Avatar billede djgreg Nybegynder
31. oktober 2007 - 21:16 Der er 31 kommentarer og
1 løsning

Så kan den hijackes

For at være på den sikre side lader jeg lige en ekspert klare den alligevel.

Jeg gider ikke høre fra folk der ikke gider hjælpe mig alligevel... Så hvis du ønsker at hjælpe, skriv gerne, hvis du ikke gider, hold dig væk.  Jeg ved godt der er meget ja, og jeg ved godt jeg ikke har service pack-tingen. Skriv gerne link til det.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:14, on 2007-10-31
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Programmer\Internet Explorer\IEXPLORE.EXE
D:\Programmer\Internet Explorer\IEXPLORE.EXE
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\Programmer\Antiy Labs\Alive\ALiveCenter.exe
D:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\Programmer\iTunes\iTunesHelper.exe
D:\Programmer\QuickTime\qttask.exe
D:\WINDOWS\System32\spoolsvv.exe
D:\Programmer\MSN Messenger\msnmsgr.exe
D:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\Programmer\Trend Micro\PC-cillin 2002\Tmntsrv.exe
D:\WINDOWS\System32\wdfmgr.exe
D:\WINDOWS\System32\MsPMSPSv.exe
D:\Programmer\Canon\CAL\CALMAIN.exe
D:\Programmer\Trend Micro\PC-cillin 2002\PCCPFW.exe
D:\Programmer\iPod\bin\iPodService.exe
D:\Programmer\MSN Messenger\usnsvc.exe
D:\Programmer\iTunes\iTunes.exe
D:\Programmer\Mozilla Firefox\firefox.exe
D:\Documents and Settings\André\Skrivebord\HiJackThis.exe
D:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://kingkongsearch.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dr.dk/sporten
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://85.255.113.67/privacyWarning.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
F2 - REG:system.ini: UserInit=D:\WINDOWS\system32\userinit.exe,D:\WINDOWS\System32\ntos.exe,
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - D:\Programmer\NewDotNet\newdotnet7_48.dll (file missing)
O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - D:\Programmer\Need2Find\bar\1.bin\ND2FNBAR.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\programmer\google\googletoolbar1.dll
O2 - BHO: XBTB06823 - {BA463437-C3DE-47da-8280-87596824388A} - D:\PROGRA~1\GOOGLE~1\TOOLBA~1.DLL
O2 - BHO: e404 helper - {F10587E9-0E47-4CBE-84AE-7DD20B8684BB} - D:\Programmer\E404 Helper\e404.v1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\programmer\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "D:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [net32] D:\WINDOWS\svhost.exe
O4 - HKLM\..\Run: [net64] D:\WINDOWS\svhoster.exe
O4 - HKLM\..\Run: [netsv32] D:\WINDOWS\sv.exe
O4 - HKLM\..\Run: [netzip] D:\WINDOWS\svzip.exe
O4 - HKLM\..\Run: [BearFlix] "D:\Programmer\BearFlix\BearFlix.exe" /pause
O4 - HKLM\..\Run: [netc] D:\WINDOWS\svc.exe
O4 - HKLM\..\Run: [runsql] D:\WINDOWS\runsql.exe
O4 - HKLM\..\Run: [spoolsvv] D:\WINDOWS\System32\spoolsvv.exe
O4 - HKCU\..\Run: [msnmsgr] "D:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [WhenUSave] "D:\Programmer\Save\Save.exe"
O4 - HKCU\..\Run: [swg] D:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [noskrnl] D:\WINDOWS\noskrnl.exe
O4 - HKCU\..\Run: [Firewall auto setup] D:\DOCUME~1\ANDR~1\LOKALE~1\Temp\winlogon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\Run: [Ordbogen.com] D:\Programmer\CoolSystems\ordbogen.com\ordbogen.exe (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: ClickOff.lnk = D:\Programmer\ClickOff\Clickoff.exe
O8 - Extra context menu item: Add to AMV Convert Tool... - D:\Programmer\MP3 Player Utilities 3.79\AMVConverter\grab.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - D:\Programmer\MP3 Player Utilities 3.79\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmer\Java\jre1.5.0_10\bin\npjpi150_10.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmer\Java\jre1.5.0_10\bin\npjpi150_10.dll
O9 - Extra button: Opret Foretrukken på mobil enhed - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Opret Foretrukken på mobil enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmer\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: D:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) - https://netbank.bgbank.dk/html/activex/BG/Menu.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1133301966077
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.bgbank.dk/html/activex/e-Safekey/BG/e-Safekey.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O20 - Winlogon Notify: botreg - D:\Documents and Settings\All Users\Dokumenter\Settings\bot.dll
O20 - Winlogon Notify: comloy - comloy.dll (file missing)
O20 - Winlogon Notify: partnershipreg - D:\Documents and Settings\All Users\Dokumenter\Settings\partnership.dll
O21 - SSODL: DCOM Server 25319 - {2C1CD3D7-86AC-4068-93BC-A02304B25319} - (no file)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Gatewaytjeneste til programlaget ALGuploadmgr (ALGuploadmgr) - Unknown owner - D:\WINDOWS\System32\a3dj.exe (file missing)
O23 - Service: Antiy live update (Alive Auto-Update Service) - Unknown owner - D:\Programmer\Antiy Labs\Alive\ALiveCenter.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - D:\Programmer\Canon\CAL\CALMAIN.exe
O23 - Service: Hændelseslog EventlogNla (EventlogNla) - Unknown owner - D:\WINDOWS\System32\advpackf.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - D:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: COM-tjenesten IMAPI cd-skrivning ImapiServiceALG (ImapiServiceALG) - Unknown owner - D:\WINDOWS\System32\1031l.exe (file missing)
O23 - Service: iPod Service - Apple Computer, Inc. - D:\Programmer\iPod\bin\iPodService.exe
O23 - Service: Messenger MessengerSSDPSRV (MessengerSSDPSRV) - Unknown owner - D:\WINDOWS\System32\advapi32b.exe (file missing)
O23 - Service: NetMeeting - Deling af fjernskrivebord mnmsrvcUMWdf (mnmsrvcUMWdf) - Unknown owner - D:\WINDOWS\System32\1037d.exe
O23 - Service: Network DDE DSDM NetDDEdsdmMessengerSSDPSRV (NetDDEdsdmMessengerSSDPSRV) - Unknown owner - D:\WINDOWS\System32\activedsph.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
O23 - Service: NVIDIA Display Driver Service NVSvcMSIServer (NVSvcMSIServer) - Unknown owner - D:\WINDOWS\System32\1031p.exe (file missing)
O23 - Service: Office Source Engine oseose (oseose) - Unknown owner - D:\WINDOWS\System32\147657854r.exe (file missing)
O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - D:\Programmer\Trend Micro\PC-cillin 2002\PCCPFW.exe
O23 - Service: Chipkort SCardSvrose (SCardSvrose) - Unknown owner - D:\WINDOWS\System32\activedsp.exe (file missing)
O23 - Service: Firewall til Internetforbindelse / Deling af Internetforbindelse SharedAccesswinmgmt (SharedAccesswinmgmt) - Unknown owner - D:\WINDOWS\System32\1033d.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - D:\Programmer\Trend Micro\PC-cillin 2002\Tmntsrv.exe

--
End of file - 11293 bytes
Avatar billede arlet Juniormester
31. oktober 2007 - 21:20 #1
Ja, det er en af de grimme..

2 sekunder, så er der en kur
Avatar billede arlet Juniormester
31. oktober 2007 - 21:23 #2
Opret først et systemgendannelsespunkt (hvis du ikke ved hvordan, så sig til). Så har du et punkt at vende tilbage til - just in case...

Hent denne fil og pak den ud til Skrivebordet:
http://sptlarsenserious.googlepages.com/...

Genstart PC i fejlsikret tilstand UDEN netværk.

VIGTIGT!!!
Du skal logge på med egen bruger, altså ikke med den Administrator, der også bliver vist.

Dobbeltklik på fixntos.reg.
Der kommer så en boks, som spørger, om du vil tilføje i regdatabasen. Klik Ja. Kort efter siger den, at det er tilføjet. Klik OK. Reg.filen sørger for, at der automatisk genopretter de nødvendige erstatningsfiler til Windows.

Nu burde du kunne slette filen, uden at Windows brokker sig (husk at ændre mappeindstillinger, så du kan se skjulte filer samt systemfiler (hvis du ikke ved hvordan, så sig til)):

C:\WINDOWS\system32\ntos.exe

----------
HVIS det skulle gå galt, må du gå op i fejlsikret igen – men i stedet for fejlsikret, skal du vælge systemgendannelse.

OBS! Jeg vil råde dig (din bror?!) til derefter at skifte de vigtige passwords, fordi I sandsynligvis har haft besøg af en såkaldt info-stealer, dvs: ”a Trojan that may steal sensitive information from the compromised computer….”

----------
Genstart PC i normal tilstand. Kør en ny scanning med HJT og lad mig se den nye log
Avatar billede arlet Juniormester
31. oktober 2007 - 21:25 #3
Hov, forkert link.

Det er denne fil du skal hente ned: http://sptlarsenserious.googlepages.com/fixntos.zip
Avatar billede arlet Juniormester
31. oktober 2007 - 21:26 #4
Og det er står under OBS med din bror skal du ikke tage dig af, da jeg har lånt vejledningen fra et andet spørgsmål..
Avatar billede djgreg Nybegynder
31. oktober 2007 - 21:29 #5
Oki, takker :) Godt med en der er seriøs.
Avatar billede djgreg Nybegynder
01. november 2007 - 09:55 #6
Okay, det tror jeg ikke lige min computer havde særlig godt af.

Når jeg åbner min computer normalt nu er det længste jeg kan komme til mit baggrundsbillede uden noget andet. Den når lige at afspille lyden til når man åbner sin computer. 80% af gangene kommer der også et skilt op med følgende:

winlogon.exe - Programfejl

Instruktionen ved "0x0008259f" refererede hukommelse ved "0xa0082c49". Hukommelsen kunne ikke "written".

Klik på "Ok" for at afslutte programmet.
Klip på "Annuller" for at udføre fejlfinding.

I fejlsikret tilstand kommer der bare en sort skærm.

(Jeg skriver fra min skoles computer i øjeblikket)
Avatar billede arlet Juniormester
01. november 2007 - 19:25 #7
Du skal starte op med f8 og så skal du gå ind i sidste kendte fungerende konfiguration, så skulle den starte rigtigt op igen
Avatar billede djgreg Nybegynder
01. november 2007 - 20:31 #8
Min nabo havde lige et lille trick så nu kan jeg komme ind igen.

Har fjernet den der fil, og nu ser det således ud:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:30, on 2007-11-01
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Programmer\Internet Explorer\IEXPLORE.EXE
D:\Programmer\Internet Explorer\IEXPLORE.EXE
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Programmer\Antiy Labs\Alive\ALiveCenter.exe
D:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\WINDOWS\Explorer.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\Programmer\iTunes\iTunesHelper.exe
D:\Programmer\QuickTime\qttask.exe
D:\WINDOWS\System32\spoolsvv.exe
D:\Programmer\MSN Messenger\msnmsgr.exe
D:\WINDOWS\System32\svchost.exe
D:\Programmer\Trend Micro\PC-cillin 2002\Tmntsrv.exe
D:\WINDOWS\System32\wdfmgr.exe
D:\WINDOWS\System32\MsPMSPSv.exe
D:\Programmer\Canon\CAL\CALMAIN.exe
D:\Programmer\Trend Micro\PC-cillin 2002\PCCPFW.exe
D:\Programmer\iPod\bin\iPodService.exe
D:\WINDOWS\System32\wbem\wmiprvse.exe
D:\Programmer\MSN Messenger\usnsvc.exe
D:\WINDOWS\System32\wuauclt.exe
D:\Documents and Settings\André\Skrivebord\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://kingkongsearch.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dr.dk/sporten
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://85.255.113.67/privacyWarning.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - D:\Programmer\NewDotNet\newdotnet7_48.dll (file missing)
O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - D:\Programmer\Need2Find\bar\1.bin\ND2FNBAR.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\programmer\google\googletoolbar1.dll
O2 - BHO: XBTB06823 - {BA463437-C3DE-47da-8280-87596824388A} - D:\PROGRA~1\GOOGLE~1\TOOLBA~1.DLL
O2 - BHO: e404 helper - {F10587E9-0E47-4CBE-84AE-7DD20B8684BB} - D:\Programmer\E404 Helper\e404.v1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\programmer\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "D:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [net32] D:\WINDOWS\svhost.exe
O4 - HKLM\..\Run: [net64] D:\WINDOWS\svhoster.exe
O4 - HKLM\..\Run: [netsv32] D:\WINDOWS\sv.exe
O4 - HKLM\..\Run: [netzip] D:\WINDOWS\svzip.exe
O4 - HKLM\..\Run: [BearFlix] "D:\Programmer\BearFlix\BearFlix.exe" /pause
O4 - HKLM\..\Run: [netc] D:\WINDOWS\svc.exe
O4 - HKLM\..\Run: [runsql] D:\WINDOWS\runsql.exe
O4 - HKLM\..\Run: [spoolsvv] D:\WINDOWS\System32\spoolsvv.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [msnmsgr] "D:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [WhenUSave] "D:\Programmer\Save\Save.exe"
O4 - HKCU\..\Run: [swg] D:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [noskrnl] D:\WINDOWS\noskrnl.exe
O4 - HKCU\..\Run: [Firewall auto setup] D:\DOCUME~1\ANDR~1\LOKALE~1\Temp\winlogon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\Run: [Ordbogen.com] D:\Programmer\CoolSystems\ordbogen.com\ordbogen.exe (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: ClickOff.lnk = D:\Programmer\ClickOff\Clickoff.exe
O8 - Extra context menu item: Add to AMV Convert Tool... - D:\Programmer\MP3 Player Utilities 3.79\AMVConverter\grab.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - D:\Programmer\MP3 Player Utilities 3.79\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmer\Java\jre1.5.0_10\bin\npjpi150_10.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmer\Java\jre1.5.0_10\bin\npjpi150_10.dll
O9 - Extra button: Opret Foretrukken på mobil enhed - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Opret Foretrukken på mobil enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmer\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: D:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) - https://netbank.bgbank.dk/html/activex/BG/Menu.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1133301966077
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.bgbank.dk/html/activex/e-Safekey/BG/e-Safekey.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O20 - Winlogon Notify: botreg - D:\Documents and Settings\All Users\Dokumenter\Settings\bot.dll
O20 - Winlogon Notify: comloy - comloy.dll (file missing)
O20 - Winlogon Notify: partnershipreg - D:\Documents and Settings\All Users\Dokumenter\Settings\partnership.dll
O21 - SSODL: DCOM Server 25319 - {2C1CD3D7-86AC-4068-93BC-A02304B25319} - (no file)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Gatewaytjeneste til programlaget ALGuploadmgr (ALGuploadmgr) - Unknown owner - D:\WINDOWS\System32\a3dj.exe (file missing)
O23 - Service: Antiy live update (Alive Auto-Update Service) - Unknown owner - D:\Programmer\Antiy Labs\Alive\ALiveCenter.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - D:\Programmer\Canon\CAL\CALMAIN.exe
O23 - Service: Hændelseslog EventlogNla (EventlogNla) - Unknown owner - D:\WINDOWS\System32\advpackf.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - D:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: COM-tjenesten IMAPI cd-skrivning ImapiServiceALG (ImapiServiceALG) - Unknown owner - D:\WINDOWS\System32\1031l.exe (file missing)
O23 - Service: iPod Service - Apple Computer, Inc. - D:\Programmer\iPod\bin\iPodService.exe
O23 - Service: Messenger MessengerSSDPSRV (MessengerSSDPSRV) - Unknown owner - D:\WINDOWS\System32\advapi32b.exe (file missing)
O23 - Service: NetMeeting - Deling af fjernskrivebord mnmsrvcUMWdf (mnmsrvcUMWdf) - Unknown owner - D:\WINDOWS\System32\1037d.exe
O23 - Service: Network DDE DSDM NetDDEdsdmMessengerSSDPSRV (NetDDEdsdmMessengerSSDPSRV) - Unknown owner - D:\WINDOWS\System32\activedsph.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
O23 - Service: NVIDIA Display Driver Service NVSvcMSIServer (NVSvcMSIServer) - Unknown owner - D:\WINDOWS\System32\1031p.exe (file missing)
O23 - Service: Office Source Engine oseose (oseose) - Unknown owner - D:\WINDOWS\System32\147657854r.exe (file missing)
O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - D:\Programmer\Trend Micro\PC-cillin 2002\PCCPFW.exe
O23 - Service: Chipkort SCardSvrose (SCardSvrose) - Unknown owner - D:\WINDOWS\System32\activedsp.exe (file missing)
O23 - Service: Firewall til Internetforbindelse / Deling af Internetforbindelse SharedAccesswinmgmt (SharedAccesswinmgmt) - Unknown owner - D:\WINDOWS\System32\1033d.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - D:\Programmer\Trend Micro\PC-cillin 2002\Tmntsrv.exe

--
End of file - 11227 bytes
Avatar billede arlet Juniormester
01. november 2007 - 20:53 #9
Kør trin 1 og 2 her http://www.malwarecheck.dk/forum/viewtopic.php?t=11 og læg log`ne ind
Avatar billede djgreg Nybegynder
01. november 2007 - 22:36 #10
Tingene er downloadet, men fortsætter lige med tingene i morgen aften. Har lidt travlt her fra nu og til i morgen, men jeg skal nok få de logs ind. Vil du i øvrigt også have en hijack log ind når jeg er færdig eller er det ligegyldigt?
Avatar billede arlet Juniormester
02. november 2007 - 07:26 #11
jo tak en ny hijackthis efter du har kørt de 2 scannere
Avatar billede djgreg Nybegynder
02. november 2007 - 23:14 #12
Jeg har nu det problem at jeg ikke når at køre de 2 scannere før min computer begynder at genstarte. Skal jeg køre dem i fejlsikret tilstand evt.?
Avatar billede arlet Juniormester
03. november 2007 - 10:16 #13
Ja, det ville være fint..
Avatar billede djgreg Nybegynder
03. november 2007 - 18:28 #14
Ja nu føles den skam bedre, her er loggen:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:28, on 2007-11-03
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Programmer\Internet Explorer\IEXPLORE.EXE
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Programmer\Antiy Labs\Alive\ALiveCenter.exe
D:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\Programmer\Trend Micro\PC-cillin 2002\Tmntsrv.exe
D:\WINDOWS\System32\wdfmgr.exe
D:\WINDOWS\System32\MsPMSPSv.exe
D:\Programmer\Trend Micro\PC-cillin 2002\PCCPFW.exe
D:\Programmer\Canon\CAL\CALMAIN.exe
D:\WINDOWS\System32\wuauclt.exe
D:\WINDOWS\Explorer.EXE
D:\Programmer\iTunes\iTunesHelper.exe
D:\Programmer\QuickTime\qttask.exe
D:\Programmer\MSN Messenger\msnmsgr.exe
D:\DOCUME~1\ANDR~1\LOKALE~1\Temp\winlogon.exe
D:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
D:\Programmer\iPod\bin\iPodService.exe
D:\Programmer\MSN Messenger\usnsvc.exe
D:\Programmer\Mozilla Firefox\firefox.exe
D:\Documents and Settings\André\Skrivebord\Ny mappe\HiJackThis.exe
D:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://kingkongsearch.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dr.dk/sporten
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://85.255.113.67/privacyWarning.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\programmer\google\googletoolbar1.dll
O2 - BHO: XBTB06823 - {BA463437-C3DE-47da-8280-87596824388A} - D:\PROGRA~1\GOOGLE~1\TOOLBA~1.DLL (file missing)
O2 - BHO: e404 helper - {F10587E9-0E47-4CBE-84AE-7DD20B8684BB} - D:\Programmer\E404 Helper\e404.v1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\programmer\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "D:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [net32] D:\WINDOWS\svhost.exe
O4 - HKLM\..\Run: [net64] D:\WINDOWS\svhoster.exe
O4 - HKLM\..\Run: [netsv32] D:\WINDOWS\sv.exe
O4 - HKLM\..\Run: [netzip] D:\WINDOWS\svzip.exe
O4 - HKLM\..\Run: [BearFlix] "D:\Programmer\BearFlix\BearFlix.exe" /pause
O4 - HKLM\..\Run: [netc] D:\WINDOWS\svc.exe
O4 - HKLM\..\Run: [runsql] D:\WINDOWS\runsql.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [msnmsgr] "D:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [WhenUSave] "D:\Programmer\Save\Save.exe"
O4 - HKCU\..\Run: [swg] D:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [noskrnl] D:\WINDOWS\noskrnl.exe
O4 - HKCU\..\Run: [Firewall auto setup] D:\DOCUME~1\ANDR~1\LOKALE~1\Temp\winlogon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\Run: [Ordbogen.com] D:\Programmer\CoolSystems\ordbogen.com\ordbogen.exe (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: ClickOff.lnk = D:\Programmer\ClickOff\Clickoff.exe
O8 - Extra context menu item: Add to AMV Convert Tool... - D:\Programmer\MP3 Player Utilities 3.79\AMVConverter\grab.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - D:\Programmer\MP3 Player Utilities 3.79\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmer\Java\jre1.5.0_10\bin\npjpi150_10.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmer\Java\jre1.5.0_10\bin\npjpi150_10.dll
O9 - Extra button: Opret Foretrukken på mobil enhed - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Opret Foretrukken på mobil enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmer\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: D:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) - https://netbank.bgbank.dk/html/activex/BG/Menu.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1133301966077
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.bgbank.dk/html/activex/e-Safekey/BG/e-Safekey.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O20 - Winlogon Notify: !SASWinLogon - D:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: botreg - D:\Documents and Settings\All Users\Dokumenter\Settings\bot.dll
O20 - Winlogon Notify: comloy - comloy.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Gatewaytjeneste til programlaget ALGuploadmgr (ALGuploadmgr) - Unknown owner - D:\WINDOWS\System32\a3dj.exe (file missing)
O23 - Service: Antiy live update (Alive Auto-Update Service) - Unknown owner - D:\Programmer\Antiy Labs\Alive\ALiveCenter.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - D:\Programmer\Canon\CAL\CALMAIN.exe
O23 - Service: Hændelseslog EventlogNla (EventlogNla) - Unknown owner - D:\WINDOWS\System32\advpackf.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - D:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: COM-tjenesten IMAPI cd-skrivning ImapiServiceALG (ImapiServiceALG) - Unknown owner - D:\WINDOWS\System32\1031l.exe (file missing)
O23 - Service: iPod Service - Apple Computer, Inc. - D:\Programmer\iPod\bin\iPodService.exe
O23 - Service: Messenger MessengerSSDPSRV (MessengerSSDPSRV) - Unknown owner - D:\WINDOWS\System32\advapi32b.exe (file missing)
O23 - Service: NetMeeting - Deling af fjernskrivebord mnmsrvcUMWdf (mnmsrvcUMWdf) - Unknown owner - D:\WINDOWS\System32\1037d.exe
O23 - Service: Network DDE DSDM NetDDEdsdmMessengerSSDPSRV (NetDDEdsdmMessengerSSDPSRV) - Unknown owner - D:\WINDOWS\System32\activedsph.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
O23 - Service: NVIDIA Display Driver Service NVSvcMSIServer (NVSvcMSIServer) - Unknown owner - D:\WINDOWS\System32\1031p.exe (file missing)
O23 - Service: Office Source Engine oseose (oseose) - Unknown owner - D:\WINDOWS\System32\147657854r.exe (file missing)
O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - D:\Programmer\Trend Micro\PC-cillin 2002\PCCPFW.exe
O23 - Service: Chipkort SCardSvrose (SCardSvrose) - Unknown owner - D:\WINDOWS\System32\activedsp.exe (file missing)
O23 - Service: Firewall til Internetforbindelse / Deling af Internetforbindelse SharedAccesswinmgmt (SharedAccesswinmgmt) - Unknown owner - D:\WINDOWS\System32\1033d.exe (file missing)
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - D:\Programmer\Trend Micro\PC-cillin 2002\Tmntsrv.exe

--
End of file - 11005 bytes
Avatar billede arlet Juniormester
04. november 2007 - 10:46 #15
Du skal nu til at i gang med at fixe:
Kør Hijackthis, scan, sæt flueben ved linien/linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked, luk hijackthis igen.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://kingkongsearch.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://85.255.113.67/privacyWarning.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - D:\Programmer\NewDotNet\newdotnet7_48.dll (file missing)
O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - D:\Programmer\Need2Find\bar\1.bin\ND2FNBAR.DLL
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: XBTB06823 - {BA463437-C3DE-47da-8280-87596824388A} - D:\PROGRA~1\GOOGLE~1\TOOLBA~1.DLL
O2 - BHO: e404 helper - {F10587E9-0E47-4CBE-84AE-7DD20B8684BB} - D:\Programmer\E404 Helper\e404.v1.dll

O4 - HKLM\..\Run: [net32] D:\WINDOWS\svhost.exe
O4 - HKLM\..\Run: [net64] D:\WINDOWS\svhoster.exe
O4 - HKLM\..\Run: [netsv32] D:\WINDOWS\sv.exe
O4 - HKLM\..\Run: [netzip] D:\WINDOWS\svzip.exe
O4 - HKLM\..\Run: [netc] D:\WINDOWS\svc.exe
O4 - HKLM\..\Run: [runsql] D:\WINDOWS\runsql.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [WhenUSave] "D:\Programmer\Save\Save.exe"
O4 - HKCU\..\Run: [noskrnl] D:\WINDOWS\noskrnl.exe
O4 - HKCU\..\Run: [Firewall auto setup] D:\DOCUME~1\ANDR~1\LOKALE~1\Temp\winlogon.exe

O20 - Winlogon Notify: botreg - D:\Documents and Settings\All Users\Dokumenter\Settings\bot.dll
O20 - Winlogon Notify: comloy - comloy.dll (file missing)

---------------------

Hent Avenger ned til skrivebordet her fra:
http://swandog46.geekstogo.com/avenger.exe

1. Dobbeltklik på avenger.exe

2. Sæt en prik i "Input Script Manually" og klik på Luppen - nu dukker der et lille vindue op, hvor du skal kopiere indholdet mellem de stiplede linier ind:

-----------------------------
Files to delete:
D:\WINDOWS\svhost.exe
D:\WINDOWS\svhoster.exe
D:\WINDOWS\sv.exe
D:\WINDOWS\svzip.exe
D:\WINDOWS\svc.exe
D:\WINDOWS\runsql.exe
D:\WINDOWS\noskrnl.exe

Folders to delete:
D:\Programmer\Save
-----------------------------

3. Klik på Trafiklyset i Avenger. Programmet vil opfordre dig til at genstarte computeren straks, hvilket du skal gøre. Programmet vil lukke din computer, slette filerne og starte computeren igen.

4. Efter genstarten vil der dukke et notepad-vindue op, med en log for Avengers handlinger. Den må du gerne lægge ind i dit næste svar sammen med en ny hijackthis log
Avatar billede djgreg Nybegynder
05. november 2007 - 21:25 #16
Hov, med den nyvundne hurtighed havde jeg nær glemt det. Går i gang så hurtigt som muligt.
Avatar billede djgreg Nybegynder
05. november 2007 - 22:07 #17
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\bbtgtnws

*******************

Script file located at: \??\D:\Program Files\dmdgkcai.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at D:\Avenger

*******************

Beginning to process script file:



File D:\WINDOWS\svhost.exe not found!
Deletion of file D:\WINDOWS\svhost.exe failed!

Could not process line:
D:\WINDOWS\svhost.exe
Status: 0xc0000034



File D:\WINDOWS\svhoster.exe not found!
Deletion of file D:\WINDOWS\svhoster.exe failed!

Could not process line:
D:\WINDOWS\svhoster.exe
Status: 0xc0000034



File D:\WINDOWS\sv.exe not found!
Deletion of file D:\WINDOWS\sv.exe failed!

Could not process line:
D:\WINDOWS\sv.exe
Status: 0xc0000034



File D:\WINDOWS\svzip.exe not found!
Deletion of file D:\WINDOWS\svzip.exe failed!

Could not process line:
D:\WINDOWS\svzip.exe
Status: 0xc0000034



File D:\WINDOWS\svc.exe not found!
Deletion of file D:\WINDOWS\svc.exe failed!

Could not process line:
D:\WINDOWS\svc.exe
Status: 0xc0000034



File D:\WINDOWS\runsql.exe not found!
Deletion of file D:\WINDOWS\runsql.exe failed!

Could not process line:
D:\WINDOWS\runsql.exe
Status: 0xc0000034

File D:\WINDOWS\noskrnl.exe deleted successfully.


Folder D:\Programmer\Save not found!
Deletion of folder D:\Programmer\Save failed!

Could not process line:
D:\Programmer\Save
Status: 0xc0000034


Completed script processing.

*******************

Finished!  Terminate.


--------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:07, on 2007-11-05
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Programmer\Internet Explorer\IEXPLORE.EXE
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\Programmer\Antiy Labs\Alive\ALiveCenter.exe
D:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\Programmer\iTunes\iTunesHelper.exe
D:\Programmer\QuickTime\qttask.exe
D:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\WINDOWS\System32\spoolsvv.exe
D:\Programmer\MSN Messenger\msnmsgr.exe
D:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Programmer\Trend Micro\PC-cillin 2002\Tmntsrv.exe
D:\WINDOWS\System32\wdfmgr.exe
D:\WINDOWS\System32\MsPMSPSv.exe
D:\Programmer\Canon\CAL\CALMAIN.exe
D:\Programmer\Trend Micro\PC-cillin 2002\PCCPFW.exe
D:\Programmer\iPod\bin\iPodService.exe
D:\WINDOWS\System32\wbem\wmiprvse.exe
D:\Programmer\Mozilla Firefox\firefox.exe
D:\WINDOWS\System32\wuauclt.exe
D:\Programmer\MSN Messenger\usnsvc.exe
D:\Documents and Settings\André\Skrivebord\Ny mappe\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dr.dk/sporten
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\programmer\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\programmer\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "D:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BearFlix] "D:\Programmer\BearFlix\BearFlix.exe" /pause
O4 - HKLM\..\Run: [spoolsvv] D:\WINDOWS\System32\spoolsvv.exe
O4 - HKCU\..\Run: [msnmsgr] "D:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] D:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\Run: [Ordbogen.com] D:\Programmer\CoolSystems\ordbogen.com\ordbogen.exe (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: ClickOff.lnk = D:\Programmer\ClickOff\Clickoff.exe
O8 - Extra context menu item: Add to AMV Convert Tool... - D:\Programmer\MP3 Player Utilities 3.79\AMVConverter\grab.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - D:\Programmer\MP3 Player Utilities 3.79\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmer\Java\jre1.5.0_10\bin\npjpi150_10.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmer\Java\jre1.5.0_10\bin\npjpi150_10.dll
O9 - Extra button: Opret Foretrukken på mobil enhed - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Opret Foretrukken på mobil enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmer\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: D:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) - https://netbank.bgbank.dk/html/activex/BG/Menu.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1133301966077
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.bgbank.dk/html/activex/e-Safekey/BG/e-Safekey.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O20 - Winlogon Notify: !SASWinLogon - D:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: botreg - D:\Documents and Settings\All Users\Dokumenter\Settings\bot.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Gatewaytjeneste til programlaget ALGuploadmgr (ALGuploadmgr) - Unknown owner - D:\WINDOWS\System32\a3dj.exe (file missing)
O23 - Service: Antiy live update (Alive Auto-Update Service) - Unknown owner - D:\Programmer\Antiy Labs\Alive\ALiveCenter.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - D:\Programmer\Canon\CAL\CALMAIN.exe
O23 - Service: Hændelseslog EventlogNla (EventlogNla) - Unknown owner - D:\WINDOWS\System32\advpackf.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - D:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: COM-tjenesten IMAPI cd-skrivning ImapiServiceALG (ImapiServiceALG) - Unknown owner - D:\WINDOWS\System32\1031l.exe (file missing)
O23 - Service: iPod Service - Apple Computer, Inc. - D:\Programmer\iPod\bin\iPodService.exe
O23 - Service: Messenger MessengerSSDPSRV (MessengerSSDPSRV) - Unknown owner - D:\WINDOWS\System32\advapi32b.exe (file missing)
O23 - Service: NetMeeting - Deling af fjernskrivebord mnmsrvcUMWdf (mnmsrvcUMWdf) - Unknown owner - D:\WINDOWS\System32\1037d.exe
O23 - Service: Network DDE DSDM NetDDEdsdmMessengerSSDPSRV (NetDDEdsdmMessengerSSDPSRV) - Unknown owner - D:\WINDOWS\System32\activedsph.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
O23 - Service: NVIDIA Display Driver Service NVSvcMSIServer (NVSvcMSIServer) - Unknown owner - D:\WINDOWS\System32\1031p.exe (file missing)
O23 - Service: Office Source Engine oseose (oseose) - Unknown owner - D:\WINDOWS\System32\147657854r.exe (file missing)
O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - D:\Programmer\Trend Micro\PC-cillin 2002\PCCPFW.exe
O23 - Service: Chipkort SCardSvrose (SCardSvrose) - Unknown owner - D:\WINDOWS\System32\activedsp.exe (file missing)
O23 - Service: Firewall til Internetforbindelse / Deling af Internetforbindelse SharedAccesswinmgmt (SharedAccesswinmgmt) - Unknown owner - D:\WINDOWS\System32\1033d.exe (file missing)
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - D:\Programmer\Trend Micro\PC-cillin 2002\Tmntsrv.exe

--
End of file - 9726 bytes
05. november 2007 - 22:20 #18
<arlet>:

??? ->
O4 - HKLM\..\Run: [spoolsvv] D:\WINDOWS\System32\spoolsvv.exe
http://www.bleepingcomputer.com/startups/spoolsvv.exe-5102.html

O20 - Winlogon Notify: botreg - D:\Documents and Settings\All Users\Dokumenter\Settings\bot.dll

(ComboFix bør kunne æde dem + mange andre "usynlige" elementer)
05. november 2007 - 22:21 #19
(Husk 'talen' om manglende SP2 samt efterfølgende 90+ opdateringer fra WindowsUpdate!)
Avatar billede djgreg Nybegynder
05. november 2007 - 22:24 #20
Sådan, efter karise_larrys kommentar:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:23, on 2007-11-05
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Programmer\Internet Explorer\IEXPLORE.EXE
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\Programmer\Antiy Labs\Alive\ALiveCenter.exe
D:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\Programmer\iTunes\iTunesHelper.exe
D:\Programmer\QuickTime\qttask.exe
D:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\Programmer\MSN Messenger\msnmsgr.exe
D:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Programmer\Trend Micro\PC-cillin 2002\Tmntsrv.exe
D:\WINDOWS\System32\wdfmgr.exe
D:\WINDOWS\System32\MsPMSPSv.exe
D:\Programmer\Canon\CAL\CALMAIN.exe
D:\Programmer\Trend Micro\PC-cillin 2002\PCCPFW.exe
D:\Programmer\iPod\bin\iPodService.exe
D:\Programmer\MSN Messenger\usnsvc.exe
D:\WINDOWS\System32\wbem\wmiprvse.exe
D:\Documents and Settings\André\Skrivebord\Ny mappe\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dr.dk/sporten
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\programmer\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\programmer\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "D:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BearFlix] "D:\Programmer\BearFlix\BearFlix.exe" /pause
O4 - HKCU\..\Run: [msnmsgr] "D:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] D:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\Run: [Ordbogen.com] D:\Programmer\CoolSystems\ordbogen.com\ordbogen.exe (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: ClickOff.lnk = D:\Programmer\ClickOff\Clickoff.exe
O8 - Extra context menu item: Add to AMV Convert Tool... - D:\Programmer\MP3 Player Utilities 3.79\AMVConverter\grab.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - D:\Programmer\MP3 Player Utilities 3.79\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmer\Java\jre1.5.0_10\bin\npjpi150_10.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmer\Java\jre1.5.0_10\bin\npjpi150_10.dll
O9 - Extra button: Opret Foretrukken på mobil enhed - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Opret Foretrukken på mobil enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmer\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: D:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) - https://netbank.bgbank.dk/html/activex/BG/Menu.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1133301966077
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.bgbank.dk/html/activex/e-Safekey/BG/e-Safekey.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O20 - Winlogon Notify: !SASWinLogon - D:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: botreg - D:\Documents and Settings\All Users\Dokumenter\Settings\bot.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Gatewaytjeneste til programlaget ALGuploadmgr (ALGuploadmgr) - Unknown owner - D:\WINDOWS\System32\a3dj.exe (file missing)
O23 - Service: Antiy live update (Alive Auto-Update Service) - Unknown owner - D:\Programmer\Antiy Labs\Alive\ALiveCenter.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - D:\Programmer\Canon\CAL\CALMAIN.exe
O23 - Service: Hændelseslog EventlogNla (EventlogNla) - Unknown owner - D:\WINDOWS\System32\advpackf.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - D:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: COM-tjenesten IMAPI cd-skrivning ImapiServiceALG (ImapiServiceALG) - Unknown owner - D:\WINDOWS\System32\1031l.exe (file missing)
O23 - Service: iPod Service - Apple Computer, Inc. - D:\Programmer\iPod\bin\iPodService.exe
O23 - Service: Messenger MessengerSSDPSRV (MessengerSSDPSRV) - Unknown owner - D:\WINDOWS\System32\advapi32b.exe (file missing)
O23 - Service: NetMeeting - Deling af fjernskrivebord mnmsrvcUMWdf (mnmsrvcUMWdf) - Unknown owner - D:\WINDOWS\System32\1037d.exe
O23 - Service: Network DDE DSDM NetDDEdsdmMessengerSSDPSRV (NetDDEdsdmMessengerSSDPSRV) - Unknown owner - D:\WINDOWS\System32\activedsph.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
O23 - Service: NVIDIA Display Driver Service NVSvcMSIServer (NVSvcMSIServer) - Unknown owner - D:\WINDOWS\System32\1031p.exe (file missing)
O23 - Service: Office Source Engine oseose (oseose) - Unknown owner - D:\WINDOWS\System32\147657854r.exe (file missing)
O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - D:\Programmer\Trend Micro\PC-cillin 2002\PCCPFW.exe
O23 - Service: Chipkort SCardSvrose (SCardSvrose) - Unknown owner - D:\WINDOWS\System32\activedsp.exe (file missing)
O23 - Service: Firewall til Internetforbindelse / Deling af Internetforbindelse SharedAccesswinmgmt (SharedAccesswinmgmt) - Unknown owner - D:\WINDOWS\System32\1033d.exe (file missing)
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - D:\Programmer\Trend Micro\PC-cillin 2002\Tmntsrv.exe

--
End of file - 9553 bytes
05. november 2007 - 22:28 #21
<arlet> kører videre herfra ... efter uskreven aftale... *S*
Avatar billede arlet Juniormester
06. november 2007 - 21:11 #22
fix i hijackthis:
O20 - Winlogon Notify: botreg - D:\Documents and Settings\All Users\Dokumenter\Settings\bot.dll

find og slet denne manuelt:
D:\Documents and Settings\All Users\Dokumenter\Settings\bot.dll

genstart og ny hijackthis log

---------------

Du bør lige opdatere dit java, som er forældet. Tjek evt også for opdateringer til dine andre programmer http://www.malwarecheck.dk/forum/viewtopic.php?t=54
Avatar billede djgreg Nybegynder
07. november 2007 - 16:11 #23
Når jeg forsøger at slette bot.dll manuelt får jeg beskeden:

Det er ikke muligt at slette bot: Filen bruges af en anden person eller et andet program.

Luk alle programmer, der muligvis bruger filen, og forsøg igen.


----------

Har prøvet at følge dens manøvre.
Avatar billede arlet Juniormester
07. november 2007 - 17:19 #24
Hent og dobbeltklik denne fil. Den pakker sig ud til C:\SDFix:
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

Genstart i fejlsikret, hvis du ikke ved hvordan så kig her (Scroll ned til "Sådan får du adgang til fejlsikret tilstand") http://kimludvigsen.dk/tips-windows-fejlsikret.html


Gå så ind i mappen SDFix på C drevet. Dobbeltklik på filen RunThis.bat, for at starte værktøjet. Tryk "y" for at bekræfte, at du kører værktøjet på egen risiko. Så vil værktøjet gå i gang med at fjerne trojanservicen, og lave et par reparationer af registreringsdatabasen. På et tidspunkt vil det bede dig om at trykke en taste for at genstarte computeren. Det skal du gøre, hvorefter computeren vil genstarte efter 15 sekunder.

Genstarten vil tage lidt længere end sædvanligt, idet værktøjet skal have tid til at udføre sit arbejde. Når skrivebordet dukker op, vil værktøjet skrive "Finished". Tryk herefter en taste for at indlæse dine skrivebordsikoner igen.

Åben så SDFix-mappen, find filen Report.txt, og kopier indholdet af denne fil herind.

samt en ny hijackthis efter en genstart
Avatar billede djgreg Nybegynder
09. november 2007 - 20:33 #25
Da jeg i fejlsikret tilstand var i programmet runthis.bat skrev den at der var fejl med indlæsningen af noget VCI og VHA? Jeg ved ikke lige hvad der var galt.
Avatar billede arlet Juniormester
09. november 2007 - 20:46 #26
Prøv lige at køre den igen og se om du kan få det til at virke
Avatar billede djgreg Nybegynder
09. november 2007 - 22:48 #27
Sorry, jeg tog fejl.

Jeg prøvede igen, og det var dette der stod:

Forkert kommando eller filnavn.

Der kan ikke indløses understøttelse af VDM IPX/SPX
Avatar billede arlet Juniormester
10. november 2007 - 08:09 #28
Okay, den dropper vi i første omgang..

-- Hent S!Ri's SmitfraudFix.zip og gem det på dit Skrivebord.
http://siri.urz.free.fr/Fix/SmitfraudFix.exe

Alternativt herfra:
http://72.232.135.12/siri/SmitfraudFix.exe

NB: Filen "process.exe" som ligger i dette værktøj bliver af visse antivirus-programmer identificeret som "RiskTool". Det har dog ikke noget på sig!

-- Genstart i fejlsikret, hvis du ikke ved hvordan så kig her:
http://www.ctrlaltdel.dk/forum/forum_posts.asp?TID=23&PN=1

-- Kør SmitfraudFix. Tast 2 - svar ja til at rense (y=yes). Lad programmet gennemføre en rensning. Det vil også checke om systemfilen wininet.dll er inficeret. Hvis den er det, vil du blive bedt om tilladelse til at erstatte den med en anden. Her skal du vælge "Yes", ved at taste "y".

Programmet bliver muligvis nødt til at genstarte undervejs. Herefter vil der dukke en liste med resultaterne af rensningen op . Kopiér denne liste ind i tråden.

-- Genstart og læg en frisk log fra hijackthis herind, sammen med loggen fra SmitfraudFix (C:\rapport.txt).

derudover:
-- Hent Combofix fra et af disse links, og gem den på dit skrivebord:
http://download.bleepingcomputer.com/sUBs/combofix.exe
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe

-- Kør så combofix.exe, som du hentede tidligere, og følg anvisningerne.
Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når combofix er færdig, og efter det har genstartet, skulle der gerne åbnes en logfil: combofix.txt
Indholdet af denne fil må du gerne lægge herind.

BEMÆRK at Combofix af nogle virusscannere bliver detekteret som inficeret. Dette har dog intet på sig.
Avatar billede djgreg Nybegynder
10. november 2007 - 22:08 #29
SmitFraudFix v2.252

Scan done at 21:26:59.51, 2007-11-10
Run from D:\Documents and Settings\Andr‚\Skrivebord\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

D:\WINDOWS\system32\ld???.tmp Deleted
D:\Documents and Settings\Andr‚\Application Data\Install.dat Deleted

»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: SiS 900-baseret PCI Fast Ethernet-netværkskort - Miniport til Packet Scheduler
DNS Server Search Order: 193.162.153.164
DNS Server Search Order: 194.239.134.83

HKLM\SYSTEM\CCS\Services\Tcpip\..\{9721E5A9-F71E-4EC0-9716-2D6E45DB2400}: DhcpNameServer=193.162.153.164 194.239.134.83
HKLM\SYSTEM\CS1\Services\Tcpip\..\{9721E5A9-F71E-4EC0-9716-2D6E45DB2400}: DhcpNameServer=193.162.153.164 194.239.134.83
HKLM\SYSTEM\CS2\Services\Tcpip\..\{9721E5A9-F71E-4EC0-9716-2D6E45DB2400}: DhcpNameServer=193.162.153.164 194.239.134.83
HKLM\SYSTEM\CS3\Services\Tcpip\..\{9721E5A9-F71E-4EC0-9716-2D6E45DB2400}: DhcpNameServer=193.162.153.164 194.239.134.83
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=193.162.153.164 194.239.134.83
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=193.162.153.164 194.239.134.83
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=193.162.153.164 194.239.134.83
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=193.162.153.164 194.239.134.83


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:08, on 2007-11-10
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Programmer\Internet Explorer\IEXPLORE.EXE
D:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\Programmer\Antiy Labs\Alive\ALiveCenter.exe
D:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\Programmer\iTunes\iTunesHelper.exe
D:\Programmer\QuickTime\qttask.exe
D:\Programmer\MSN Messenger\msnmsgr.exe
D:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
D:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\Programmer\Trend Micro\PC-cillin 2002\Tmntsrv.exe
D:\WINDOWS\System32\MsPMSPSv.exe
D:\Programmer\Canon\CAL\CALMAIN.exe
D:\Programmer\Trend Micro\PC-cillin 2002\PCCPFW.exe
D:\Programmer\iPod\bin\iPodService.exe
D:\Programmer\MSN Messenger\usnsvc.exe
D:\Programmer\Mozilla Firefox\firefox.exe
D:\WINDOWS\System32\wuauclt.exe
D:\Documents and Settings\André\Skrivebord\Ny mappe\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dr.dk/sporten
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\programmer\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\programmer\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "D:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BearFlix] "D:\Programmer\BearFlix\BearFlix.exe" /pause
O4 - HKCU\..\Run: [msnmsgr] "D:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] D:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\Run: [Ordbogen.com] D:\Programmer\CoolSystems\ordbogen.com\ordbogen.exe (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: ClickOff.lnk = D:\Programmer\ClickOff\Clickoff.exe
O8 - Extra context menu item: Add to AMV Convert Tool... - D:\Programmer\MP3 Player Utilities 3.79\AMVConverter\grab.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - D:\Programmer\MP3 Player Utilities 3.79\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmer\Java\jre1.5.0_10\bin\npjpi150_10.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmer\Java\jre1.5.0_10\bin\npjpi150_10.dll
O9 - Extra button: Opret Foretrukken på mobil enhed - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Opret Foretrukken på mobil enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmer\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: D:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) - https://netbank.bgbank.dk/html/activex/BG/Menu.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1133301966077
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.bgbank.dk/html/activex/e-Safekey/BG/e-Safekey.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O20 - Winlogon Notify: !SASWinLogon - D:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: botreg - D:\Documents and Settings\All Users\Dokumenter\Settings\bot.dll
O21 - SSODL: PagingSYS - {009541A0-3B00-1F1C-00F3-040224001C01} - (no file)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Gatewaytjeneste til programlaget (ALG) - Unknown owner - cmd.exe (file missing)
O23 - Service: Gatewaytjeneste til programlaget ALGuploadmgr (ALGuploadmgr) - Unknown owner - D:\WINDOWS\System32\a3dj.exe (file missing)
O23 - Service: Antiy live update (Alive Auto-Update Service) - Unknown owner - D:\Programmer\Antiy Labs\Alive\ALiveCenter.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - D:\Programmer\Canon\CAL\CALMAIN.exe
O23 - Service: Hændelseslog EventlogNla (EventlogNla) - Unknown owner - D:\WINDOWS\System32\advpackf.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - D:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: COM-tjenesten IMAPI cd-skrivning ImapiServiceALG (ImapiServiceALG) - Unknown owner - D:\WINDOWS\System32\1031l.exe (file missing)
O23 - Service: iPod Service - Apple Computer, Inc. - D:\Programmer\iPod\bin\iPodService.exe
O23 - Service: Messenger MessengerSSDPSRV (MessengerSSDPSRV) - Unknown owner - D:\WINDOWS\System32\advapi32b.exe (file missing)
O23 - Service: NetMeeting - Deling af fjernskrivebord mnmsrvcUMWdf (mnmsrvcUMWdf) - Unknown owner - D:\WINDOWS\System32\1037d.exe
O23 - Service: Network DDE DSDM NetDDEdsdmMessengerSSDPSRV (NetDDEdsdmMessengerSSDPSRV) - Unknown owner - D:\WINDOWS\System32\activedsph.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
O23 - Service: NVIDIA Display Driver Service NVSvcMSIServer (NVSvcMSIServer) - Unknown owner - D:\WINDOWS\System32\1031p.exe (file missing)
O23 - Service: Office Source Engine oseose (oseose) - Unknown owner - D:\WINDOWS\System32\147657854r.exe (file missing)
O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - D:\Programmer\Trend Micro\PC-cillin 2002\PCCPFW.exe
O23 - Service: Chipkort SCardSvrose (SCardSvrose) - Unknown owner - D:\WINDOWS\System32\activedsp.exe (file missing)
O23 - Service: Firewall til Internetforbindelse / Deling af Internetforbindelse SharedAccesswinmgmt (SharedAccesswinmgmt) - Unknown owner - D:\WINDOWS\System32\1033d.exe (file missing)
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - D:\Programmer\Trend Micro\PC-cillin 2002\Tmntsrv.exe

--
End of file - 9634 bytes
Avatar billede arlet Juniormester
11. november 2007 - 07:56 #30
Jeg ville også gerne have en combofis log beskrevet nederst her: 10/11-2007 08:09:51
Avatar billede djgreg Nybegynder
11. november 2007 - 18:01 #31
ja, men den kommer ikke. For programmet starter og kører de der ca. 28 stages, og så siger den at denat den åbner et nyt vindue for at starte renselsesprocessen tror jeg, og det vindue forbliver bare tomt, og for at få computeren tilbage til normal må man genstarte den.
Avatar billede djgreg Nybegynder
10. januar 2011 - 22:51 #32
m
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester