Avatar billede Nesta Juniormester
29. august 2007 - 17:06 Der er 21 kommentarer og
1 løsning

Virus-problemer

Hej

Jeg har desværre fået noget virus/spyware på min PC.

Jeg har prøvet med Ad-Aware, AVG Anti-Spyware 7.5, Norton Antivirus 2007, Housecall, Xmicro og XoftSpySE.

Den sidste fandt flere cookies. En af mange var WinAntivirus Cookie. Den har jeg slettet flere gange, men kommer hele tiden igen.

Jeg har samlet dette billede. En af mine virusser/spyware er ErrorSafe.

Link 1: http://img407.imageshack.us/img407/2756/62295650wh7.jpg

1: Den kommer nok som følge af ErrorSafe.

2: Jeg tror denne (Downloader.MisleadApp) er fejlen til det hele. Norton fortæller mig hele tiden,
at denne forsøger at bryde ind i systemet. Af den grund kan jeg heller ikke aktivere Ultimate defender/fixer/cleaner i Personal Security Center (billedet i link 2).

3: Det billed kommer på alle Internetsider. Nok pga. ErrorSafe.

4: Det sidste kommer også, når jeg åbner Internet Explorer. Klikker jeg luk, så lukker den alle vinduer ned.

Link 2: http://img407.imageshack.us/img407/6840/51434927hg0.jpg

Her er Personal Security Center. Jeg kan ikke aktivere dem pga. Downloader.MisleadApp

Eksempelvis kan jeg heller ikke gå ind på siden www.frip.dk - den siger "Not enough storage is available to complete this operation."

Hvad kan jeg gøre ved det? Har fået at vide, at jeg skal formatere, men man må kunne fjerne den virus.

Her er logfil fra HiJackThis.

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 16:26:36, on 29-08-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
C:\Programmer\Fælles filer\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
D:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
D:\Programmer\X-Micro\Bluetooth-software\bin\btwdins.exe
D:\Programmer\KSE\nHancer 32bit\nHancerService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\regsvr32.exe
C:\Programmer\SecCenter\scprot4.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Fælles filer\Ahead\Lib\NMBgMonitor.exe
D:\Programmer\X-Micro\Bluetooth-software\BTTray.exe
C:\Programmer\Fælles filer\Ahead\Lib\NMIndexingService.exe
C:\Programmer\Fælles filer\Ahead\Lib\NMIndexStoreSvr.exe
D:\Programmer\Mirc\mirc.exe
C:\Programmer\MSN Messenger\usnsvc.exe
D:\Programmer\Adobe\Reader\AcroRd32.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\SecCenter\scprot4.exe
D:\Downloads\HiJackThis_v2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.dk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sol.dk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sol.dk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sol.dk
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3F5E9987-FD12-408E-3612-018845CDF059} - C:\Programmer\Kjmkkwap\bxqlmdsy.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5621007F-BBEE-4674-8077-94C3591DE7C3} - C:\WINDOWS\system32\nnnnlig.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {B3FB97CE-E687-4771-AACB-985AE82BF295} - C:\WINDOWS\system32\geedd.dll
O2 - BHO: (no name) - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC} - C:\WINDOWS\system32\ssaqqnqi.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Programmer\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Programmer\Adobe\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmer\Fælles filer\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [gzupoved] rundll32.exe "C:\Programmer\gzupoved\wvkredcl.dll",Init
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\owrepueq.dll",forkonce
O4 - HKLM\..\Run: [gbefczkx] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\gbefczkx.dll"
O4 - HKLM\..\Run: [SC2] C:\Programmer\SecCenter\scprot4.exe
O4 - HKLM\..\RunServices: [Microsoft] uzjswsu.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmer\Fælles filer\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://F:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send til &Bluetooth - D:\Programmer\X-Micro\Bluetooth-software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Subscribe in NewzCrawler - file://D:\Programmer\Newzcrawler\NewzCrawler\context.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Newz Crawler - {CA7C41C8-5C9D-4A03-A101-B0AA4F0C3ABC} - D:\Programmer\Newzcrawler\NewzCrawler\News.exe
O9 - Extra 'Tools' menuitem: Newz Crawler - {CA7C41C8-5C9D-4A03-A101-B0AA4F0C3ABC} - D:\Programmer\Newzcrawler\NewzCrawler\News.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Programmer\X-Micro\Bluetooth-software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Programmer\X-Micro\Bluetooth-software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O20 - Winlogon Notify: geedd - C:\WINDOWS\system32\geedd.dll
O20 - Winlogon Notify: nnnnlig - C:\WINDOWS\SYSTEM32\nnnnlig.dll
O20 - Winlogon Notify: winzdn32 - C:\WINDOWS\SYSTEM32\winzdn32.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - D:\Programmer\X-Micro\Bluetooth-software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec IS – Godkendelse af adgangskoder (ISPwdSvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NBService - Nero AG - C:\Programmer\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: nHancer Support (nHancer) - KSE - Korndörfer Software Engineering - D:\Programmer\KSE\nHancer 32bit\nHancerService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programmer\Fælles filer\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\AppCore\AppSvc32.exe

--
End of file - 8596 bytes
Avatar billede arlet Juniormester
29. august 2007 - 17:15 #1
kigger på den
Avatar billede arlet Juniormester
29. august 2007 - 17:24 #2
Der er meget snavs...

kør trin 1 og 4 herfra: http://www.malwarecheck.dk/forum/viewtopic.php?t=11
Kopier log´ne herind..

derefter:
Hent Combofix, og gem den på dit skrivebord:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Kør så combofix.exe, og følg vejledningen i vinduet.

Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når combofix er færdig, og efter det har genstartet, skulle der gerne åbnes en logfil: combofix.txt som kan findes her-C:\combofix.txt

Kopier også denne log her ind.
Avatar billede Nesta Juniormester
29. august 2007 - 18:14 #3
Hej

Beklager jeg ikke lige fik svaret. Gik dog i gang med det samme.

- SuperAnti-Spyware kom med en log:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 08/29/2007 at 05:46 PM

Application Version : 3.9.1008

Core Rules Database Version : 3294
Trace Rules Database Version: 1305

Scan type      : Quick Scan
Total Scan Time : 00:14:57

Memory items scanned      : 574
Memory threats detected  : 4
Registry items scanned    : 795
Registry threats detected : 24
File items scanned        : 17582
File threats detected    : 86

Adware.Vundo Variant
    C:\WINDOWS\SYSTEM32\GEEDD.DLL
    C:\WINDOWS\SYSTEM32\GEEDD.DLL
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B3FB97CE-E687-4771-AACB-985AE82BF295}
    HKCR\CLSID\{B3FB97CE-E687-4771-AACB-985AE82BF295}
    HKCR\CLSID\{B3FB97CE-E687-4771-AACB-985AE82BF295}\InprocServer32
    HKCR\CLSID\{B3FB97CE-E687-4771-AACB-985AE82BF295}\InprocServer32#ThreadingModel
    Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\geedd

Trojan.Mezzia/Resident
    C:\WINDOWS\SYSTEM32\WINZDN32.DLL
    C:\WINDOWS\SYSTEM32\WINZDN32.DLL

Adware.Vundo Variant/Resident
    C:\WINDOWS\SYSTEM32\NNNNLIG.DLL
    C:\WINDOWS\SYSTEM32\NNNNLIG.DLL

Trojan.Downloader-PSCMain
    C:\PROGRAMMER\SECCENTER\SCPROT4.EXE
    C:\PROGRAMMER\SECCENTER\SCPROT4.EXE
    [SC2] C:\PROGRAMMER\SECCENTER\SCPROT4.EXE
    C:\WINDOWS\Prefetch\SCPROT4.EXE-25EB2D6E.pf

Trojan.Downloader-Gen/HitItQuitIt
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5621007F-BBEE-4674-8077-94C3591DE7C3}
    HKCR\CLSID\{5621007F-BBEE-4674-8077-94C3591DE7C3}
    HKCR\CLSID\{5621007F-BBEE-4674-8077-94C3591DE7C3}\InprocServer32
    HKCR\CLSID\{5621007F-BBEE-4674-8077-94C3591DE7C3}\InprocServer32#ThreadingModel
    HKCR\CLSID\{5621007F-BBEE-4674-8077-94C3591DE7C3}\TreatAs
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{5621007F-BBEE-4674-8077-94C3591DE7C3}
    Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\nnnnlig

Unclassified.Unknown Origin
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C6039E6C-BDE9-4de5-BB40-768CAA584FDC}
    HKCR\CLSID\{C6039E6C-BDE9-4DE5-BB40-768CAA584FDC}
    HKCR\CLSID\{C6039E6C-BDE9-4DE5-BB40-768CAA584FDC}\InprocServer32
    HKCR\CLSID\{C6039E6C-BDE9-4DE5-BB40-768CAA584FDC}\InprocServer32#ThreadingModel
    HKCR\CLSID\{C6039E6C-BDE9-4DE5-BB40-768CAA584FDC}\TreatAs
    C:\WINDOWS\SYSTEM32\SSAQQNQI.DLL
    HKCR\CLSID\{C6039E6C-BDE9-4DE5-BB40-768CAA584FDC}

Trojan.Downloader-Win/GHY
    Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\winzdn32

Adware.Tracking Cookie
    C:\Documents and Settings\Fogh\Cookies\fogh@doubleclick[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@burstnet[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@4.adbrite[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@www.pornvideos[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@clickbank[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@cassava[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@e2.emediate[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@ad.bolddk[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@banner.centrebet[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@drivecleaner[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@goal.adbureau[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@dk.drivecleaner[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@hit.stat[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@cpvfeed[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@stat.postdanmark[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@eas.apm.emediate[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@888[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@ads2.gamereactor[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@qxl.banneradministration[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@ad1.clickhype[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@cgi-bin[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@goclick[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@banner.fynskemedier[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@stats.channel4[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@pulz.banneradministration[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@partygaming.122.2o7[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@atdmt[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@1070076147[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@richmedia.yahoo[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@sexdebut[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@server.cpmstar[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@www.livewebstats[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@3.adbrite[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@stats.drivecleaner[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@stats1.reliablestats[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@adtech[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@adv.boomer[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@ads.us.e-planning[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@sport1[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@ads.gamershell[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@tradedoubler[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@clicktorrent[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@a[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@cgi-bin[3].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@ad.zanox[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@smileycentral[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@67.15.239[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@cgi-bin[6].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@anad.tacoda[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@dk.winantivirus[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@adfair[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@partypoker[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@sport1-de[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@tipsbladet.banneradministration[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@adbrite[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@s[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@advertising[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@av018l6[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@feed[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@ad.yieldmanager[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@1068415716[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@1072707600[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@67.15.239[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@enhance[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@zedo[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@ads2.d1g[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@media.movies.ign[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@online.adservicemedia[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@valueclick[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@mediaplex[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@cgi-bin[5].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@statcounter[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@fastclick[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@winantivirus[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@ad[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@ads.globalsportsmedia[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@interclick[2].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@clicksor[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@adecn[1].txt
    C:\Documents and Settings\Fogh\Cookies\fogh@track.adform[1].txt

Trojan.Unknown Origin
    HKLM\SOFTWARE\Microsoft\MSSMGR
    HKLM\SOFTWARE\Microsoft\MSSMGR#Brnd
    HKLM\SOFTWARE\Microsoft\MSSMGR#BSTV
    HKLM\SOFTWARE\Microsoft\MSSMGR#SSTV



- Rogue-Remover kom ikke med en log. Den sagde dog, at den ikke fandt fejl.

- Combofix kom med en log:

[code]
2007-05-12 14:41      104    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Fogh\APPLIC~1\Microsoft\Internet Explorer\Quick Launch\INTERN~1.LNK.vir
2007-08-28 12:44      6448    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\ddeeg.bak1.vir
2007-08-29 00:44      638499    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\ddeeg.bak2.vir
2007-08-29 00:49      125504    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\owrepueq.dll.vir
2007-08-29 16:58      218528    --a------    C:\Qoobox\Quarantine\C\ComboFix\ComboFix.bat.vir
2007-08-29 17:38      661147    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\ddeeg.tmp.vir
2007-08-29 17:48      661147    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\ddeeg.ini2.vir
2007-08-29 18:03      646    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\qeuperwo.ini.vir
2007-08-29 18:05      846    --a------    C:\Qoobox\Quarantine\Registry_backups\LEGACY_DOMAINSERVICE.reg.cf
2007-08-29 18:09      592161    --a------    C:\Qoobox\snapshot_2007-08-29_180910.10.cf


Mappetr‘
Diskenhedens serienummer er 00080188 40B9:94DD
C:\QOOBOX
|  snapshot_2007-08-29_180910.10.cf

\---Quarantine
    +---C
    |  +---ComboFix
    |  |      ComboFix.bat.vir
    |  |     
    |  +---DOCUME~1
    |  |  \---Fogh
    |  |      \---APPLIC~1
    |  |          \---Microsoft
    |  |              \---Internet Explorer
    |  |                  \---Quick Launch
    |  |                          INTERN~1.LNK.vir
    |  |                         
    |  \---WINDOWS
    |      \---system32
    |              ddeeg.bak1.vir
    |              ddeeg.bak2.vir
    |              ddeeg.ini2.vir
    |              ddeeg.tmp.vir
    |              owrepueq.dll.vir
    |              qeuperwo.ini.vir
    |             
    \---Registry_backups
            LEGACY_DOMAINSERVICE.reg.cf
           
[/code]

På forhånd tak for hjælpen.

Mvh Martin
Avatar billede Nesta Juniormester
29. august 2007 - 18:18 #4
Den kommer ikke med en fejlmelding nu og lader til ErrorSafe er væk.

Jeg har dog lige et spørgsmål mere.

Vælg din bærbare PC fra Dell.

Hvorfor ser tegnene sådan ud? AltsåÆ, Ø og Å.
Avatar billede arlet Juniormester
29. august 2007 - 18:34 #5
Jeg skal lige se en ny hijackthis log

og du skal lige køre combofix en gang til og komme med en ny log
Avatar billede Nesta Juniormester
29. august 2007 - 18:49 #6
HiJackThis:

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 18:40:50, on 29-08-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
C:\Programmer\Fælles filer\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
D:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\Programmer\X-Micro\Bluetooth-software\bin\btwdins.exe
D:\Programmer\KSE\nHancer 32bit\nHancerService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\regsvr32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Fælles filer\Ahead\Lib\NMBgMonitor.exe
D:\Programmer\X-Micro\Bluetooth-software\BTTray.exe
C:\Programmer\Fælles filer\Ahead\Lib\NMIndexingService.exe
C:\Programmer\Fælles filer\Ahead\Lib\NMIndexStoreSvr.exe
C:\Programmer\internet explorer\iexplore.exe
D:\Downloads\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sol.dk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sol.dk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sol.dk
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3F5E9987-FD12-408E-3612-018845CDF059} - C:\Programmer\Kjmkkwap\bxqlmdsy.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Programmer\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Programmer\Adobe\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmer\Fælles filer\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [gzupoved] rundll32.exe "C:\Programmer\gzupoved\wvkredcl.dll",Init
O4 - HKLM\..\Run: [gbefczkx] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\gbefczkx.dll"
O4 - HKLM\..\RunServices: [Microsoft] uzjswsu.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmer\Fælles filer\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://F:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send til &Bluetooth - D:\Programmer\X-Micro\Bluetooth-software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Subscribe in NewzCrawler - file://D:\Programmer\Newzcrawler\NewzCrawler\context.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Newz Crawler - {CA7C41C8-5C9D-4A03-A101-B0AA4F0C3ABC} - D:\Programmer\Newzcrawler\NewzCrawler\News.exe
O9 - Extra 'Tools' menuitem: Newz Crawler - {CA7C41C8-5C9D-4A03-A101-B0AA4F0C3ABC} - D:\Programmer\Newzcrawler\NewzCrawler\News.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Programmer\X-Micro\Bluetooth-software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Programmer\X-Micro\Bluetooth-software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O20 - Winlogon Notify: !SASWinLogon - D:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - D:\Programmer\X-Micro\Bluetooth-software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec IS – Godkendelse af adgangskoder (ISPwdSvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NBService - Nero AG - C:\Programmer\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: nHancer Support (nHancer) - KSE - Korndörfer Software Engineering - D:\Programmer\KSE\nHancer 32bit\nHancerService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programmer\Fælles filer\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\AppCore\AppSvc32.exe

--
End of file - 7853 bytes

ComboFix:

ComboFix 07-08-29.3 - "Fogh" 2007-08-29 18:42:49.2 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1030.18.1064 [GMT 2:00]


(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\Fogh\APPLIC~1\microsoft\internet explorer\quick launch\intern~1.lnk


(((((((((((((((((((((((((  Files Created from 2007-07-28 to 2007-08-29  )))))))))))))))))))))))))))))))


2007-08-29 18:03    51,200    --a------    C:\WINDOWS\nircmd.exe
2007-08-29 17:57    <DIR>    d--------    C:\WINDOWS\pss
2007-08-29 17:29    <DIR>    d--------    C:\DOCUME~1\Fogh\APPLIC~1\SUPERAntiSpyware.com
2007-08-29 17:29    <DIR>    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-08-29 14:29    10,872    --a------    C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-08-29 12:28    102,400    --a------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\gbefczkx.dll
2007-08-29 12:28    <DIR>    d--------    C:\WINDOWS\system32\wdqpokti
2007-08-27 17:35    <DIR>    d--hs----    C:\WINDOWS\ftpcache
2007-08-26 21:56    <DIR>    d--------    C:\DOCUME~1\Fogh\APPLIC~1\dvdcss
2007-08-26 21:49    <DIR>    d--------    C:\Program Files
2007-08-16 14:53    <DIR>    d--------    C:\DOCUME~1\Fogh\APPLIC~1\nHancer
2007-08-16 14:39    <DIR>    d--------    C:\WINDOWS\system32\URTTemp
2007-08-03 11:16    <DIR>    d--------    C:\Programmer\MSXML 4.0
2007-08-02 14:45    <DIR>    d--------    C:\DOCUME~1\Fogh\APPLIC~1\Ahead
2007-08-02 14:45    <DIR>    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
2007-08-02 14:43    <DIR>    d--------    C:\Programmer\Nero
2007-08-02 14:43    <DIR>    d--------    C:\Programmer\F‘lles filer\Ahead
2007-08-02 14:43    <DIR>    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
2007-07-31 16:09    <DIR>    d--------    C:\DOCUME~1\Fogh\Bluetooth Software
2007-07-31 16:07    100,992    --a--c---    C:\WINDOWS\system32\dllcache\bthpan.sys
2007-07-31 16:07    100,992    --a------    C:\WINDOWS\system32\drivers\bthpan.sys


((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-29 15:40    ---------    d--------    C:\DOCUME~1\Fogh\APPLIC~1\uTorrent
2007-08-21 21:44    ---------    d--h-----    C:\Programmer\InstallShield Installation Information
2007-07-30 19:19    92504    --a------    C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19    549720    --a------    C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19    53080    --a------    C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19    43352    --a------    C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19    325976    --a------    C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19    203096    --a------    C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19    1712984    --a------    C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18    33624    --a------    C:\WINDOWS\system32\wups.dll
2007-07-01 16:15    ---------    d--------    C:\DOCUME~1\Fogh\APPLIC~1\Locktime
2007-07-01 16:14    ---------    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Locktime
2007-06-29 01:54    356352    --a------    C:\WINDOWS\system32\nvusmb.exe
2007-06-29 01:54    356352    --a------    C:\WINDOWS\system32\nvunrm.exe
2007-06-29 01:54    356352    --a------    C:\WINDOWS\system32\NVUNINST.EXE
2007-06-29 01:54    356352    --a------    C:\WINDOWS\system32\nvuide.exe
2007-06-29 01:54    356352    --a------    C:\WINDOWS\system32\nvudisp.exe
2007-06-29 00:43    8466432    --a------    C:\WINDOWS\system32\nvcpl.dll
2007-06-29 00:43    81920    --a------    C:\WINDOWS\system32\nvwddi.dll
2007-06-29 00:43    81920    --a------    C:\WINDOWS\system32\nvmctray.dll
2007-06-29 00:43    753664    --a------    C:\WINDOWS\system32\nvcplui.exe
2007-06-29 00:43    6807328    --a------    C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-06-29 00:43    6729728    --a------    C:\WINDOWS\system32\nvoglnt.dll
2007-06-29 00:43    6234112    --a------    C:\WINDOWS\system32\nvdisps.dll
2007-06-29 00:43    5690624    --a------    C:\WINDOWS\system32\nv4_disp.dll
2007-06-29 00:43    5455872    --a------    C:\WINDOWS\system32\nvdispsr.dll
2007-06-29 00:43    466944    --a------    C:\WINDOWS\system32\nvshell.dll
2007-06-29 00:43    458752    --a------    C:\WINDOWS\system32\nvmccssr.dll
2007-06-29 00:43    45056    --a------    C:\WINDOWS\system32\nvmccsrs.dll
2007-06-29 00:43    442368    --a------    C:\WINDOWS\system32\nvappbar.exe
2007-06-29 00:43    425984    --a------    C:\WINDOWS\system32\keystone.exe
2007-06-29 00:43    37376    --a------    C:\WINDOWS\system32\nvcodins.dll
2007-06-29 00:43    37376    --a------    C:\WINDOWS\system32\nvcod.dll
2007-06-29 00:43    360448    --a------    C:\WINDOWS\system32\nvapi.dll
2007-06-29 00:43    3600384    --a------    C:\WINDOWS\system32\nvvitvsr.dll
2007-06-29 00:43    3518464    --a------    C:\WINDOWS\system32\nvvitvs.dll
2007-06-29 00:43    3321856    --a------    C:\WINDOWS\system32\nvgames.dll
2007-06-29 00:43    3072000    --a------    C:\WINDOWS\system32\nvgamesr.dll
2007-06-29 00:43    307200    --a------    C:\WINDOWS\system32\nvexpbar.dll
2007-06-29 00:43    286720    --a------    C:\WINDOWS\system32\nvnt4cpl.dll
2007-06-29 00:43    2854912    --a------    C:\WINDOWS\system32\nvmoblsr.dll
2007-06-29 00:43    2416640    --a------    C:\WINDOWS\system32\nvwssr.dll
2007-06-29 00:43    2330624    --a------    C:\WINDOWS\system32\nvwss.dll
2007-06-29 00:43    229376    --a------    C:\WINDOWS\system32\nvmccs.dll
2007-06-29 00:43    188416    --a------    C:\WINDOWS\system32\nvmccss.dll
2007-06-29 00:43    1703936    --a------    C:\WINDOWS\system32\nvwdmcpl.dll
2007-06-29 00:43    1626112    --a------    C:\WINDOWS\system32\nwiz.exe
2007-06-29 00:43    155716    --a------    C:\WINDOWS\system32\nvsvc32.exe
2007-06-29 00:43    1474560    --a------    C:\WINDOWS\system32\nview.dll
2007-06-29 00:43    147456    --a------    C:\WINDOWS\system32\nvcolor.exe
2007-06-29 00:43    1339392    --a------    C:\WINDOWS\system32\nvdspsch.exe
2007-06-29 00:43    1142784    --a------    C:\WINDOWS\system32\nvmobls.dll
2007-06-29 00:43    1073152    --a------    C:\WINDOWS\system32\nvcpluir.dll
2007-06-29 00:43    1019904    --a------    C:\WINDOWS\system32\nvwimg.dll
2007-06-29 00:43    1018772    --a------    C:\WINDOWS\system32\nvucode.bin
2007-06-26 08:10    1104896    --a------    C:\WINDOWS\system32\msxml3.dll
2007-06-19 15:32    282112    --a------    C:\WINDOWS\system32\gdi32.dll
2007-06-15 20:20    108144    --a------    C:\WINDOWS\system32\CmdLineExt.dll
2007-06-13 15:22    280064    -r-hs----    C:\WINDOWS\system32\uzjswsu.exe
2007-06-13 15:22    1034240    --a------    C:\WINDOWS\explorer.exe
    ---------        C:\Programmer\Fælles filer\Wise Installation Wizard
    ---------        C:\Programmer\Fælles filer\Symantec Shared
    ---------        C:\Programmer\Fælles filer\Ahead
    ---------        C:\Programmer\Fælles filer


(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3F5E9987-FD12-408E-3612-018845CDF059}]
            C:\Programmer\Kjmkkwap\bxqlmdsy.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-29 00:43]
"nwiz"="nwiz.exe" [2007-06-29 00:43 C:\WINDOWS\system32\nwiz.exe]
"CTHelper"="CTHELPER.EXE" [2003-10-06 15:57 C:\WINDOWS\system32\CTHELPER.EXE]
"ccApp"="C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe" []
"osCheck"="C:\Programmer\Norton AntiVirus\osCheck.exe" [2006-09-05 19:22]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"Adobe Reader Speed Launcher"="D:\Programmer\Adobe\Reader\Reader_sl.exe" [2007-05-11 03:06]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-27 14:00 C:\WINDOWS\system32\bthprops.cpl]
"NeroFilterCheck"="C:\Programmer\Fælles filer\Ahead\Lib\NeroCheck.exe" []
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-29 00:43]
"gzupoved"="C:\Programmer\gzupoved\wvkredcl.dll" []
"gbefczkx"="regsvr32 /u C:\Documents and Settings\All Users\Application Data\gbefczkx.dll" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 14:00]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programmer\Fælles filer\Ahead\Lib\NMBgMonitor.exe" []

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"Microsoft"=uzjswsu.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= D:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
D:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 D:\Programmer\SUPERAntiSpyware\SASWINLO.dll

R0 SI3132;SiI-3132 SATALink Controller;C:\WINDOWS\system32\DRIVERS\SI3132.sys
R2 Automatisk LiveUpdate-planlægning;Automatisk LiveUpdate-planlægning;"C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe"
R2 nHancer;nHancer Support;"D:\Programmer\KSE\nHancer 32bit\nHancerService.exe"


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
AutoRun\command- F:\setup\rsrc\Autorun.exe
dinstall\command- F:\Directx\dxsetup.exe


Contents of the 'Scheduled Tasks' folder
2007-08-24 18:13:09 C:\WINDOWS\Tasks\Norton AntiVirus - Kør fuld systemskanning - Fogh.job
2007-08-29 16:07:22 C:\WINDOWS\Tasks\XoftSpySE 2.job
2007-08-29 13:17:44 C:\WINDOWS\Tasks\XoftSpySE.job - D:\Programmer\XoftSpySE\XoftSpy.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-29 18:44:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-29 18:45:35
C:\ComboFix-quarantined-files.txt ... 2007-08-29 18:45

    --- E O F ---

Havde du et svar på de her tegn: "Vælg din bærbare PC fra Dell" ?
29. august 2007 - 18:59 #7
*SUK* Sådan ka' det let gå når man 'leger' med P2P programmer:
C:\DOCUME~1\Fogh\APPLIC~1\uTorrent

Der er meget tilbage endnu!

<arlet>: Du fortsætter bare...
Avatar billede Nesta Juniormester
29. august 2007 - 19:05 #8
Haha. uTorrent er et must have :)
Avatar billede Nesta Juniormester
29. august 2007 - 19:09 #9
Og i øvrigt er det ikke den vej, at virussen(erne) er kommet =)
Avatar billede arlet Juniormester
29. august 2007 - 19:13 #10
Kopiér indholdet mellem de bølgede linier ind i et notepad-vindue, og gem indholdet i samme mappe, som Combofix ligger med navnet CFScript.txt.
Når du gemmer, skal du sikre, at der under "filtyper" står "alle filer".

-------------------------

Folder::
C:\Programmer\gzupoved
C:\Programmer\Kjmkkwap
File::
C:\WINDOWS\system32\wdqpokti
C:\DOCUME~1\Fogh\APPLIC~1\uTorrent
C:\WINDOWS\system32\uzjswsu.exe
C:\Documents and Settings\All Users\Application Data\gbefczkx.dl
Registry::

-------------------------

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen. - http://peecee.dk/?id=60784
Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.

Kopier indholdet af Combofix.txt her ind.

Derudover laver du en ny hijackthis log
Avatar billede Nesta Juniormester
29. august 2007 - 19:25 #11
De bølgede linjer?

((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))


Er det teksten under ovennænvte?
Avatar billede arlet Juniormester
29. august 2007 - 19:38 #12
nej, undskyld..

Det er de stiplede linjer i mit indlæg over folder og under registry
Avatar billede Nesta Juniormester
29. august 2007 - 19:51 #13
Den bad ikke om reboot efter jeg brugte ComboFix.

ComboFix 07-08-29.3 - "Fogh" 2007-08-29 19:46:15.3 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1030.18.1030 [GMT 2:00]
Command switches used ::  D:\Programmer\ComboFix\CFScript.txt
* Created a new restore point

FILE::
C:\WINDOWS\system32\wdqpokti
C:\DOCUME~1\Fogh\APPLIC~1\uTorrent
C:\WINDOWS\system32\uzjswsu.exe
C:\Documents and Settings\All Users\Application Data\gbefczkx.dl


(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\Fogh\APPLIC~1\microsoft\internet explorer\quick launch\intern~1.lnk
C:\WINDOWS\system32\uzjswsu.exe


(((((((((((((((((((((((((  Files Created from 2007-07-28 to 2007-08-29  )))))))))))))))))))))))))))))))


2007-08-29 18:03    51,200    --a------    C:\WINDOWS\nircmd.exe
2007-08-29 17:57    <DIR>    d--------    C:\WINDOWS\pss
2007-08-29 17:29    <DIR>    d--------    C:\DOCUME~1\Fogh\APPLIC~1\SUPERAntiSpyware.com
2007-08-29 17:29    <DIR>    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-08-29 14:29    10,872    --a------    C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-08-27 17:35    <DIR>    d--hs----    C:\WINDOWS\ftpcache
2007-08-26 21:56    <DIR>    d--------    C:\DOCUME~1\Fogh\APPLIC~1\dvdcss
2007-08-26 21:49    <DIR>    d--------    C:\Program Files
2007-08-16 14:53    <DIR>    d--------    C:\DOCUME~1\Fogh\APPLIC~1\nHancer
2007-08-16 14:39    <DIR>    d--------    C:\WINDOWS\system32\URTTemp
2007-08-03 11:16    <DIR>    d--------    C:\Programmer\MSXML 4.0
2007-08-02 14:45    <DIR>    d--------    C:\DOCUME~1\Fogh\APPLIC~1\Ahead
2007-08-02 14:45    <DIR>    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
2007-08-02 14:43    <DIR>    d--------    C:\Programmer\Nero
2007-08-02 14:43    <DIR>    d--------    C:\Programmer\F‘lles filer\Ahead
2007-08-02 14:43    <DIR>    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
2007-07-31 16:09    <DIR>    d--------    C:\DOCUME~1\Fogh\Bluetooth Software
2007-07-31 16:07    100,992    --a--c---    C:\WINDOWS\system32\dllcache\bthpan.sys
2007-07-31 16:07    100,992    --a------    C:\WINDOWS\system32\drivers\bthpan.sys


((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-29 19:12    ---------    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-21 21:44    ---------    d--h-----    C:\Programmer\InstallShield Installation Information
2007-07-30 19:19    92504    --a------    C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19    549720    --a------    C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19    53080    --a------    C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19    43352    --a------    C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19    325976    --a------    C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19    203096    --a------    C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19    1712984    --a------    C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18    33624    --a------    C:\WINDOWS\system32\wups.dll
2007-07-01 16:15    ---------    d--------    C:\DOCUME~1\Fogh\APPLIC~1\Locktime
2007-07-01 16:14    ---------    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Locktime
2007-06-29 01:54    356352    --a------    C:\WINDOWS\system32\nvusmb.exe
2007-06-29 01:54    356352    --a------    C:\WINDOWS\system32\nvunrm.exe
2007-06-29 01:54    356352    --a------    C:\WINDOWS\system32\NVUNINST.EXE
2007-06-29 01:54    356352    --a------    C:\WINDOWS\system32\nvuide.exe
2007-06-29 01:54    356352    --a------    C:\WINDOWS\system32\nvudisp.exe
2007-06-29 00:43    8466432    --a------    C:\WINDOWS\system32\nvcpl.dll
2007-06-29 00:43    81920    --a------    C:\WINDOWS\system32\nvwddi.dll
2007-06-29 00:43    81920    --a------    C:\WINDOWS\system32\nvmctray.dll
2007-06-29 00:43    753664    --a------    C:\WINDOWS\system32\nvcplui.exe
2007-06-29 00:43    6807328    --a------    C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-06-29 00:43    6729728    --a------    C:\WINDOWS\system32\nvoglnt.dll
2007-06-29 00:43    6234112    --a------    C:\WINDOWS\system32\nvdisps.dll
2007-06-29 00:43    5690624    --a------    C:\WINDOWS\system32\nv4_disp.dll
2007-06-29 00:43    5455872    --a------    C:\WINDOWS\system32\nvdispsr.dll
2007-06-29 00:43    466944    --a------    C:\WINDOWS\system32\nvshell.dll
2007-06-29 00:43    458752    --a------    C:\WINDOWS\system32\nvmccssr.dll
2007-06-29 00:43    45056    --a------    C:\WINDOWS\system32\nvmccsrs.dll
2007-06-29 00:43    442368    --a------    C:\WINDOWS\system32\nvappbar.exe
2007-06-29 00:43    425984    --a------    C:\WINDOWS\system32\keystone.exe
2007-06-29 00:43    37376    --a------    C:\WINDOWS\system32\nvcodins.dll
2007-06-29 00:43    37376    --a------    C:\WINDOWS\system32\nvcod.dll
2007-06-29 00:43    360448    --a------    C:\WINDOWS\system32\nvapi.dll
2007-06-29 00:43    3600384    --a------    C:\WINDOWS\system32\nvvitvsr.dll
2007-06-29 00:43    3518464    --a------    C:\WINDOWS\system32\nvvitvs.dll
2007-06-29 00:43    3321856    --a------    C:\WINDOWS\system32\nvgames.dll
2007-06-29 00:43    3072000    --a------    C:\WINDOWS\system32\nvgamesr.dll
2007-06-29 00:43    307200    --a------    C:\WINDOWS\system32\nvexpbar.dll
2007-06-29 00:43    286720    --a------    C:\WINDOWS\system32\nvnt4cpl.dll
2007-06-29 00:43    2854912    --a------    C:\WINDOWS\system32\nvmoblsr.dll
2007-06-29 00:43    2416640    --a------    C:\WINDOWS\system32\nvwssr.dll
2007-06-29 00:43    2330624    --a------    C:\WINDOWS\system32\nvwss.dll
2007-06-29 00:43    229376    --a------    C:\WINDOWS\system32\nvmccs.dll
2007-06-29 00:43    188416    --a------    C:\WINDOWS\system32\nvmccss.dll
2007-06-29 00:43    1703936    --a------    C:\WINDOWS\system32\nvwdmcpl.dll
2007-06-29 00:43    1626112    --a------    C:\WINDOWS\system32\nwiz.exe
2007-06-29 00:43    155716    --a------    C:\WINDOWS\system32\nvsvc32.exe
2007-06-29 00:43    1474560    --a------    C:\WINDOWS\system32\nview.dll
2007-06-29 00:43    147456    --a------    C:\WINDOWS\system32\nvcolor.exe
2007-06-29 00:43    1339392    --a------    C:\WINDOWS\system32\nvdspsch.exe
2007-06-29 00:43    1142784    --a------    C:\WINDOWS\system32\nvmobls.dll
2007-06-29 00:43    1073152    --a------    C:\WINDOWS\system32\nvcpluir.dll
2007-06-29 00:43    1019904    --a------    C:\WINDOWS\system32\nvwimg.dll
2007-06-29 00:43    1018772    --a------    C:\WINDOWS\system32\nvucode.bin
2007-06-26 08:10    1104896    --a------    C:\WINDOWS\system32\msxml3.dll
2007-06-19 15:32    282112    --a------    C:\WINDOWS\system32\gdi32.dll
2007-06-15 20:20    108144    --a------    C:\WINDOWS\system32\CmdLineExt.dll
2007-06-13 15:22    1034240    --a------    C:\WINDOWS\explorer.exe
    ---------        C:\Programmer\Fælles filer\Wise Installation Wizard
    ---------        C:\Programmer\Fælles filer\Symantec Shared
    ---------        C:\Programmer\Fælles filer\Ahead
    ---------        C:\Programmer\Fælles filer


(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3F5E9987-FD12-408E-3612-018845CDF059}]
            C:\Programmer\Kjmkkwap\bxqlmdsy.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-29 00:43]
"nwiz"="nwiz.exe" [2007-06-29 00:43 C:\WINDOWS\system32\nwiz.exe]
"CTHelper"="CTHELPER.EXE" [2003-10-06 15:57 C:\WINDOWS\system32\CTHELPER.EXE]
"ccApp"="C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe" []
"osCheck"="C:\Programmer\Norton AntiVirus\osCheck.exe" [2006-09-05 19:22]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"Adobe Reader Speed Launcher"="D:\Programmer\Adobe\Reader\Reader_sl.exe" [2007-05-11 03:06]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-27 14:00 C:\WINDOWS\system32\bthprops.cpl]
"NeroFilterCheck"="C:\Programmer\Fælles filer\Ahead\Lib\NeroCheck.exe" []
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-29 00:43]
"gzupoved"="C:\Programmer\gzupoved\wvkredcl.dll" []
"gbefczkx"="regsvr32 /u C:\Documents and Settings\All Users\Application Data\gbefczkx.dll" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 14:00]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programmer\Fælles filer\Ahead\Lib\NMBgMonitor.exe" []

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"Microsoft"=uzjswsu.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= D:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
D:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 D:\Programmer\SUPERAntiSpyware\SASWINLO.dll

R0 SI3132;SiI-3132 SATALink Controller;C:\WINDOWS\system32\DRIVERS\SI3132.sys
R2 Automatisk LiveUpdate-planlægning;Automatisk LiveUpdate-planlægning;"C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe"
R2 nHancer;nHancer Support;"D:\Programmer\KSE\nHancer 32bit\nHancerService.exe"


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
AutoRun\command- F:\setup\rsrc\Autorun.exe
dinstall\command- F:\Directx\dxsetup.exe


Contents of the 'Scheduled Tasks' folder
2007-08-24 18:13:09 C:\WINDOWS\Tasks\Norton AntiVirus - Kør fuld systemskanning - Fogh.job
2007-08-29 16:07:22 C:\WINDOWS\Tasks\XoftSpySE 2.job
2007-08-29 13:17:44 C:\WINDOWS\Tasks\XoftSpySE.job - D:\Programmer\XoftSpySE\XoftSpy.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-29 19:47:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-29 19:48:19
C:\ComboFix-quarantined-files.txt ... 2007-08-29 19:48

    --- E O F ---

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 19:49:05, on 29-08-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
C:\Programmer\Fælles filer\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
D:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\Programmer\X-Micro\Bluetooth-software\bin\btwdins.exe
D:\Programmer\KSE\nHancer 32bit\nHancerService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\regsvr32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Fælles filer\Ahead\Lib\NMBgMonitor.exe
D:\Programmer\X-Micro\Bluetooth-software\BTTray.exe
C:\Programmer\Fælles filer\Ahead\Lib\NMIndexingService.exe
C:\Programmer\Fælles filer\Ahead\Lib\NMIndexStoreSvr.exe
C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\explorer.exe
D:\Downloads\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sol.dk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sol.dk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sol.dk
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3F5E9987-FD12-408E-3612-018845CDF059} - C:\Programmer\Kjmkkwap\bxqlmdsy.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Programmer\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Programmer\Adobe\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmer\Fælles filer\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [gzupoved] rundll32.exe "C:\Programmer\gzupoved\wvkredcl.dll",Init
O4 - HKLM\..\Run: [gbefczkx] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\gbefczkx.dll"
O4 - HKLM\..\RunServices: [Microsoft] uzjswsu.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmer\Fælles filer\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://F:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send til &Bluetooth - D:\Programmer\X-Micro\Bluetooth-software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Subscribe in NewzCrawler - file://D:\Programmer\Newzcrawler\NewzCrawler\context.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Newz Crawler - {CA7C41C8-5C9D-4A03-A101-B0AA4F0C3ABC} - D:\Programmer\Newzcrawler\NewzCrawler\News.exe
O9 - Extra 'Tools' menuitem: Newz Crawler - {CA7C41C8-5C9D-4A03-A101-B0AA4F0C3ABC} - D:\Programmer\Newzcrawler\NewzCrawler\News.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Programmer\X-Micro\Bluetooth-software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Programmer\X-Micro\Bluetooth-software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O20 - Winlogon Notify: !SASWinLogon - D:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - D:\Programmer\X-Micro\Bluetooth-software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec IS – Godkendelse af adgangskoder (ISPwdSvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NBService - Nero AG - C:\Programmer\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: nHancer Support (nHancer) - KSE - Korndörfer Software Engineering - D:\Programmer\KSE\nHancer 32bit\nHancerService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programmer\Fælles filer\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\AppCore\AppSvc32.exe

--
End of file - 7597 bytes
Avatar billede Nesta Juniormester
29. august 2007 - 20:01 #14
C:\WINDOWS\system32\uzjswsu.exe
C:\Documents and Settings\All Users\Application Data\gbefczkx.dl

Så vidt jeg kan se, så mangler de 2 at blive fjernet.
Avatar billede Nesta Juniormester
29. august 2007 - 20:07 #15
Har prøvet at gå ind i selve mapperne.

gbefczkx.dl kan ikke slettes, da den siger, filen er i brug.

uzjswsu.exe kan jeg ikke finde.
Avatar billede arlet Juniormester
29. august 2007 - 20:11 #16
Hent Avenger ned til skrivebordet her fra:
http://swandog46.geekstogo.com/avenger.exe

1. Dobbeltklik på avenger.exe

2. Sæt en prik i "Input Script Manually" og klik på Luppen - nu dukker der et lille vindue op, hvor du skal kopiere indholdet mellem de stiplede linier ind:

-----------------------------

Files to delete:
C:\WINDOWS\system32\wdqpokti
C:\DOCUME~1\Fogh\APPLIC~1\uTorrent
C:\WINDOWS\system32\uzjswsu.exe
C:\Documents and Settings\All Users\Application Data\gbefczkx.dl

Files to replace with dummy:

Files to move:

Folders to delete:

Registry keys to delete:

Registry keys to replace with dummy:

Registry values to delete:

Registry values to replace with dummy:

Programs to launch on reboot:

Drivers to unload:

-----------------------------

3. Klik på Trafiklyset i Avenger. Programmet vil opfordre dig til at genstarte computeren straks, hvilket du skal gøre. Programmet vil lukke din computer, slette filerne og starte computeren igen.

4. Efter genstarten vil der dukke et notepad-vindue op, med en log for Avengers handlinger. Den må du gerne lægge ind i dit næste svar sammen med en ny hijackthis
Avatar billede Nesta Juniormester
29. august 2007 - 20:23 #17
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\xdqauyqn

*******************

Script file located at: ibfdkmfc

Could not open script file!  Error

Could not open script file!  Status: 0xc000003b  Abort!

------

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 20:22:41, on 29-08-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
C:\Programmer\Fælles filer\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\rundll32.exe
D:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\Programmer\Adobe\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Fælles filer\Ahead\Lib\NMBgMonitor.exe
D:\Programmer\X-Micro\Bluetooth-software\BTTray.exe
D:\Programmer\X-Micro\Bluetooth-software\bin\btwdins.exe
D:\Programmer\KSE\nHancer 32bit\nHancerService.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmer\Fælles filer\Ahead\Lib\NMIndexingService.exe
C:\Programmer\Fælles filer\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wuauclt.exe
D:\Downloads\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sol.dk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sol.dk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sol.dk
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3F5E9987-FD12-408E-3612-018845CDF059} - C:\Programmer\Kjmkkwap\bxqlmdsy.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Programmer\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmer\Fælles filer\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Programmer\Adobe\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmer\Fælles filer\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://F:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send til &Bluetooth - D:\Programmer\X-Micro\Bluetooth-software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Subscribe in NewzCrawler - file://D:\Programmer\Newzcrawler\NewzCrawler\context.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Newz Crawler - {CA7C41C8-5C9D-4A03-A101-B0AA4F0C3ABC} - D:\Programmer\Newzcrawler\NewzCrawler\News.exe
O9 - Extra 'Tools' menuitem: Newz Crawler - {CA7C41C8-5C9D-4A03-A101-B0AA4F0C3ABC} - D:\Programmer\Newzcrawler\NewzCrawler\News.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Programmer\X-Micro\Bluetooth-software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Programmer\X-Micro\Bluetooth-software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O20 - Winlogon Notify: !SASWinLogon - D:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - D:\Programmer\X-Micro\Bluetooth-software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec IS – Godkendelse af adgangskoder (ISPwdSvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NBService - Nero AG - C:\Programmer\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: nHancer Support (nHancer) - KSE - Korndörfer Software Engineering - D:\Programmer\KSE\nHancer 32bit\nHancerService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programmer\Fælles filer\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\AppCore\AppSvc32.exe

--
End of file - 7427 bytes
Avatar billede arlet Juniormester
29. august 2007 - 20:36 #18
Så er der kun rester tilbage..

Kør Hijackthis, scan, sæt flueben ved linien/linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked, luk hijackthis igen.

O2 - BHO: (no name) - {3F5E9987-FD12-408E-3612-018845CDF059} - C:\Programmer\Kjmkkwap\bxqlmdsy.dll (file missing)

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

Genstart og loggen er ren..

Som afslutning, så kør lige trin 5 og 6 herfra: http://www.malwarecheck.dk/forum/viewtopic.php?t=11
Avatar billede Nesta Juniormester
29. august 2007 - 20:37 #19
http://img112.imageshack.us/img112/8813/xoftio0.jpg

Jeg har lige brugt XoftSpySE igen. Hvad kan det være, at den stadig finder alt dette?
Avatar billede arlet Juniormester
29. august 2007 - 20:47 #20
Det skulle ewido gerne tage: kør trin 2 herfra: http://www.malwarecheck.dk/forum/viewtopic.php?t=11
Avatar billede Nesta Juniormester
29. august 2007 - 21:17 #21
Okay. Mange tak for hjælpen.

Nu kører den igen. Kan desværre kun gi' 200 point for al bøvlet :)
Avatar billede arlet Juniormester
29. august 2007 - 21:36 #22
For at sikre at winfixer osv ikke kommer mere, så se her: http://www.malwarecheck.dk/forum/viewtopic.php?t=17<

Læs vores sikkerhedspakke her: http://www.malwarecheck.dk/forum/viewtopic.php?t=156
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester