windows\system32\drivers\i8042prt.sys
[Scan path] c:\windows\system32\drivers\imapi.sys
[Scan path] c:\windows\system32\drivers\intelide.sys
[Scan path] c:\windows\system32\drivers\ip6fw.sys
[Scan path] c:\windows\system32\drivers\ipfltdrv.sys
[Scan path] c:\windows\system32\drivers\ipinip.sys
[Scan path] c:\windows\system32\drivers\ipnat.sys
[Scan path] c:\windows\system32\drivers\ipsec.sys
[Scan path] c:\windows\system32\drivers\irenum.sys
[Scan path] c:\windows\system32\drivers\isapnp.sys
[Scan path] c:\windows\system32\drivers\k750bus.sys
[Scan path] c:\windows\system32\drivers\k750mdfl.sys
[Scan path] c:\windows\system32\drivers\k750mdm.sys
[Scan path] c:\windows\system32\drivers\k750mgmt.sys
[Scan path] c:\windows\system32\drivers\k750obex.sys
[Scan path] c:\windows\system32\drivers\kbdclass.sys
[Scan path] c:\windows\system32\drivers\kmixer.sys
[Scan path] c:\windows\system32\drivers\l8042pr2.sys
[Scan path] c:\windows\system32\drivers\lhidflt2.sys
[Scan path] c:\windows\system32\drivers\lmouflt2.sys
[Scan path] c:\windows\system32\drivers\mouclass.sys
[Scan path] c:\windows\system32\drivers\mouhid.sys
[Scan path] c:\windows\system32\drivers\mrxdav.sys
[Scan path] c:\windows\system32\drivers\mrxsmb.sys
[Scan path] c:\windows\system32\drivers\msgpc.sys
[Scan path] c:\windows\system32\drivers\mskssrv.sys
[Scan path] c:\windows\system32\drivers\mspclock.sys
[Scan path] c:\windows\system32\drivers\mspqm.sys
[Scan path] c:\windows\system32\drivers\mssmbios.sys
[Scan path] c:\windows\system32\drivers\mstee.sys
[Scan path] c:\windows\system32\drivers\nabtsfec.sys
[Scan path] c:\windows\system32\drivers\ndisip.sys
[Scan path] c:\windows\system32\drivers\ndistapi.sys
[Scan path] c:\windows\system32\drivers\ndisuio.sys
[Scan path] c:\windows\system32\drivers\ndiswan.sys
[Scan path] c:\windows\system32\drivers\netbios.sys
[Scan path] c:\windows\system32\drivers\netbt.sys
[Scan path] c:\windows\system32\drivers\nic1394.sys
[Scan path] c:\windows\system32\drivers\nv4_mini.sys
[Scan path] c:\windows\system32\drivers\nwlnkflt.sys
[Scan path] c:\windows\system32\drivers\nwlnkfwd.sys
[Scan path] c:\windows\system32\drivers\ohci1394.sys
[Scan path] c:\windows\system32\drivers\parport.sys
[Scan path] c:\windows\system32\drivers\pci.sys
[Scan path] c:\windows\system32\drivers\pciide.sys
[Scan path] c:\windows\system32\drivers\pcouffin.sys
[Scan path] c:\windows\system32\drivers\processr.sys
[Scan path] c:\windows\system32\drivers\ps2.sys
[Scan path] c:\windows\system32\drivers\psched.sys
[Scan path] c:\windows\system32\drivers\ptilink.sys
[Scan path] c:\windows\system32\drivers\rasacd.sys
[Scan path] c:\windows\system32\drivers\rasl2tp.sys
[Scan path] c:\windows\system32\drivers\raspppoe.sys
[Scan path] c:\windows\system32\drivers\raspptp.sys
[Scan path] c:\windows\system32\drivers\raspti.sys
[Scan path] c:\windows\system32\drivers\rdbss.sys
[Scan path] c:\windows\system32\drivers\rdpcdd.sys
[Scan path] c:\windows\system32\drivers\redbook.sys
[Scan path] c:\windows\system32\drivers\rtl8139.sys
[Scan path] c:\windows\system32\drivers\rtlnicxp.sys
[Scan path] c:\windows\system32\drivers\secdrv.sys
[Scan path] c:\windows\system32\drivers\serenum.sys
[Scan path] c:\windows\system32\drivers\serial.sys
[Scan path] c:\windows\system32\drivers\slip.sys
[Scan path] c:\windows\system32\drivers\splitter.sys
[Scan path] c:\windows\system32\drivers\sr.sys
[Scan path] c:\windows\system32\drivers\srv.sys
[Scan path] c:\windows\system32\drivers\streamip.sys
[Scan path] c:\windows\system32\drivers\swenum.sys
[Scan path] c:\windows\system32\drivers\swmidi.sys
[Scan path] c:\windows\system32\drivers\sysaudio.sys
[Scan path] c:\windows\system32\drivers\tcpip.sys
[Scan path] c:\windows\system32\drivers\termdd.sys
[Scan path] c:\windows\system32\drivers\tmcomm.sys
[Scan path] c:\windows\system32\drivers\update.sys
[Scan path] c:\windows\system32\drivers\usbaudio.sys
[Scan path] c:\windows\system32\drivers\usbccgp.sys
[Scan path] c:\windows\system32\drivers\usbehci.sys
[Scan path] c:\windows\system32\drivers\usbhub.sys
[Scan path] c:\windows\system32\drivers\usbohci.sys
[Scan path] c:\windows\system32\drivers\usbstor.sys
[Scan path] c:\windows\system32\drivers\usbuhci.sys
[Scan path] c:\windows\system32\drivers\vga.sys
[Scan path] c:\windows\system32\drivers\viaide.sys
[Scan path] c:\windows\system32\drivers\vx6000xp.sys
[Scan path] c:\windows\system32\drivers\wanarp.sys
[Scan path] c:\windows\system32\drivers\wdmaud.sys
[Scan path] c:\windows\system32\drivers\ws2ifsl.sys
[Scan path] c:\windows\system32\drivers\wstcodec.sys
[Scan path] c:\windows\system32\drivers\wudfpf.sys
[Scan path] c:\windows\system32\drivers\wudfrd.sys
[Scan path] c:\windows\system32\dskquoui.dll
[Scan path] c:\windows\system32\dsquery.dll
[Scan path] c:\windows\system32\dssec.dll
[Scan path] c:\windows\system32\dsuiext.dll
[Scan path] c:\windows\system32\extmgr.dll
[Scan path] c:\windows\system32\fontext.dll
[Scan path] c:\windows\system32\gdi32.dll
[Scan path] c:\windows\system32\hptcpmon.dll
[Scan path] c:\windows\system32\hpzipm12.exe
[Scan path] c:\windows\system32\hticons.dll
[Scan path] c:\windows\system32\icmui.dll
[Scan path] c:\windows\system32\ie4uinit.exe
[Scan path] c:\windows\system32\iedkcs32.dll
[Scan path] c:\windows\system32\ieframe.dll
[Scan path] c:\windows\system32\ieudinit.exe
[Scan path] c:\windows\system32\imagehlp.dll
[Scan path] c:\windows\system32\imapi.exe
[Scan path] c:\windows\system32\inetcomm.dll
[Scan path] c:\windows\system32\itss.dll
[Scan path] c:\windows\system32\kerberos.dll
[Scan path] c:\windows\system32\kernel32.dll
[Scan path] c:\windows\system32\localspl.dll
[Scan path] c:\windows\system32\locator.exe
[Scan path] c:\windows\system32\logonui.exe
[Scan path] c:\windows\system32\lsass.exe
[Scan path] c:\windows\system32\lz32.dll
[Scan path] c:\windows\system32\mmcshext.dll
[Scan path] c:\windows\system32\mmsys.cpl
[Scan path] c:\windows\system32\mnmsrvc.exe
[Scan path] c:\windows\system32\mscoree.dll
[Scan path] c:\windows\system32\mscories.dll
[Scan path] c:\windows\system32\msdtc.exe
[Scan path] c:\windows\system32\mshtml.dll
[Scan path] c:\windows\system32\msieftp.dll
[Scan path] c:\windows\system32\msiexec.exe
[Scan path] c:\windows\system32\mstask.dll
[Scan path] c:\windows\system32\msv1_0.dll
[Scan path] c:\windows\system32\msvidctl.dll
[Scan path] c:\windows\system32\mswsock.dll
[Scan path] c:\windows\system32\mydocs.dll
[Scan path] c:\windows\system32\netdde.exe
[Scan path] c:\windows\system32\netplwiz.dll
[Scan path] c:\windows\system32\netshell.dll
[Scan path] c:\windows\system32\notepad.exe
[Scan path] c:\windows\system32\ntlanui2.dll
[Scan path] c:\windows\system32\ntsd.exe
[Scan path] c:\windows\system32\ntshrui.dll
[Scan path] c:\windows\system32\nvcpl.dll
[Scan path] c:\windows\system32\nvshell.dll
[Scan path] c:\windows\system32\nvsvc32.exe
[Scan path] c:\windows\system32\occache.dll
[Scan path] c:\windows\system32\ole32.dll
[Scan path] c:\windows\system32\oleaut32.dll
[Scan path] c:\windows\system32\olecli32.dll
[Scan path] c:\windows\system32\olecnv32.dll
[Scan path] c:\windows\system32\olesvr32.dll
[Scan path] c:\windows\system32\olethk32.dll
[Scan path] c:\windows\system32\photowiz.dll
[Scan path] c:\windows\system32\pjlmon.dll
[Scan path] c:\windows\system32\printui.dll
[Scan path] c:\windows\system32\regsvr32.exe
[Scan path] c:\windows\system32\remotepg.dll
[Scan path] c:\windows\system32\rpcrt4.dll
[Scan path] c:\windows\system32\rpcss.dll
[Scan path] c:\windows\system32\rshx32.dll
[Scan path] c:\windows\system32\rsvp.exe
[Scan path] c:\windows\system32\rsvpsp.dll
[Scan path] c:\windows\system32\rundll32.exe
[Scan path] c:\windows\system32\scardsvr.exe
[Scan path] c:\windows\system32\scecli.dll
[Scan path] c:\windows\system32\schannel.dll
[Scan path] c:\windows\system32\sclgntfy.dll
[Scan path] c:\windows\system32\sendmail.dll
[Scan path] c:\windows\system32\services.exe
[Scan path] c:\windows\system32\sessmgr.exe
[Scan path] c:\windows\system32\setup\fxsocm.dll
[Scan path] c:\windows\system32\shdocvw.dll
[Scan path] c:\windows\system32\shell32.dll
[Scan path] c:\windows\system32\shellvrtf.dll
[Scan path] c:\windows\system32\shimgvw.dll
[Scan path] c:\windows\system32\shmedia.dll
[Scan path] c:\windows\system32\shmgrate.exe
[Scan path] c:\windows\system32\shscrap.dll
[Scan path] c:\windows\system32\slayerxp.dll
[Scan path] c:\windows\system32\smlogsvc.exe
[Scan path] c:\windows\system32\smss.exe
[Scan path] c:\windows\system32\spoolsv.exe
[Scan path] c:\windows\system32\stobject.dll
[Scan path] c:\windows\system32\svchost.exe
[Scan path] c:\windows\system32\syncui.dll
[Scan path] c:\windows\system32\tcpmon.dll
[Scan path] c:\windows\system32\themeui.dll
[Scan path] c:\windows\system32\twext.dll
[Scan path] c:\windows\system32\ups.exe
[Scan path] c:\windows\system32\url.dll
[Scan path] c:\windows\system32\urlmon.dll
[Scan path] c:\windows\system32\usbmon.dll
[Scan path] c:\windows\system32\user32.dll
[Scan path] c:\windows\system32\version.dll
[Scan path] c:\windows\system32\vssvc.exe
[Scan path] c:\windows\system32\wbem\wmiapsrv.exe
[Scan path] c:\windows\system32\wdigest.dll
[Scan path] c:\windows\system32\webcheck.dll
[Scan path] c:\windows\system32\wiascr.dll
[Scan path] c:\windows\system32\wiashext.dll
[Scan path] c:\windows\system32\wininet.dll
[Scan path] c:\windows\system32\winlogon.exe
[Scan path] c:\windows\system32\wldap32.dll
[Scan path] c:\windows\system32\wlnotify.dll
[Scan path] c:\windows\system32\wmpshell.dll
[Scan path] c:\windows\system32\wpdshext.dll
[Scan path] c:\windows\system32\wpdshserviceobj.dll
[Scan path] c:\windows\system32\wshext.dll
[Scan path] c:\windows\system32\wuaucpl.cpl
[Scan path] c:\windows\system32\xpsshhdr.dll
[Scan path] c:\windows\system32\zipfldr.dll
[Scan path] c:\windows\vvx6000.exe
[Scan path] g:\programmer\sikkerhed\drweb-cureit.exe
Avatar billede faus Praktikant
12. februar 2007 - 13:49 #3
forsat:
Scan statistics
-----------------------------------------------------------------------------
Objects scanned: 337
Infected objects found: 0
Objects with modifications found: 0
Suspicious objects found: 1
Adware programs found: 0
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 0
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 0
Objects renamed: 0
Objects moved: 0
Objects ignored: 0
Scan speed: 1244 Kb/s
Scan time: 00:01:20
-----------------------------------------------------------------------------

c:\programmer\tdc kabel tv sikkerhedspakke\fwes\program\fsdfwd.exe - deleted

[Scan path] C:\
C:\Documents and Settings\HP_Ejer\NTUSER.DAT - read error
C:\Documents and Settings\HP_Ejer\NTUSER~1.LOG - read error

Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\enterprize@oncable.dk\DFSR\Staging\CS{9C5D5626-4130-DAE7-44A9-6A8352BFD7B3}\01\16-{9C5D5626-4130-DAE7-44A9-6A8352BFD7B3}-v1-{3D7F71E1-3E92-4646-BE53-A43687E8E239}-v16-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\enterprize@oncable.dk\DFSR\Staging\CS{9C5D5626-4130-DAE7-44A9-6A8352BFD7B3}\11\11-{D71DE333-988E-4B11-A055-991A41CDE81C}-v11-{D71DE333-988E-4B11-A055-991A41CDE81C}-v11-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\enterprize@oncable.dk\DFSR\Staging\CS{9C5D5626-4130-DAE7-44A9-6A8352BFD7B3}\12\12-{D71DE333-988E-4B11-A055-991A41CDE81C}-v12-{D71DE333-988E-4B11-A055-991A41CDE81C}-v12-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\enterprize@oncable.dk\DFSR\Staging\CS{9C5D5626-4130-DAE7-44A9-6A8352BFD7B3}\13\13-{D71DE333-988E-4B11-A055-991A41CDE81C}-v13-{D71DE333-988E-4B11-A055-991A41CDE81C}-v13-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\enterprize@oncable.dk\DFSR\Staging\CS{9C5D5626-4130-DAE7-44A9-6A8352BFD7B3}\14\14-{D71DE333-988E-4B11-A055-991A41CDE81C}-v14-{D71DE333-988E-4B11-A055-991A41CDE81C}-v14-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\enterprize@oncable.dk\DFSR\Staging\CS{9C5D5626-4130-DAE7-44A9-6A8352BFD7B3}\15\15-{D71DE333-988E-4B11-A055-991A41CDE81C}-v15-{D71DE333-988E-4B11-A055-991A41CDE81C}-v15-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\enterprize@oncable.dk\DFSR\Staging\CS{9C5D5626-4130-DAE7-44A9-6A8352BFD7B3}\16\16-{D71DE333-988E-4B11-A055-991A41CDE81C}-v16-{D71DE333-988E-4B11-A055-991A41CDE81C}-v16-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\enterprize@oncable.dk\DFSR\Staging\CS{9C5D5626-4130-DAE7-44A9-6A8352BFD7B3}\17\17-{D71DE333-988E-4B11-A055-991A41CDE81C}-v17-{D71DE333-988E-4B11-A055-991A41CDE81C}-v17-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\enterprize@oncable.dk\DFSR\Staging\CS{9C5D5626-4130-DAE7-44A9-6A8352BFD7B3}\18\18-{D71DE333-988E-4B11-A055-991A41CDE81C}-v18-{D71DE333-988E-4B11-A055-991A41CDE81C}-v18-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\enterprize@oncable.dk\DFSR\Staging\CS{9C5D5626-4130-DAE7-44A9-6A8352BFD7B3}\19\19-{D71DE333-988E-4B11-A055-991A41CDE81C}-v19-{D71DE333-988E-4B11-A055-991A41CDE81C}-v19-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\enterprize@oncable.dk\DFSR\Staging\CS{9C5D5626-4130-DAE7-44A9-6A8352BFD7B3}\20\20-{3D7F71E1-3E92-4646-BE53-A43687E8E239}-v20-{3D7F71E1-3E92-4646-BE53-A43687E8E239}-v20-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\enterprize@oncable.dk\DFSR\Staging\CS{9C5D5626-4130-DAE7-44A9-6A8352BFD7B3}\20\20-{D71DE333-988E-4B11-A055-991A41CDE81C}-v20-{D71DE333-988E-4B11-A055-991A41CDE81C}-v20-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\enterprize@oncable.dk\DFSR\Staging\CS{9C5D5626-4130-DAE7-44A9-6A8352BFD7B3}\21\21-{3D7F71E1-3E92-4646-BE53-A43687E8E239}-v21-{3D7F71E1-3E92-4646-BE53-A43687E8E239}-v21-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\enterprize@oncable.dk\DFSR\Staging\CS{9C5D5626-4130-DAE7-44A9-6A8352BFD7B3}\21\21-{D71DE333-988E-4B11-A055-991A41CDE81C}-v21-{D71DE333-988E-4B11-A055-991A41CDE81C}-v21-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\enterprize@oncable.dk\DFSR\Staging\CS{9C5D5626-4130-DAE7-44A9-6A8352BFD7B3}\22\22-{3D7F71E1-3E92-4646-BE53-A43687E8E239}-v22-{3D7F71E1-3E92-4646-BE53-A43687E8E239}-v22-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\enterprize@oncable.dk\DFSR\Staging\CS{9C5D5626-4130-DAE7-44A9-6A8352BFD7B3}\22\22-{D71DE333-988E-4B11-A055-991A41CDE81C}-v22-{D71DE333-988E-4B11-A055-991A41CDE81C}-v22-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\enterprize@oncable.dk\DFSR\Staging\CS{9C5D5626-4130-DAE7-44A9-6A8352BFD7B3}\23\23-{D71DE333-988E-4B11-A055-991A41CDE81C}-v23-{D71DE333-988E-4B11-A055-991A41CDE81C}-v23-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\enterprize@oncable.dk\DFSR\Staging\CS{9C5D5626-4130-DAE7-44A9-6A8352BFD7B3}\24\24-{D71DE333-988E-4B11-A055-991A41CDE81C}-v24-{D71DE333-988E-4B11-A055-991A41CDE81C}-v24-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\enterprize@oncable.dk\DFSR\Staging\CS{9C5D5626-4130-DAE7-44A9-6A8352BFD7B3}\25\25-{D71DE333-988E-4B11-A055-991A41CDE81C}-v25-{D71DE333-988E-4B11-A055-991A41CDE81C}-v25-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\enterprize@oncable.dk\DFSR\Staging\CS{9C5D5626-4130-DAE7-44A9-6A8352BFD7B3}\26\26-{D71DE333-988E-4B11-A055-991A41CDE81C}-v26-{D71DE333-988E-4B11-A055-991A41CDE81C}-v26-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\flemming_11@msn.com\DFSR\Staging\CS{B9180D1B-15C8-B6B4-3BE5-7FBCF52B44AE}\01\11-{B9180D1B-15C8-B6B4-3BE5-7FBCF52B44AE}-v1-{3D7F71E1-3E92-4646-BE53-A43687E8E239}-v11-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\flemming_11@msn.com\DFSR\Staging\CS{B9180D1B-15C8-B6B4-3BE5-7FBCF52B44AE}\14\14-{3D7F71E1-3E92-4646-BE53-A43687E8E239}-v14-{3D7F71E1-3E92-4646-BE53-A43687E8E239}-v14-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\flemming_11@msn.com\DFSR\Staging\CS{B9180D1B-15C8-B6B4-3BE5-7FBCF52B44AE}\24\24-{7FE96E3C-53DE-4567-B3D6-03D06F60F0BE}-v24-{7FE96E3C-53DE-4567-B3D6-03D06F60F0BE}-v24-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\flemming_11@msn.com\DFSR\Staging\CS{B9180D1B-15C8-B6B4-3BE5-7FBCF52B44AE}\25\25-{7FE96E3C-53DE-4567-B3D6-03D06F60F0BE}-v25-{7FE96E3C-53DE-4567-B3D6-03D06F60F0BE}-v25-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\flemming_11@msn.com\DFSR\Staging\CS{B9180D1B-15C8-B6B4-3BE5-7FBCF52B44AE}\34\34-{7FE96E3C-53DE-4567-B3D6-03D06F60F0BE}-v34-{7FE96E3C-53DE-4567-B3D6-03D06F60F0BE}-v34-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\flemming_11@msn.com\DFSR\Staging\CS{B9180D1B-15C8-B6B4-3BE5-7FBCF52B44AE}\35\35-{7FE96E3C-53DE-4567-B3D6-03D06F60F0BE}-v35-{7FE96E3C-53DE-4567-B3D6-03D06F60F0BE}-v35-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\flemming_11@msn.com\DFSR\Staging\CS{B9180D1B-15C8-B6B4-3BE5-7FBCF52B44AE}\36\36-{7FE96E3C-53DE-4567-B3D6-03D06F60F0BE}-v36-{7FE96E3C-53DE-4567-B3D6-03D06F60F0BE}-v36-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\flemming_11@msn.com\DFSR\Staging\CS{B9180D1B-15C8-B6B4-3BE5-7FBCF52B44AE}\37\37-{7FE96E3C-53DE-4567-B3D6-03D06F60F0BE}-v37-{7FE96E3C-53DE-4567-B3D6-03D06F60F0BE}-v37-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\flemming_11@msn.com\DFSR\Staging\CS{B9180D1B-15C8-B6B4-3BE5-7FBCF52B44AE}\38\38-{7FE96E3C-53DE-4567-B3D6-03D06F60F0BE}-v38-{7FE96E3C-53DE-4567-B3D6-03D06F60F0BE}-v38-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\kajabej@hotmail.com\DFSR\Staging\CS{DA2C9974-ADC5-36CF-CA90-F0376F1B9EC4}\01\10-{DA2C9974-ADC5-36CF-CA90-F0376F1B9EC4}-v1-{3D7F71E1-3E92-4646-BE53-A43687E8E239}-v10-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\kajabej@hotmail.com\DFSR\Staging\CS{DA2C9974-ADC5-36CF-CA90-F0376F1B9EC4}\26\14-{7D1C664C-5B3E-48F9-9EEF-A4C1D6591C19}-v26-{3CCA82B0-67CF-40A7-B8D9-569E75F0B791}-v14-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\kajabej@hotmail.com\DFSR\Staging\CS{DA2C9974-ADC5-36CF-CA90-F0376F1B9EC4}\27\15-{7D1C664C-5B3E-48F9-9EEF-A4C1D6591C19}-v27-{3CCA82B0-67CF-40A7-B8D9-569E75F0B791}-v15-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\kajabej@hotmail.com\DFSR\Staging\CS{DA2C9974-ADC5-36CF-CA90-F0376F1B9EC4}\28\16-{7D1C664C-5B3E-48F9-9EEF-A4C1D6591C19}-v28-{3CCA82B0-67CF-40A7-B8D9-569E75F0B791}-v16-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\kajabej@hotmail.com\DFSR\Staging\CS{DA2C9974-ADC5-36CF-CA90-F0376F1B9EC4}\29\17-{7D1C664C-5B3E-48F9-9EEF-A4C1D6591C19}-v29-{3CCA82B0-67CF-40A7-B8D9-569E75F0B791}-v17-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\kajabej@hotmail.com\DFSR\Staging\CS{DA2C9974-ADC5-36CF-CA90-F0376F1B9EC4}\30\18-{7D1C664C-5B3E-48F9-9EEF-A4C1D6591C19}-v30-{3CCA82B0-67CF-40A7-B8D9-569E75F0B791}-v18-Downloaded.frx
Invalid path to file C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Messenger\faus255@hotmail.com\SharingMetadata\kajabej@hotmail.com\DFSR\Staging\CS{DA2C9974-ADC5-36CF-CA90-F0376F1B9EC4}\31\19-{7D1C664C-5B3E-48F9-9EEF-A4C1D6591C19}-v31-{3CCA82B0-67CF-40A7-B8D9-569E75F0B791}-v19-Downloaded.frx
C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat - read error
C:\Documents and Settings\HP_Ejer\Lokale indstillinger\Application Data\Microsoft\Windows\USRCLA~1.LOG - read error
C:\Documents and Settings\NetworkService\NTUSER.DAT - read error
C:\Documents and Settings\NetworkService\NTUSER~1.LOG - read error
C:\Documents and Settings\NetworkService\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat - read error
C:\Documents and Settings\NetworkService\Lokale indstillinger\Application Data\Microsoft\Windows\USRCLA~1.LOG - read error
C:\WINDOWS\system32\config\default - read error
C:\WINDOWS\system32\config\default.LOG - read error
C:\WINDOWS\system32\config\SAM - read error
C:\WINDOWS\system32\config\SAM.LOG - read error
C:\WINDOWS\system32\config\SECURITY - read error
C:\WINDOWS\system32\config\SECURITY.LOG - read error
C:\WINDOWS\system32\config\software - read error
C:\WINDOWS\system32\config\software.LOG - read error
C:\WINDOWS\system32\config\system - read error
C:\WINDOWS\system32\config\system.LOG - read error

[Scan path] D:\
[Scan path] F:\
[Scan path] G:\
-----------------------------------------------------------------------------
Scan statistics
-----------------------------------------------------------------------------
Objects scanned: 93935
Infected objects found: 0
Objects with modifications found: 0
Suspicious objects found: 0
Adware programs found: 0
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 0
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 0
Objects renamed: 0
Objects moved: 0
Objects ignored: 0
Scan speed: 441 Kb/s
Scan time: 01:05:05
-----------------------------------------------------------------------------

=============================================================================
Total session statistics
=============================================================================
Objects scanned: 94272
Infected objects found: 0
Objects with modifications found: 0
Suspicious objects found: 1
Adware programs found: 0
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 0
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 1
Objects renamed: 0
Objects moved: 0
Objects ignored: 0
Scan speed: 457 Kb/s
Scan time: 01:06:25
====================================================================
Avatar billede faus Praktikant
12. februar 2007 - 13:50 #4
Superantispyware log:

SUPERAntiSpyware Scan Log
Generated 02/12/2007 at 12:53 PM

Application Version : 3.3.1020

Core Rules Database Version : 3182
Trace Rules Database Version: 1192

Scan type      : Complete Scan
Total Scan Time : 00:30:13

Memory items scanned      : 193
Memory threats detected  : 0
Registry items scanned    : 5596
Registry threats detected : 0
File items scanned        : 5264
File threats detected    : 1

Adware.Tracking Cookie
    C:\Documents and Settings\HP_Ejer\Cookies\hp_ejer@track.adform[2].txt


--------------------------------------------------------
Og Rootlog:
********************************* ROOTCHK-LOG, by ejvindh
12-02-2007 13:18:57,75

The rootkits that are detected by this tool were not found.

********************************* ROOTCHK-LOG-end


Det var dem:-)
Avatar billede ejvindh Ekspert
12. februar 2007 - 14:04 #5
Der er ikke noget at komme efter i dine logs. Det er muligt, at det er firewallen, der spærrer for dine online-scans.

Men hvis jeg skal være ærlig, så tror jeg ikke de alligevel ville finde noget, som SAS og Dr.Web ikke kan finde ;-)
Avatar billede faus Praktikant
12. februar 2007 - 14:19 #6
okey.  Takker for gennemsyndet .   
Point til " ejvindh"

Træd afsluttet...
Avatar billede ejvindh Ekspert
12. februar 2007 - 14:22 #7
Du er velkommen.
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester