Avatar billede area48 Nybegynder
11. februar 2007 - 02:56 Der er 6 kommentarer og
1 løsning

Logfile vedr. HijackThis v1.99.1 - Win32:Brontok-I

Igår oplyste mit Avast antivirus program mig om at min computer var inficeret med ovenstående. Jeg foretog en system-restore (det er en Dell maskine) og gik igang med at få det hele til at fungere igen.
Da jeg var ved at være færdig fik jeg samme besked af Avast, som lagde filerne i Avast Viruskiste...
Jeg ved ikke om det er nok eller om jeg muligvis stadig er inficeret med denne lille irriterende orm.
Håber derfor at en ekspert har lyst/mulighed for at kigge nærmere på min HijackThis log for at se om der skal foretages yderligere:

På forhånd tak..

Logfile of HijackThis v1.99.1
Scan saved at 02:53:01, on 11-02-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Programmer\r\CyberLink\PowerDVD\DVDLauncher.exe
C:\Programmer\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programmer\WinPortrait\wpctrl.exe
C:\Programmer\ATI Technologies\ATI.ACE\CLI.EXE
C:\Programmer\Picasa2\PicasaMediaDetector.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\WinPortrait\floater.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\Programmer\ATI Technologies\ATI.ACE\cli.exe
C:\Programmer\ATI Technologies\ATI.ACE\cli.exe
C:\Programmer\MSN Messenger\usnsvc.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\XXX\Skrivebord\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ni.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Programmer\r\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Programmer\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FÆLLES~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Programmer\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [PivotSoftware] "C:\Programmer\WinPortrait\wpctrl.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Programmer\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Unknown owner - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: avast! Antivirus - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Programmer\Intel\PROSetWired\NCS\Sync\NetSvc.exe
Avatar billede levich Nybegynder
11. februar 2007 - 16:25 #1
Jeg ser på det, øjeblik.
Avatar billede levich Nybegynder
11. februar 2007 - 16:33 #2
Der ser ikke ud til at være noget galt, men for at være lidt mere sikker, så hent http://www.spywarefri.dk/downloads1/ewido-setup.exe (AVG Anti-Spyware).
Installer programmer og opdater det, scan, fix de ting som den finder og kopier loggen herind.
Avatar billede area48 Nybegynder
11. februar 2007 - 16:52 #3
Takker for hjælpen... Her er Rapporten:

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on:            16:51:17, 11-02-2007
+ Report-Checksum:        514B5E62

+ Scan result:

    :mozilla.10:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
    :mozilla.11:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
    :mozilla.12:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
    :mozilla.23:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    :mozilla.26:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.27:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.28:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.29:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.77:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.78:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.84:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Masterstats : Cleaned with backup
    :mozilla.87:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
    :mozilla.89:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Adbrite : Cleaned with backup
    :mozilla.90:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Adbrite : Cleaned with backup
    :mozilla.91:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Adbrite : Cleaned with backup
    :mozilla.94:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.95:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.96:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.97:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.98:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.99:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.100:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.101:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.102:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    :mozilla.103:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    :mozilla.104:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.105:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    :mozilla.106:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.107:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.108:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.109:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.110:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.111:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.113:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.115:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.116:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    :mozilla.117:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.136:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
    :mozilla.161:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.162:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.163:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.164:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.165:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.166:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
    :mozilla.179:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Adbrite : Cleaned with backup
    :mozilla.211:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
    :mozilla.212:C:\Documents and Settings\Tom Unkerskov\Application Data\Mozilla\Firefox\Profiles\hfcs0xzb.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
    C:\Documents and Settings\Tom Unkerskov\Cookies\tom_unkerskov@adtech[2].txt -> Spyware.Cookie.Adtech : Cleaned with backup
    C:\Documents and Settings\Tom Unkerskov\Cookies\tom_unkerskov@advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
    C:\Documents and Settings\Tom Unkerskov\Cookies\tom_unkerskov@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
    C:\Documents and Settings\Tom Unkerskov\Cookies\tom_unkerskov@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    C:\Documents and Settings\Tom Unkerskov\Cookies\tom_unkerskov@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
    C:\i386\MRT.exe -> Heuristic.Win32.AVKiller : Cleaned with backup
    C:\WINDOWS\SoftwareDistribution\Download\cc13848f6a7026148bab98a1b3410d8f0d36fd48/mrt.exe -> Heuristic.Win32.AVKiller : Error during cleaning
    C:\WINDOWS\SoftwareDistribution\Download\cc13848f6a7026148bab98a1b3410d8f0d36fd48/mrt.exe -> Heuristic.Win32.AVKiller : Error during cleaning
    C:\WINDOWS\system32\MRT.exe -> Heuristic.Win32.AVKiller : Cleaned with backup


::Report End
Avatar billede levich Nybegynder
11. februar 2007 - 18:24 #4
Du skal ikke foretage dig yderligt.
Avatar billede area48 Nybegynder
11. februar 2007 - 21:15 #5
Tusinde tak for hjælpen!! Det er mere end fornemt!
Avatar billede area48 Nybegynder
11. februar 2007 - 21:16 #6
håber at velfortjente point er overført korrekt!
Avatar billede levich Nybegynder
11. februar 2007 - 21:35 #7
Jeps, de er overført.
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester