Avatar billede mido1337 Nybegynder
16. november 2007 - 22:17 Der er 11 kommentarer og
2 løsninger

msn Virus inficeret, har brug for hjælp

jeg er desværre en af de dumme, som hoppede på at acceptere virus fra en fra listen :(. men min virus scanner AVAST og alle mine spyware programmer kan ikke finde løsningen, så håber i kan finde det, ved denne liste:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:15:04, on 16-11-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\HJTrenamed.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Programmer\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RefreshLock] E:\ekstern hdd\formatere\RefreshLock.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PowerStrip] c:\programmer\powerstrip\pstrip.exe
O4 - HKLM\..\Run: [EasyTuneVPro] C:\Programmer\Gigabyte\ET5Pro\ETcall.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programmer\Fælles filer\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Programmer\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Programmer\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Steam] "c:\steam\steam.exe" -silent
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Programmer\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Policies\Explorer\Run: [NTSpool] NTSpool.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: hamachi.lnk = C:\Programmer\Hamachi\hamachi.exe
O4 - Startup: SpywareGuard.lnk = C:\Programmer\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Microgaming\Poker\nordicbetMPP\MPPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://mppv2flash3.valueactive.com/NordicBet/FlashAX.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Programmer\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6163 bytes
Avatar billede arlet Juniormester
16. november 2007 - 22:23 #1
1)Lad ccleaner lave en oprydning : www.arlet.dk/ccleaner.htm

2)Kør trin 1 her http://www.malwarecheck.dk/forum/viewtopic.php?t=11 og læg loggen ind

3)Hijackthis skal ikke været lavet fra fejlsikret, ny hijackthis log fra normal opstart

4)Hent Combofix fra et af disse links, og gem den på dit skrivebord:
http://download.bleepingcomputer.com/sUBs/combofix.exe
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe

-- Kør så combofix.exe, som du hentede tidligere, og følg anvisningerne.
Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når combofix er færdig, og efter det har genstartet, skulle der gerne åbnes en logfil: combofix.txt
Indholdet af denne fil må du gerne lægge herind.

BEMÆRK at Combofix af nogle virusscannere bliver detekteret som inficeret. Dette har dog intet på sig.

Vi skal se logs fra punkt 2 - 3 - 4
Avatar billede mido1337 Nybegynder
16. november 2007 - 23:08 #2
ComboFix 07-11-08.1 - Dorio-PC 2007-11-16 23:07:10.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1030.18.2622 [GMT 1:00]
Running from: C:\Documents and Settings\Dorio-PC\Skrivebord\ComboFix.exe
* Created a new restore point
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\OPTIONS\CABS\_desktop.ini

.
(((((((((((((((((((((((((  Files Created from 2007-10-16 to 2007-11-16  )))))))))))))))))))))))))))))))
.

2007-11-16 22:37    51,200    --a------    C:\WINDOWS\NirCmd.exe
2007-11-16 22:35    <DIR>    d--------    C:\Programmer\Lavasoft
2007-11-16 22:35    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-16 22:34    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2007-11-16 22:34    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\SUPERAntiSpyware.com
2007-11-16 22:34    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-11-16 22:28    <DIR>    d--------    C:\Programmer\CCleaner
2007-11-16 22:14    401,720    --a------    C:\Programmer\HJTrenamed.exe
2007-11-16 20:50    757,888    --a------    C:\WINDOWS\pics06.zip
2007-11-15 12:29    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\vlc
2007-11-15 11:39    <DIR>    d--------    C:\Programmer\VideoLAN
2007-11-15 00:50    <DIR>    d--------    C:\Programmer\SpywareGuard
2007-11-15 00:12    <DIR>    d--------    C:\Programmer\Spyware Terminator
2007-11-15 00:12    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\Spyware Terminator
2007-11-15 00:12    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2007-11-14 14:49    <DIR>    d--------    C:\Programmer\Ventrilo
2007-11-14 14:49    <DIR>    d--------    C:\Programmer\Fælles filer\Wise Installation Wizard
2007-11-14 00:26    <DIR>    d--------    C:\Programmer\Microsoft Works
2007-11-14 00:25    <DIR>    d--------    C:\Programmer\Microsoft.NET
2007-11-14 00:23    <DIR>    d--------    C:\WINDOWS\SHELLNEW
2007-11-14 00:23    <DIR>    dr-h-----    C:\MSOCache
2007-11-14 00:23    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-14 00:20    176,128    ---------    C:\WINDOWS\system32\Pdrvinst.dll
2007-11-14 00:20    69,632    ---------    C:\WINDOWS\system32\BrWebIns.dll
2007-11-14 00:20    61,440    ---------    C:\WINDOWS\system32\BRWEBUP.EXE
2007-11-14 00:20    45,056    ---------    C:\WINDOWS\system32\PTRCDAN.DLL
2007-11-14 00:20    0    --a------    C:\Programmer\error.dat
2007-11-14 00:16    52,224    --a------    C:\WINDOWS\system32\brinsstr.dll
2007-11-14 00:16    50    --a------    C:\WINDOWS\system32\bridf06a.dat
2007-11-14 00:15    <DIR>    d--------    C:\Programmer\ScanSoft
2007-11-14 00:15    <DIR>    d--------    C:\Programmer\Fælles filer\ScanSoft Shared
2007-11-14 00:15    <DIR>    d--------    C:\Programmer\Brother
2007-11-14 00:15    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\ScanSoft
2007-11-14 00:15    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\InstallShield
2007-11-14 00:15    147,456    ---------    C:\WINDOWS\brunin03.dll
2007-11-14 00:14    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Brother
2007-11-12 15:33    <DIR>    d--------    C:\Programmer\Fælles filer\Futuremark Shared
2007-11-12 08:21    <DIR>    d--------    C:\Programmer\Hamachi
2007-11-12 08:21    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\Hamachi
2007-11-12 08:21    25,280    ---------    C:\WINDOWS\system32\drivers\hamachi.sys
2007-11-11 15:46    <DIR>    d--------    C:\Programmer\SpeedFan
2007-11-11 14:27    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\Azureus
2007-11-11 14:27    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Azureus
2007-11-11 14:26    <DIR>    d--------    C:\Programmer\Azureus
2007-11-11 14:19    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\SopCast
2007-11-10 21:21    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-09 23:03    <DIR>    dr-h-----    C:\Documents and Settings\Dorio-PC\Application Data\SecuROM
2007-11-09 23:03    107,888    --a------    C:\WINDOWS\system32\CmdLineExt.dll
2007-11-09 22:26    <DIR>    d--------    C:\Programmer\THQ
2007-11-09 22:25    3,495,784    --a------    C:\WINDOWS\system32\d3dx9_33.dll
2007-11-09 22:25    1,123,696    --a------    C:\WINDOWS\system32\D3DCompiler_33.dll
2007-11-09 22:25    443,752    --a------    C:\WINDOWS\system32\d3dx10_33.dll
2007-11-09 22:24    <DIR>    d--hs----    C:\WINDOWS\ftpcache
2007-11-09 22:07    <DIR>    d--------    C:\Programmer\BurnInTest
2007-11-09 22:07    <DIR>    d-a------    C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-09 22:07    2,414,360    --a------    C:\WINDOWS\system32\d3dx9_31.dll
2007-11-08 23:01    <DIR>    d--------    C:\Programmer\Fælles filer\Adobe
2007-11-08 19:04    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\Grisoft
2007-11-08 19:04    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-08 19:04    10,872    --a------    C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-08 17:44    24,944    --a------    C:\WINDOWS\system32\drivers\GVTDrv.sys
2007-11-08 17:43    40,136    --a------    C:\WINDOWS\system32\drivers\ET5Drv.sys
2007-11-08 17:41    327,168    --a------    C:\WINDOWS\IsUninst.exe
2007-11-08 14:51    <DIR>    d--------    C:\Microgaming
2007-11-08 14:51    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\Microgaming
2007-11-08 14:48    <DIR>    d--------    C:\WINDOWS\system32\FlashAX
2007-11-08 13:01    <DIR>    d--------    C:\Programmer\GIGABYTE
2007-11-08 05:52    <DIR>    d--------    C:\WINDOWS\system32\Futuremark
2007-11-08 05:52    27,672    ---------    C:\WINDOWS\system32\drivers\Entech.sys
2007-11-08 05:52    5,632    ---------    C:\WINDOWS\system32\drivers\Entech64.sys
2007-11-08 05:52    3,972    ---------    C:\WINDOWS\system32\drivers\PciBus.sys
2007-11-08 05:51    <DIR>    d--------    C:\Programmer\Futuremark
2007-11-07 20:43    <DIR>    d--------    C:\Programmer\SopCast
2007-11-07 18:31    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\Ventrilo
2007-11-07 00:44    <DIR>    d--------    C:\Programmer\Lavalys
2007-11-07 00:35    <DIR>    d--------    C:\WINDOWS\Sun
2007-11-07 00:34    <DIR>    d--------    C:\Programmer\RivaTuner v2.06
2007-11-07 00:13    <DIR>    d--------    C:\Programmer\NVIDIA Corporation
2007-11-07 00:03    1,144    --a------    C:\WINDOWS\mozver.dat
2007-11-06 23:50    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\Talkback
2007-11-06 23:50    0    --a------    C:\WINDOWS\nsreg.dat
2007-11-06 23:41    <DIR>    d--------    C:\Programmer\PowerStrip
2007-11-06 22:43    <DIR>    d--------    C:\Steam
2007-11-06 22:40    <DIR>    d--------    C:\Programmer\MSXML 6.0
2007-11-06 22:29    <DIR>    d--------    C:\Programmer\MSBuild
2007-11-06 22:27    <DIR>    d--------    C:\WINDOWS\system32\XPSViewer
2007-11-06 22:27    <DIR>    d--------    C:\Programmer\Reference Assemblies
2007-11-06 22:26    <DIR>    d--------    C:\Programmer\Windows Media Connect 2
2007-11-06 22:26    14,048    ---------    C:\WINDOWS\system32\spmsg2.dll
2007-11-06 22:21    221,184    --a------    C:\WINDOWS\system32\wmpns.dll
2007-11-06 22:17    <DIR>    d--------    C:\WINDOWS\system32\URTTemp
2007-11-06 22:05    <DIR>    d--------    C:\Programmer\Java
2007-11-06 22:04    <DIR>    d--------    C:\Programmer\Fælles filer\Java
2007-11-06 21:57    <DIR>    d--------    C:\Programmer\MSN Messenger
2007-11-06 21:57    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Contacts
2007-11-06 21:47    <DIR>    d--------    C:\WINDOWS\nview
2007-11-06 21:47    356,352    --a------    C:\WINDOWS\system32\nvudisp.exe
2007-11-06 21:46    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Creative
2007-11-06 21:45    <DIR>    d--------    C:\WINDOWS\system32\Data
2007-11-06 21:45    <DIR>    d--------    C:\NVIDIA

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-16 21:36    8,142    ----a-w    C:\Programmer\hijackthis.log
2007-11-16 21:29    ---------    d-----w    C:\Programmer\Yahoo!
2007-11-16 12:44    757,760    ----a-w    C:\WINDOWS\system32\NTSpool.exe
2007-11-13 23:20    ---------    d--h--w    C:\Programmer\InstallShield Installation Information
2007-11-13 23:20    ---------    d-----w    C:\Programmer\Fælles filer\InstallShield
2007-10-04 16:14    81,920    ----a-w    C:\WINDOWS\system32\nvwddi.dll
2007-10-04 16:14    81,920    ----a-w    C:\WINDOWS\system32\nvmctray.dll
2007-10-04 16:14    8,491,008    ----a-w    C:\WINDOWS\system32\nvcpl.dll
2007-10-04 16:14    753,664    ----a-w    C:\WINDOWS\system32\nvcplui.exe
2007-10-04 16:14    6,854,464    ------w    C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-10-04 16:14    6,750,208    ----a-w    C:\WINDOWS\system32\nvoglnt.dll
2007-10-04 16:14    6,344,704    ----a-w    C:\WINDOWS\system32\nvdisps.dll
2007-10-04 16:14    5,783,424    ----a-w    C:\WINDOWS\system32\nv4_disp.dll
2007-10-04 16:14    466,944    ----a-w    C:\WINDOWS\system32\nvshell.dll
2007-10-04 16:14    45,056    ----a-w    C:\WINDOWS\system32\nvmccsrs.dll
2007-10-04 16:14    442,368    ----a-w    C:\WINDOWS\system32\nvappbar.exe
2007-10-04 16:14    425,984    ----a-w    C:\WINDOWS\system32\keystone.exe
2007-10-04 16:14    364,544    ----a-w    C:\WINDOWS\system32\nvapi.dll
2007-10-04 16:14    36,864    ----a-w    C:\WINDOWS\system32\nvcodins.dll
2007-10-04 16:14    36,864    ----a-w    C:\WINDOWS\system32\nvcod.dll
2007-10-04 16:14    307,200    ----a-w    C:\WINDOWS\system32\nvexpbar.dll
2007-10-04 16:14    3,551,232    ----a-w    C:\WINDOWS\system32\nvvitvs.dll
2007-10-04 16:14    3,334,144    ----a-w    C:\WINDOWS\system32\nvgames.dll
2007-10-04 16:14    286,720    ----a-w    C:\WINDOWS\system32\nvnt4cpl.dll
2007-10-04 16:14    229,376    ----a-w    C:\WINDOWS\system32\nvmccs.dll
2007-10-04 16:14    2,371,584    ----a-w    C:\WINDOWS\system32\nvwss.dll
2007-10-04 16:14    188,416    ----a-w    C:\WINDOWS\system32\nvmccss.dll
2007-10-04 16:14    155,716    ----a-w    C:\WINDOWS\system32\nvsvc32.exe
2007-10-04 16:14    147,456    ----a-w    C:\WINDOWS\system32\nvcolor.exe
2007-10-04 16:14    1,703,936    ----a-w    C:\WINDOWS\system32\nvwdmcpl.dll
2007-10-04 16:14    1,626,112    ----a-w    C:\WINDOWS\system32\nwiz.exe
2007-10-04 16:14    1,478,656    ----a-w    C:\WINDOWS\system32\nview.dll
2007-10-04 16:14    1,339,392    ----a-w    C:\WINDOWS\system32\nvdspsch.exe
2007-10-04 16:14    1,150,976    ----a-w    C:\WINDOWS\system32\nvmobls.dll
2007-10-04 16:14    1,019,904    ----a-w    C:\WINDOWS\system32\nvwimg.dll
2007-08-21 06:17    683,520    ----a-w    C:\WINDOWS\system32\inetcomm.dll
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 10:33 C:\WINDOWS\RTHDCPL.exe]
"JMB36X IDE Setup"="C:\WINDOWS\JM\JMInsIDE.exe" [2006-10-30 13:44]
"36X Raid Configurer"="C:\WINDOWS\system32\JMRaidSetup.exe" [2007-02-06 13:08]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-07-28 00:03]
"CTHelper"="CTHELPER.EXE" [2006-08-17 11:32 C:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-17 11:32 C:\WINDOWS\system32\CTXFIHLP.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-04 17:14]
"nwiz"="nwiz.exe" [2007-10-04 17:14 C:\WINDOWS\system32\nwiz.exe]
"RefreshLock"="E:\ekstern hdd\formatere\RefreshLock.exe" [2002-05-28 20:30]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-10-04 17:14]
"PowerStrip"="c:\programmer\powerstrip\pstrip.exe" [2007-07-14 10:35]
"EasyTuneVPro"="C:\Programmer\Gigabyte\ET5Pro\ETcall.exe" [2007-07-26 15:05]
"!AVG Anti-Spyware"="C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"SSBkgdUpdate"="C:\Programmer\Fælles filer\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 10:22]
"PaperPort PTD"="C:\Programmer\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-18 16:11]
"IndexSearch"="C:\Programmer\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-18 16:22]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 13:00]
"Steam"="c:\steam\steam.exe" [2007-11-15 23:00]
"NVIDIA nTune"="C:\Programmer\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-07-03 12:32]
"SpybotSD TeaTimer"="C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

C:\Documents and Settings\Dorio-PC\Menuen Start\Programmer\Start\
hamachi.lnk - C:\Programmer\Hamachi\hamachi.exe [2007-11-12 08:21:08]
SpywareGuard.lnk - C:\Programmer\SpywareGuard\sgmain.exe [2003-08-29 19:05:35]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

R2 PStrip;PSTRIP;\??\C:\WINDOWS\system32\DRIVERS\PSTRIP.SYS
R3 GVTDrv;GVTDrv;\??\C:\WINDOWS\system32\Drivers\GVTDrv.sys
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys
R3 MarkFun_NT;MarkFun_NT;\??\C:\Programmer\Gigabyte\ET5Pro\markfun.w32
S3 gdrv;gdrv;\??\C:\WINDOWS\gdrv.sys
S3 RivaTuner32;RivaTuner32;\??\C:\Programmer\RivaTuner v2.06\RivaTuner32.sys

*Newly Created Service* - AAWSERVICE
*Newly Created Service* - CATCHME
*Newly Created Service* - MARKFUN_NT
*Newly Created Service* - SASDIFSV
*Newly Created Service* - SASENUM
*Newly Created Service* - SASKUTIL
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-16 23:07:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-16 23:08:08
.
    --- E O F ---
Avatar billede mido1337 Nybegynder
17. november 2007 - 02:10 #3
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:10:14, on 17-11-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Programmer\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Programmer\Mozilla Firefox\firefox.exe
E:\ekstern hdd\formatere\RefreshLock.exe
C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\programmer\powerstrip\pstrip.exe
C:\Programmer\Gigabyte\ET5Pro\GUI.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Programmer\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\steam\steam.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\GameSpy\Comrade\Comrade.exe
C:\Programmer\Hamachi\hamachi.exe
C:\Programmer\SpywareGuard\sgmain.exe
C:\Programmer\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\HJTrenamed.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Programmer\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RefreshLock] E:\ekstern hdd\formatere\RefreshLock.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PowerStrip] c:\programmer\powerstrip\pstrip.exe
O4 - HKLM\..\Run: [EasyTuneVPro] C:\Programmer\Gigabyte\ET5Pro\ETcall.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programmer\Fælles filer\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Programmer\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Programmer\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "c:\steam\steam.exe" -silent
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Programmer\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Comrade.exe] C:\Programmer\GameSpy\Comrade\Comrade.exe
O4 - HKCU\..\Policies\Explorer\Run: [NTSpool] NTSpool.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: hamachi.lnk = C:\Programmer\Hamachi\hamachi.exe
O4 - Startup: SpywareGuard.lnk = C:\Programmer\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Microgaming\Poker\nordicbetMPP\MPPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmer\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://mppv2flash3.valueactive.com/NordicBet/FlashAX.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Programmer\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

--
End of file - 8051 bytes
Avatar billede arlet Juniormester
17. november 2007 - 08:32 #4
Kopiér indholdet mellem de stiplede linier ind i et notepad-vindue, og gem indholdet i samme mappe, som Combofix ligger med navnet CFScript.txt.
Når du gemmer, skal du sikre, at der under "filtyper" står "alle filer".

-------------------------

File::
C:\WINDOWS\system32\NTSpool.exe
C:\WINDOWS\pics06.zip
-------------------------

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen. - http://www.fromsej.saknet.dk/billeder/cfscript.gif
Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.

Kopier indholdet af Combofix.txt her ind sammen med en ny hijackthis log
Avatar billede mido1337 Nybegynder
17. november 2007 - 12:39 #5
ComboFix 07-11-08.1 - Dorio-PC 2007-11-17 12:38:23.5 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1030.18.2750 [GMT 1:00]
Running from: C:\Documents and Settings\Dorio-PC\Skrivebord\ComboFix.exe
Command switches used :: C:\Documents and Settings\Dorio-PC\Skrivebord\CFScript.txt
* Created a new restore point
.

(((((((((((((((((((((((((  Files Created from 2007-10-17 to 2007-11-17  )))))))))))))))))))))))))))))))
.

2007-11-17 12:33    757,878    --a------    C:\WINDOWS\pics06.zip
2007-11-17 02:15    <DIR>    d--------    C:\Temp
2007-11-17 02:15    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Prevx
2007-11-17 02:03    <DIR>    d--------    C:\Programmer\GameSpy
2007-11-17 01:59    22,328    --a------    C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-11-17 01:59    22,328    --a------    C:\Documents and Settings\Dorio-PC\Application Data\PnkBstrK.sys
2007-11-17 01:44    <DIR>    d--------    C:\Programmer\Electronic Arts
2007-11-16 22:37    51,200    --a------    C:\WINDOWS\NirCmd.exe
2007-11-16 22:35    <DIR>    d--------    C:\Programmer\Lavasoft
2007-11-16 22:35    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-16 22:34    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2007-11-16 22:34    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\SUPERAntiSpyware.com
2007-11-16 22:34    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-11-16 22:28    <DIR>    d--------    C:\Programmer\CCleaner
2007-11-16 22:14    401,720    --a------    C:\Programmer\HJTrenamed.exe
2007-11-15 12:29    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\vlc
2007-11-15 11:39    <DIR>    d--------    C:\Programmer\VideoLAN
2007-11-15 00:50    <DIR>    d--------    C:\Programmer\SpywareGuard
2007-11-15 00:12    <DIR>    d--------    C:\Programmer\Spyware Terminator
2007-11-15 00:12    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\Spyware Terminator
2007-11-15 00:12    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2007-11-14 14:49    <DIR>    d--------    C:\Programmer\Ventrilo
2007-11-14 14:49    <DIR>    d--------    C:\Programmer\Fælles filer\Wise Installation Wizard
2007-11-14 00:26    <DIR>    d--------    C:\Programmer\Microsoft Works
2007-11-14 00:25    <DIR>    d--------    C:\Programmer\Microsoft.NET
2007-11-14 00:23    <DIR>    d--------    C:\WINDOWS\SHELLNEW
2007-11-14 00:23    <DIR>    dr-h-----    C:\MSOCache
2007-11-14 00:23    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-14 00:20    176,128    ---------    C:\WINDOWS\system32\Pdrvinst.dll
2007-11-14 00:20    69,632    ---------    C:\WINDOWS\system32\BrWebIns.dll
2007-11-14 00:20    61,440    ---------    C:\WINDOWS\system32\BRWEBUP.EXE
2007-11-14 00:20    45,056    ---------    C:\WINDOWS\system32\PTRCDAN.DLL
2007-11-14 00:20    0    --a------    C:\Programmer\error.dat
2007-11-14 00:16    52,224    --a------    C:\WINDOWS\system32\brinsstr.dll
2007-11-14 00:16    50    --a------    C:\WINDOWS\system32\bridf06a.dat
2007-11-14 00:15    <DIR>    d--------    C:\Programmer\ScanSoft
2007-11-14 00:15    <DIR>    d--------    C:\Programmer\Fælles filer\ScanSoft Shared
2007-11-14 00:15    <DIR>    d--------    C:\Programmer\Brother
2007-11-14 00:15    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\ScanSoft
2007-11-14 00:15    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\InstallShield
2007-11-14 00:15    147,456    ---------    C:\WINDOWS\brunin03.dll
2007-11-14 00:14    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Brother
2007-11-12 15:33    <DIR>    d--------    C:\Programmer\Fælles filer\Futuremark Shared
2007-11-12 08:21    <DIR>    d--------    C:\Programmer\Hamachi
2007-11-12 08:21    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\Hamachi
2007-11-12 08:21    25,280    ---------    C:\WINDOWS\system32\drivers\hamachi.sys
2007-11-11 15:46    <DIR>    d--------    C:\Programmer\SpeedFan
2007-11-11 14:27    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\Azureus
2007-11-11 14:27    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Azureus
2007-11-11 14:26    <DIR>    d--------    C:\Programmer\Azureus
2007-11-11 14:19    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\SopCast
2007-11-10 21:21    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-09 23:03    <DIR>    dr-h-----    C:\Documents and Settings\Dorio-PC\Application Data\SecuROM
2007-11-09 23:03    107,888    --a------    C:\WINDOWS\system32\CmdLineExt.dll
2007-11-09 22:26    <DIR>    d--------    C:\Programmer\THQ
2007-11-09 22:25    3,495,784    --a------    C:\WINDOWS\system32\d3dx9_33.dll
2007-11-09 22:25    1,123,696    --a------    C:\WINDOWS\system32\D3DCompiler_33.dll
2007-11-09 22:25    443,752    --a------    C:\WINDOWS\system32\d3dx10_33.dll
2007-11-09 22:24    <DIR>    d--hs----    C:\WINDOWS\ftpcache
2007-11-09 22:07    <DIR>    d--------    C:\Programmer\BurnInTest
2007-11-09 22:07    <DIR>    d-a------    C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-09 22:07    2,414,360    --a------    C:\WINDOWS\system32\d3dx9_31.dll
2007-11-08 23:01    <DIR>    d--------    C:\Programmer\Fælles filer\Adobe
2007-11-08 19:04    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\Grisoft
2007-11-08 19:04    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-08 19:04    10,872    --a------    C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-08 17:44    24,944    --a------    C:\WINDOWS\system32\drivers\GVTDrv.sys
2007-11-08 17:43    40,136    --a------    C:\WINDOWS\system32\drivers\ET5Drv.sys
2007-11-08 17:41    327,168    --a------    C:\WINDOWS\IsUninst.exe
2007-11-08 14:51    <DIR>    d--------    C:\Microgaming
2007-11-08 14:51    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\Microgaming
2007-11-08 14:48    <DIR>    d--------    C:\WINDOWS\system32\FlashAX
2007-11-08 13:01    <DIR>    d--------    C:\Programmer\GIGABYTE
2007-11-08 05:52    <DIR>    d--------    C:\WINDOWS\system32\Futuremark
2007-11-08 05:52    27,672    ---------    C:\WINDOWS\system32\drivers\Entech.sys
2007-11-08 05:52    5,632    ---------    C:\WINDOWS\system32\drivers\Entech64.sys
2007-11-08 05:52    3,972    ---------    C:\WINDOWS\system32\drivers\PciBus.sys
2007-11-08 05:51    <DIR>    d--------    C:\Programmer\Futuremark
2007-11-07 20:43    <DIR>    d--------    C:\Programmer\SopCast
2007-11-07 18:31    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\Ventrilo
2007-11-07 00:44    <DIR>    d--------    C:\Programmer\Lavalys
2007-11-07 00:35    <DIR>    d--------    C:\WINDOWS\Sun
2007-11-07 00:34    <DIR>    d--------    C:\Programmer\RivaTuner v2.06
2007-11-07 00:13    <DIR>    d--------    C:\Programmer\NVIDIA Corporation
2007-11-07 00:03    1,144    --a------    C:\WINDOWS\mozver.dat
2007-11-06 23:50    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\Talkback
2007-11-06 23:50    0    --a------    C:\WINDOWS\nsreg.dat
2007-11-06 23:41    <DIR>    d--------    C:\Programmer\PowerStrip
2007-11-06 22:43    <DIR>    d--------    C:\Steam
2007-11-06 22:40    <DIR>    d--------    C:\Programmer\MSXML 6.0
2007-11-06 22:29    <DIR>    d--------    C:\Programmer\MSBuild
2007-11-06 22:27    <DIR>    d--------    C:\WINDOWS\system32\XPSViewer
2007-11-06 22:27    <DIR>    d--------    C:\Programmer\Reference Assemblies
2007-11-06 22:26    <DIR>    d--------    C:\Programmer\Windows Media Connect 2
2007-11-06 22:26    14,048    ---------    C:\WINDOWS\system32\spmsg2.dll
2007-11-06 22:21    221,184    --a------    C:\WINDOWS\system32\wmpns.dll
2007-11-06 22:17    <DIR>    d--------    C:\WINDOWS\system32\URTTemp
2007-11-06 22:05    <DIR>    d--------    C:\Programmer\Java
2007-11-06 22:04    <DIR>    d--------    C:\Programmer\Fælles filer\Java
2007-11-06 21:57    <DIR>    d--------    C:\Programmer\MSN Messenger

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-17 01:10    8,052    ----a-w    C:\Programmer\hijackthis.log
2007-11-17 00:58    669,184    ----a-w    C:\WINDOWS\system32\pbsvc.exe
2007-11-17 00:58    66,872    ----a-w    C:\WINDOWS\system32\PnkBstrA.exe
2007-11-17 00:58    103,736    ----a-w    C:\WINDOWS\system32\PnkBstrB.exe
2007-11-16 21:29    ---------    d-----w    C:\Programmer\Yahoo!
2007-11-16 12:44    757,760    ----a-w    C:\WINDOWS\system32\NTSpool.exe
2007-11-13 23:20    ---------    d--h--w    C:\Programmer\InstallShield Installation Information
2007-11-13 23:20    ---------    d-----w    C:\Programmer\Fælles filer\InstallShield
2007-10-04 16:14    81,920    ----a-w    C:\WINDOWS\system32\nvwddi.dll
2007-10-04 16:14    81,920    ----a-w    C:\WINDOWS\system32\nvmctray.dll
2007-10-04 16:14    8,491,008    ----a-w    C:\WINDOWS\system32\nvcpl.dll
2007-10-04 16:14    753,664    ----a-w    C:\WINDOWS\system32\nvcplui.exe
2007-10-04 16:14    6,854,464    ------w    C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-10-04 16:14    6,750,208    ----a-w    C:\WINDOWS\system32\nvoglnt.dll
2007-10-04 16:14    6,344,704    ----a-w    C:\WINDOWS\system32\nvdisps.dll
2007-10-04 16:14    5,783,424    ----a-w    C:\WINDOWS\system32\nv4_disp.dll
2007-10-04 16:14    466,944    ----a-w    C:\WINDOWS\system32\nvshell.dll
2007-10-04 16:14    45,056    ----a-w    C:\WINDOWS\system32\nvmccsrs.dll
2007-10-04 16:14    442,368    ----a-w    C:\WINDOWS\system32\nvappbar.exe
2007-10-04 16:14    425,984    ----a-w    C:\WINDOWS\system32\keystone.exe
2007-10-04 16:14    364,544    ----a-w    C:\WINDOWS\system32\nvapi.dll
2007-10-04 16:14    36,864    ----a-w    C:\WINDOWS\system32\nvcodins.dll
2007-10-04 16:14    36,864    ----a-w    C:\WINDOWS\system32\nvcod.dll
2007-10-04 16:14    307,200    ----a-w    C:\WINDOWS\system32\nvexpbar.dll
2007-10-04 16:14    3,551,232    ----a-w    C:\WINDOWS\system32\nvvitvs.dll
2007-10-04 16:14    3,334,144    ----a-w    C:\WINDOWS\system32\nvgames.dll
2007-10-04 16:14    286,720    ----a-w    C:\WINDOWS\system32\nvnt4cpl.dll
2007-10-04 16:14    229,376    ----a-w    C:\WINDOWS\system32\nvmccs.dll
2007-10-04 16:14    2,371,584    ----a-w    C:\WINDOWS\system32\nvwss.dll
2007-10-04 16:14    188,416    ----a-w    C:\WINDOWS\system32\nvmccss.dll
2007-10-04 16:14    155,716    ----a-w    C:\WINDOWS\system32\nvsvc32.exe
2007-10-04 16:14    147,456    ----a-w    C:\WINDOWS\system32\nvcolor.exe
2007-10-04 16:14    1,703,936    ----a-w    C:\WINDOWS\system32\nvwdmcpl.dll
2007-10-04 16:14    1,626,112    ----a-w    C:\WINDOWS\system32\nwiz.exe
2007-10-04 16:14    1,478,656    ----a-w    C:\WINDOWS\system32\nview.dll
2007-10-04 16:14    1,339,392    ----a-w    C:\WINDOWS\system32\nvdspsch.exe
2007-10-04 16:14    1,150,976    ----a-w    C:\WINDOWS\system32\nvmobls.dll
2007-10-04 16:14    1,019,904    ----a-w    C:\WINDOWS\system32\nvwimg.dll
2007-08-21 06:17    683,520    ----a-w    C:\WINDOWS\system32\inetcomm.dll
.

(((((((((((((((((((((((((((((  snapshot_2007-11-17_ 2.19.59,17  )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-08 22:02:18    295,606    ----a-r    C:\WINDOWS\Installer\{AC76BA86-7AD7-1030-7B44-A81000000003}\SC_Reader.exe
+ 2007-11-17 01:39:47    295,606    ----a-r    C:\WINDOWS\Installer\{AC76BA86-7AD7-1030-7B44-A81000000003}\SC_Reader.exe
+ 2007-11-17 11:33:15    16,384    ----atw    C:\WINDOWS\Temp\Perflib_Perfdata_5b0.dat
+ 2007-11-17 11:32:47    16,384    ----atw    C:\WINDOWS\Temp\Perflib_Perfdata_78c.dat
.
(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 10:33 C:\WINDOWS\RTHDCPL.exe]
"JMB36X IDE Setup"="C:\WINDOWS\JM\JMInsIDE.exe" [2006-10-30 13:44]
"36X Raid Configurer"="C:\WINDOWS\system32\JMRaidSetup.exe" [2007-02-06 13:08]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-07-28 00:03]
"CTHelper"="CTHELPER.EXE" [2006-08-17 11:32 C:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-17 11:32 C:\WINDOWS\system32\CTXFIHLP.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-04 17:14]
"nwiz"="nwiz.exe" [2007-10-04 17:14 C:\WINDOWS\system32\nwiz.exe]
"RefreshLock"="E:\ekstern hdd\formatere\RefreshLock.exe" [2002-05-28 20:30]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-10-04 17:14]
"PowerStrip"="c:\programmer\powerstrip\pstrip.exe" [2007-07-14 10:35]
"EasyTuneVPro"="C:\Programmer\Gigabyte\ET5Pro\ETcall.exe" [2007-07-26 15:05]
"!AVG Anti-Spyware"="C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"SSBkgdUpdate"="C:\Programmer\Fælles filer\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 10:22]
"PaperPort PTD"="C:\Programmer\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-18 16:11]
"IndexSearch"="C:\Programmer\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-18 16:22]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 13:00]
"Steam"="c:\steam\steam.exe" [2007-11-15 23:00]
"NVIDIA nTune"="C:\Programmer\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-07-03 12:32]
"SpybotSD TeaTimer"="C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
"Comrade.exe"="C:\Programmer\GameSpy\Comrade\Comrade.exe" [2007-06-29 15:03]

C:\Documents and Settings\Dorio-PC\Menuen Start\Programmer\Start\
hamachi.lnk - C:\Programmer\Hamachi\hamachi.exe [2007-11-12 08:21:08]
SpywareGuard.lnk - C:\Programmer\SpywareGuard\sgmain.exe [2003-08-29 19:05:35]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

R2 PStrip;PSTRIP;\??\C:\WINDOWS\system32\DRIVERS\PSTRIP.SYS
R3 GVTDrv;GVTDrv;\??\C:\WINDOWS\system32\Drivers\GVTDrv.sys
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys
R3 MarkFun_NT;MarkFun_NT;\??\C:\Programmer\Gigabyte\ET5Pro\markfun.w32
S3 gdrv;gdrv;\??\C:\WINDOWS\gdrv.sys
S3 RivaTuner32;RivaTuner32;\??\C:\Programmer\RivaTuner v2.06\RivaTuner32.sys

.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-17 12:38:54
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-17 12:39:11
C:\ComboFix2.txt ... 2007-11-17 12:36
.
    --- E O F ---
Avatar billede mido1337 Nybegynder
17. november 2007 - 12:40 #6
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:40:00, on 17-11-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Programmer\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
E:\ekstern hdd\formatere\RefreshLock.exe
C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\programmer\powerstrip\pstrip.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Programmer\Gigabyte\ET5Pro\GUI.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\Programmer\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\steam\steam.exe
C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\GameSpy\Comrade\Comrade.exe
C:\Programmer\Hamachi\hamachi.exe
C:\Programmer\SpywareGuard\sgmain.exe
C:\Programmer\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Programmer\HJTrenamed.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Programmer\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RefreshLock] E:\ekstern hdd\formatere\RefreshLock.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PowerStrip] c:\programmer\powerstrip\pstrip.exe
O4 - HKLM\..\Run: [EasyTuneVPro] C:\Programmer\Gigabyte\ET5Pro\ETcall.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programmer\Fælles filer\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Programmer\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Programmer\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "c:\steam\steam.exe" -silent
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Programmer\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Comrade.exe] C:\Programmer\GameSpy\Comrade\Comrade.exe
O4 - HKCU\..\Policies\Explorer\Run: [NTSpool] NTSpool.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: hamachi.lnk = C:\Programmer\Hamachi\hamachi.exe
O4 - Startup: SpywareGuard.lnk = C:\Programmer\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Microgaming\Poker\nordicbetMPP\MPPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmer\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://mppv2flash3.valueactive.com/NordicBet/FlashAX.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Programmer\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

--
End of file - 7998 bytes
Avatar billede arlet Juniormester
17. november 2007 - 12:46 #7
Det virkede ikke, men jeg fik vist også lavet et lille mellemrum, så vi prøver igen:

Kopiér indholdet mellem de stiplede linier ind i et notepad-vindue, og gem indholdet i samme mappe, som Combofix ligger med navnet CFScript.txt.
Når du gemmer, skal du sikre, at der under "filtyper" står "alle filer".

-------------------------
File::
C:\WINDOWS\system32\NTSpool.exe
C:\WINDOWS\pics06.zip
-------------------------

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen. - http://www.fromsej.saknet.dk/billeder/cfscript.gif
Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.

Kopier indholdet af Combofix.txt her ind sammen med en ny hijackthis log
Avatar billede mido1337 Nybegynder
17. november 2007 - 12:52 #8
ComboFix 07-11-08.1 - Dorio-PC 2007-11-17 12:51:21.6 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1030.18.2698 [GMT 1:00]
Running from: C:\Documents and Settings\Dorio-PC\Skrivebord\ComboFix.exe
Command switches used :: C:\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\pics06.zip
C:\WINDOWS\system32\NTSpool.exe
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\pics06.zip
C:\WINDOWS\system32\NTSpool.exe

.
(((((((((((((((((((((((((  Files Created from 2007-10-17 to 2007-11-17  )))))))))))))))))))))))))))))))
.

2007-11-17 02:15    <DIR>    d--------    C:\Temp
2007-11-17 02:15    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Prevx
2007-11-17 02:03    <DIR>    d--------    C:\Programmer\GameSpy
2007-11-17 01:59    22,328    --a------    C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-11-17 01:59    22,328    --a------    C:\Documents and Settings\Dorio-PC\Application Data\PnkBstrK.sys
2007-11-17 01:44    <DIR>    d--------    C:\Programmer\Electronic Arts
2007-11-16 22:37    51,200    --a------    C:\WINDOWS\NirCmd.exe
2007-11-16 22:35    <DIR>    d--------    C:\Programmer\Lavasoft
2007-11-16 22:35    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-16 22:34    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2007-11-16 22:34    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\SUPERAntiSpyware.com
2007-11-16 22:34    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-11-16 22:28    <DIR>    d--------    C:\Programmer\CCleaner
2007-11-16 22:14    401,720    --a------    C:\Programmer\HJTrenamed.exe
2007-11-15 12:29    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\vlc
2007-11-15 11:39    <DIR>    d--------    C:\Programmer\VideoLAN
2007-11-15 00:50    <DIR>    d--------    C:\Programmer\SpywareGuard
2007-11-15 00:12    <DIR>    d--------    C:\Programmer\Spyware Terminator
2007-11-15 00:12    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\Spyware Terminator
2007-11-15 00:12    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2007-11-14 14:49    <DIR>    d--------    C:\Programmer\Ventrilo
2007-11-14 14:49    <DIR>    d--------    C:\Programmer\Fælles filer\Wise Installation Wizard
2007-11-14 00:26    <DIR>    d--------    C:\Programmer\Microsoft Works
2007-11-14 00:25    <DIR>    d--------    C:\Programmer\Microsoft.NET
2007-11-14 00:23    <DIR>    d--------    C:\WINDOWS\SHELLNEW
2007-11-14 00:23    <DIR>    dr-h-----    C:\MSOCache
2007-11-14 00:23    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-14 00:20    176,128    ---------    C:\WINDOWS\system32\Pdrvinst.dll
2007-11-14 00:20    69,632    ---------    C:\WINDOWS\system32\BrWebIns.dll
2007-11-14 00:20    61,440    ---------    C:\WINDOWS\system32\BRWEBUP.EXE
2007-11-14 00:20    45,056    ---------    C:\WINDOWS\system32\PTRCDAN.DLL
2007-11-14 00:20    0    --a------    C:\Programmer\error.dat
2007-11-14 00:16    52,224    --a------    C:\WINDOWS\system32\brinsstr.dll
2007-11-14 00:16    50    --a------    C:\WINDOWS\system32\bridf06a.dat
2007-11-14 00:15    <DIR>    d--------    C:\Programmer\ScanSoft
2007-11-14 00:15    <DIR>    d--------    C:\Programmer\Fælles filer\ScanSoft Shared
2007-11-14 00:15    <DIR>    d--------    C:\Programmer\Brother
2007-11-14 00:15    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\ScanSoft
2007-11-14 00:15    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\InstallShield
2007-11-14 00:15    147,456    ---------    C:\WINDOWS\brunin03.dll
2007-11-14 00:14    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Brother
2007-11-12 15:33    <DIR>    d--------    C:\Programmer\Fælles filer\Futuremark Shared
2007-11-12 08:21    <DIR>    d--------    C:\Programmer\Hamachi
2007-11-12 08:21    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\Hamachi
2007-11-12 08:21    25,280    ---------    C:\WINDOWS\system32\drivers\hamachi.sys
2007-11-11 15:46    <DIR>    d--------    C:\Programmer\SpeedFan
2007-11-11 14:27    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\Azureus
2007-11-11 14:27    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Azureus
2007-11-11 14:26    <DIR>    d--------    C:\Programmer\Azureus
2007-11-11 14:19    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\SopCast
2007-11-10 21:21    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-09 23:03    <DIR>    dr-h-----    C:\Documents and Settings\Dorio-PC\Application Data\SecuROM
2007-11-09 23:03    107,888    --a------    C:\WINDOWS\system32\CmdLineExt.dll
2007-11-09 22:26    <DIR>    d--------    C:\Programmer\THQ
2007-11-09 22:25    3,495,784    --a------    C:\WINDOWS\system32\d3dx9_33.dll
2007-11-09 22:25    1,123,696    --a------    C:\WINDOWS\system32\D3DCompiler_33.dll
2007-11-09 22:25    443,752    --a------    C:\WINDOWS\system32\d3dx10_33.dll
2007-11-09 22:24    <DIR>    d--hs----    C:\WINDOWS\ftpcache
2007-11-09 22:07    <DIR>    d--------    C:\Programmer\BurnInTest
2007-11-09 22:07    <DIR>    d-a------    C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-09 22:07    2,414,360    --a------    C:\WINDOWS\system32\d3dx9_31.dll
2007-11-08 23:01    <DIR>    d--------    C:\Programmer\Fælles filer\Adobe
2007-11-08 19:04    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\Grisoft
2007-11-08 19:04    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-08 19:04    10,872    --a------    C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-08 17:44    24,944    --a------    C:\WINDOWS\system32\drivers\GVTDrv.sys
2007-11-08 17:43    40,136    --a------    C:\WINDOWS\system32\drivers\ET5Drv.sys
2007-11-08 17:41    327,168    --a------    C:\WINDOWS\IsUninst.exe
2007-11-08 14:51    <DIR>    d--------    C:\Microgaming
2007-11-08 14:51    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\Microgaming
2007-11-08 14:48    <DIR>    d--------    C:\WINDOWS\system32\FlashAX
2007-11-08 13:01    <DIR>    d--------    C:\Programmer\GIGABYTE
2007-11-08 05:52    <DIR>    d--------    C:\WINDOWS\system32\Futuremark
2007-11-08 05:52    27,672    ---------    C:\WINDOWS\system32\drivers\Entech.sys
2007-11-08 05:52    5,632    ---------    C:\WINDOWS\system32\drivers\Entech64.sys
2007-11-08 05:52    3,972    ---------    C:\WINDOWS\system32\drivers\PciBus.sys
2007-11-08 05:51    <DIR>    d--------    C:\Programmer\Futuremark
2007-11-07 20:43    <DIR>    d--------    C:\Programmer\SopCast
2007-11-07 18:31    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\Ventrilo
2007-11-07 00:44    <DIR>    d--------    C:\Programmer\Lavalys
2007-11-07 00:35    <DIR>    d--------    C:\WINDOWS\Sun
2007-11-07 00:34    <DIR>    d--------    C:\Programmer\RivaTuner v2.06
2007-11-07 00:13    <DIR>    d--------    C:\Programmer\NVIDIA Corporation
2007-11-07 00:03    1,144    --a------    C:\WINDOWS\mozver.dat
2007-11-06 23:50    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Application Data\Talkback
2007-11-06 23:50    0    --a------    C:\WINDOWS\nsreg.dat
2007-11-06 23:41    <DIR>    d--------    C:\Programmer\PowerStrip
2007-11-06 22:43    <DIR>    d--------    C:\Steam
2007-11-06 22:40    <DIR>    d--------    C:\Programmer\MSXML 6.0
2007-11-06 22:29    <DIR>    d--------    C:\Programmer\MSBuild
2007-11-06 22:27    <DIR>    d--------    C:\WINDOWS\system32\XPSViewer
2007-11-06 22:27    <DIR>    d--------    C:\Programmer\Reference Assemblies
2007-11-06 22:26    <DIR>    d--------    C:\Programmer\Windows Media Connect 2
2007-11-06 22:26    14,048    ---------    C:\WINDOWS\system32\spmsg2.dll
2007-11-06 22:21    221,184    --a------    C:\WINDOWS\system32\wmpns.dll
2007-11-06 22:17    <DIR>    d--------    C:\WINDOWS\system32\URTTemp
2007-11-06 22:05    <DIR>    d--------    C:\Programmer\Java
2007-11-06 22:04    <DIR>    d--------    C:\Programmer\Fælles filer\Java
2007-11-06 21:57    <DIR>    d--------    C:\Programmer\MSN Messenger
2007-11-06 21:57    <DIR>    d--------    C:\Documents and Settings\Dorio-PC\Contacts

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-17 11:40    7,999    ----a-w    C:\Programmer\hijackthis.log
2007-11-17 00:58    669,184    ----a-w    C:\WINDOWS\system32\pbsvc.exe
2007-11-17 00:58    66,872    ----a-w    C:\WINDOWS\system32\PnkBstrA.exe
2007-11-17 00:58    103,736    ----a-w    C:\WINDOWS\system32\PnkBstrB.exe
2007-11-16 21:29    ---------    d-----w    C:\Programmer\Yahoo!
2007-11-13 23:20    ---------    d--h--w    C:\Programmer\InstallShield Installation Information
2007-11-13 23:20    ---------    d-----w    C:\Programmer\Fælles filer\InstallShield
2007-10-04 16:14    81,920    ----a-w    C:\WINDOWS\system32\nvwddi.dll
2007-10-04 16:14    81,920    ----a-w    C:\WINDOWS\system32\nvmctray.dll
2007-10-04 16:14    8,491,008    ----a-w    C:\WINDOWS\system32\nvcpl.dll
2007-10-04 16:14    753,664    ----a-w    C:\WINDOWS\system32\nvcplui.exe
2007-10-04 16:14    6,854,464    ------w    C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-10-04 16:14    6,750,208    ----a-w    C:\WINDOWS\system32\nvoglnt.dll
2007-10-04 16:14    6,344,704    ----a-w    C:\WINDOWS\system32\nvdisps.dll
2007-10-04 16:14    5,783,424    ----a-w    C:\WINDOWS\system32\nv4_disp.dll
2007-10-04 16:14    466,944    ----a-w    C:\WINDOWS\system32\nvshell.dll
2007-10-04 16:14    45,056    ----a-w    C:\WINDOWS\system32\nvmccsrs.dll
2007-10-04 16:14    442,368    ----a-w    C:\WINDOWS\system32\nvappbar.exe
2007-10-04 16:14    425,984    ----a-w    C:\WINDOWS\system32\keystone.exe
2007-10-04 16:14    364,544    ----a-w    C:\WINDOWS\system32\nvapi.dll
2007-10-04 16:14    36,864    ----a-w    C:\WINDOWS\system32\nvcodins.dll
2007-10-04 16:14    36,864    ----a-w    C:\WINDOWS\system32\nvcod.dll
2007-10-04 16:14    307,200    ----a-w    C:\WINDOWS\system32\nvexpbar.dll
2007-10-04 16:14    3,551,232    ----a-w    C:\WINDOWS\system32\nvvitvs.dll
2007-10-04 16:14    3,334,144    ----a-w    C:\WINDOWS\system32\nvgames.dll
2007-10-04 16:14    286,720    ----a-w    C:\WINDOWS\system32\nvnt4cpl.dll
2007-10-04 16:14    229,376    ----a-w    C:\WINDOWS\system32\nvmccs.dll
2007-10-04 16:14    2,371,584    ----a-w    C:\WINDOWS\system32\nvwss.dll
2007-10-04 16:14    188,416    ----a-w    C:\WINDOWS\system32\nvmccss.dll
2007-10-04 16:14    155,716    ----a-w    C:\WINDOWS\system32\nvsvc32.exe
2007-10-04 16:14    147,456    ----a-w    C:\WINDOWS\system32\nvcolor.exe
2007-10-04 16:14    1,703,936    ----a-w    C:\WINDOWS\system32\nvwdmcpl.dll
2007-10-04 16:14    1,626,112    ----a-w    C:\WINDOWS\system32\nwiz.exe
2007-10-04 16:14    1,478,656    ----a-w    C:\WINDOWS\system32\nview.dll
2007-10-04 16:14    1,339,392    ----a-w    C:\WINDOWS\system32\nvdspsch.exe
2007-10-04 16:14    1,150,976    ----a-w    C:\WINDOWS\system32\nvmobls.dll
2007-10-04 16:14    1,019,904    ----a-w    C:\WINDOWS\system32\nvwimg.dll
2007-08-21 06:17    683,520    ----a-w    C:\WINDOWS\system32\inetcomm.dll
.

(((((((((((((((((((((((((((((  snapshot_2007-11-17_ 2.19.59,17  )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-08 22:02:18    295,606    ----a-r    C:\WINDOWS\Installer\{AC76BA86-7AD7-1030-7B44-A81000000003}\SC_Reader.exe
+ 2007-11-17 01:39:47    295,606    ----a-r    C:\WINDOWS\Installer\{AC76BA86-7AD7-1030-7B44-A81000000003}\SC_Reader.exe
+ 2007-11-17 11:33:15    16,384    ----atw    C:\WINDOWS\Temp\Perflib_Perfdata_5b0.dat
+ 2007-11-17 11:32:47    16,384    ----atw    C:\WINDOWS\Temp\Perflib_Perfdata_78c.dat
.
(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 10:33 C:\WINDOWS\RTHDCPL.exe]
"JMB36X IDE Setup"="C:\WINDOWS\JM\JMInsIDE.exe" [2006-10-30 13:44]
"36X Raid Configurer"="C:\WINDOWS\system32\JMRaidSetup.exe" [2007-02-06 13:08]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-07-28 00:03]
"CTHelper"="CTHELPER.EXE" [2006-08-17 11:32 C:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-17 11:32 C:\WINDOWS\system32\CTXFIHLP.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-04 17:14]
"nwiz"="nwiz.exe" [2007-10-04 17:14 C:\WINDOWS\system32\nwiz.exe]
"RefreshLock"="E:\ekstern hdd\formatere\RefreshLock.exe" [2002-05-28 20:30]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-10-04 17:14]
"PowerStrip"="c:\programmer\powerstrip\pstrip.exe" [2007-07-14 10:35]
"EasyTuneVPro"="C:\Programmer\Gigabyte\ET5Pro\ETcall.exe" [2007-07-26 15:05]
"!AVG Anti-Spyware"="C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"SSBkgdUpdate"="C:\Programmer\Fælles filer\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 10:22]
"PaperPort PTD"="C:\Programmer\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-18 16:11]
"IndexSearch"="C:\Programmer\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-18 16:22]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 13:00]
"Steam"="c:\steam\steam.exe" [2007-11-15 23:00]
"NVIDIA nTune"="C:\Programmer\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-07-03 12:32]
"SpybotSD TeaTimer"="C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
"Comrade.exe"="C:\Programmer\GameSpy\Comrade\Comrade.exe" [2007-06-29 15:03]

C:\Documents and Settings\Dorio-PC\Menuen Start\Programmer\Start\
hamachi.lnk - C:\Programmer\Hamachi\hamachi.exe [2007-11-12 08:21:08]
SpywareGuard.lnk - C:\Programmer\SpywareGuard\sgmain.exe [2003-08-29 19:05:35]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

R2 PStrip;PSTRIP;\??\C:\WINDOWS\system32\DRIVERS\PSTRIP.SYS
R3 GVTDrv;GVTDrv;\??\C:\WINDOWS\system32\Drivers\GVTDrv.sys
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys
R3 MarkFun_NT;MarkFun_NT;\??\C:\Programmer\Gigabyte\ET5Pro\markfun.w32
S3 gdrv;gdrv;\??\C:\WINDOWS\gdrv.sys
S3 RivaTuner32;RivaTuner32;\??\C:\Programmer\RivaTuner v2.06\RivaTuner32.sys

.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-17 12:51:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-17 12:52:10
C:\ComboFix2.txt ... 2007-11-17 12:39
C:\ComboFix3.txt ... 2007-11-17 12:36
.
    --- E O F ---
Avatar billede mido1337 Nybegynder
17. november 2007 - 12:52 #9
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:52:40, on 17-11-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Programmer\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
E:\ekstern hdd\formatere\RefreshLock.exe
C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe
C:\programmer\powerstrip\pstrip.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Programmer\Gigabyte\ET5Pro\GUI.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\Programmer\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\steam\steam.exe
C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\GameSpy\Comrade\Comrade.exe
C:\Programmer\Hamachi\hamachi.exe
C:\Programmer\SpywareGuard\sgmain.exe
C:\Programmer\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Programmer\HJTrenamed.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Programmer\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RefreshLock] E:\ekstern hdd\formatere\RefreshLock.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PowerStrip] c:\programmer\powerstrip\pstrip.exe
O4 - HKLM\..\Run: [EasyTuneVPro] C:\Programmer\Gigabyte\ET5Pro\ETcall.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programmer\Fælles filer\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Programmer\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Programmer\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "c:\steam\steam.exe" -silent
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Programmer\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Comrade.exe] C:\Programmer\GameSpy\Comrade\Comrade.exe
O4 - HKCU\..\Policies\Explorer\Run: [NTSpool] NTSpool.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: hamachi.lnk = C:\Programmer\Hamachi\hamachi.exe
O4 - Startup: SpywareGuard.lnk = C:\Programmer\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Microgaming\Poker\nordicbetMPP\MPPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmer\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://mppv2flash3.valueactive.com/NordicBet/FlashAX.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Programmer\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

--
End of file - 7964 bytes
Avatar billede arlet Juniormester
17. november 2007 - 13:07 #10
Så virkede det..

Kør Hijackthis, scan, sæt flueben ved linien/linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked, luk hijackthis igen.

O4 - HKCU\..\Policies\Explorer\Run: [NTSpool] NTSpool.exe
(det kan være at den ikke er der, så går du bare videre)

Hent og dobbeltklik denne fil. Den pakker sig ud til C:\SDFix:
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

Genstart i fejlsikret, hvis du ikke ved hvordan så kig her (Scroll ned til "Sådan får du adgang til fejlsikret tilstand") http://kimludvigsen.dk/tips-windows-fejlsikret.html


Gå så ind i mappen SDFix på C drevet. Dobbeltklik på filen RunThis.bat, for at starte værktøjet. Tryk "y" for at bekræfte, at du kører værktøjet på egen risiko. Så vil værktøjet gå i gang med at fjerne trojanservicen, og lave et par reparationer af registreringsdatabasen. På et tidspunkt vil det bede dig om at trykke en taste for at genstarte computeren. Det skal du gøre, hvorefter computeren vil genstarte efter 15 sekunder.

Genstarten vil tage lidt længere end sædvanligt, idet værktøjet skal have tid til at udføre sit arbejde. Når skrivebordet dukker op, vil værktøjet skrive "Finished". Tryk herefter en taste for at indlæse dine skrivebordsikoner igen.

Åben så SDFix-mappen, find filen Report.txt, og kopier indholdet af denne fil herind.
Avatar billede mido1337 Nybegynder
17. november 2007 - 13:25 #11
SDFix: Version 1.114

Run by Dorio-PC on 17-11-2007 at 13:16

Microsoft Windows XP [version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

No Trojan Files Found




Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



                                Final Check:

catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-17 13:22:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

C:\Documents and Settings\Dorio-PC\Lokale indstillinger\Application Data\Microsoft\Messenger\Dorio@stofanet.dk\SharingMetadata\nermin14_4@hotmail.com\DFSR\Staging\CS{18DF4267-58F7-9ED2-3442-CB82AFDF22AA}\01\10-{18DF4267-58F7-9ED2-3442-CB82AFDF22AA}-v1-{D6D94B63-A5DD-40F3-894D-0E30D61D7AC4}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Dorio-PC\Lokale indstillinger\Application Data\Microsoft\Messenger\Dorio@stofanet.dk\SharingMetadata\sniperspot84@yahoo.dk\DFSR\Staging\CS{E14B7E5C-CD41-C56E-678E-70FD52B1CCFB}\01\18-{E14B7E5C-CD41-C56E-678E-70FD52B1CCFB}-v1-{D6D94B63-A5DD-40F3-894D-0E30D61D7AC4}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Dorio-PC\Lokale indstillinger\Application Data\Microsoft\Messenger\Dorio@stofanet.dk\SharingMetadata\trungdo0501@hotmail.com\DFSR\Staging\CS{629DF40B-E4C3-D648-6229-59E2348C4CBC}\01\12-{629DF40B-E4C3-D648-6229-59E2348C4CBC}-v1-{D6D94B63-A5DD-40F3-894D-0E30D61D7AC4}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 3


Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

Remaining Files:
---------------


Files with Hidden Attributes:


Finished!
Avatar billede arlet Juniormester
17. november 2007 - 14:18 #12
Så ser det bedre ud..

Hjalp kuren??

Kør lige trin 5 og 6 herfra: http://www.malwarecheck.dk/forum/viewtopic.php?t=11

Her kan du læse om vores skudsikre sikkerhedspakke: http://www.malwarecheck.dk/forum/viewtopic.php?t=156 .
Hvis du har nogle spørgsmål, så spørger du bare..
Avatar billede mido1337 Nybegynder
17. november 2007 - 14:22 #13
takker det hjalp :)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester